* For the Installer and Downloader XPC Services, if these executables are code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID.
* For the Downloader XPC Service, the request URL must be http/https
* For Autoupdate, if stage 1 of installation hasn't been completed yet and this executable is code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID. As before, multiple simultaneous connections are still disallowed.
* For Autoupdate, if it's not signed with Apple issued certificate, when installing package updates the bundle being updated must be itself and owned by root on disk (as one expects from a PKG installation)
* The authorization prompt message in the Installer Service is more computed inside the service so the client can't pass a completely arbitrary message
* Add extra nullable checking of parameters coming from XPC endpoints
* Add more thread-safe synchronization for Autoupdate installer
* Add logs for more failure points
Adds an opt-in option (SUVerifyUpdateBeforeExtraction) to enforce verifying updates before extracting them for stronger security. EdDSA signing is required to use this option. As fallback in case EdDSA keys are lost, disk image archives's code signatures are validated assuming it's Developer ID signed. Key rotation is still possible.
Apple Archives (aar, yaa) now require using this option.
* Don't allow removal of (Ed)DSA keys for pre-validated updates (delta updates, .aar updates)
* Don't allow removal of code signing identity in new update (at minimum, an adhoc signature can be used)
This will preserve the file creation date of the new app bundle, but not the file creation date of any of the files inside the new app bundle because tracking those changes is complex/undesirable.
This bumps the major binary delta version to 4. A new test has been added for testing that the new bundle creation date is also preserved.
* Handle failing to extract password protected disk images even when a decryption password isn't provided.
* Propagate error with more information when hdiutil attach fails.
* Wait for detaching disk images for unit tests (fixes not being able to run tests repeatably).
Check `man aa` and https://developer.apple.com/documentation/applearchive for more details. This is an efficient Apple custom archive format available since versions of macOS 10.15.
In macOS 10.15, this utility used to be called yaa.
If we detect the wrong archive is being served (i.e, expected content length differs from archive length) we log this out to developers. If the app version in the archive (if available) also differs, we report this discrepancy as well. If the update archive looks the same but signing validation fails, we tell the developer the update may have not been signed correctly.
I'm not changing the generic error that is reported to users about the update being improperly signed (that would involve propagating this information there and updating bunch of localizations). The extra info is more for the developer than it is for the user.
Fixes#2468
This only applies when multiple XML nodes are present with the same name. E.g. multiple description or releaseNoteLink elements with different xml:lang's specified.
Also generate a warning if an language has to be interpreted implicitly when there is no xml:lang explicitly specified and there are multiple node items.
This also allows embedded release notes to be plain text using sparkle:format="plain-text" attribute.
Also, Catalyst apps only support plain text release notes (compared to before where release notes weren't supported for Catalyst apps).
Also log out the download failure when a delta update fails to download (such as a 404 error for example).
Additionally, add a check to make sure that top-level appcast items cannot be delta update items.
For creation, we will disallow creating delta updates if a custom resource fork icon data is found in either the old or app bundles.
For applying, we will just ignore the icon data when performing hash verification and continue applying the patch.
Normally when a major upgrade is skipped, subsequent updates for that major release are skipped. This element however allows publishing updates that ignore the user skipping the major version before a specific sub-release.
This allows marking all updates below a specific version as informational only.
A new element (sparkle:belowVersion) was introduced this over a new attribute for sparkle:version due to compatibility reasons.
* Only track 0755 permissions for symbolic links
Also warn the user when encountering symbolic links that have a non-standard permission mode.
* Warn users when bad or irregular permissions are encountered
We have one heuristic for when a .framework version changes, and another for when a file with the same name moves to another location.
To support this, we added a clone + binary diff command.
Also document and improve the format.
This new format introduces:
* A new container format which stores metadata in a way that is more efficient for compression, decompression, and size. Creation time can be 2x faster, apply time can be a few seconds faster, size savings can be 500 KB - couple of MB due to metadata alone.
* An array of supported compression formats including lzma, bzip2, zlib and more. We now default to lzma which is as competitive as bzip2 (which we were using in version 2 format) in applying/creation times, but can save several MB on size.
* Tracking of files from an old app being replicated in different locations in the new app. This can track unchanged files being renamed and can result in significant savings if the files are large.
Version 2 format is still the default. To use version 3, pass --version=3 to BinaryDelta when creating a patch. We will switch the default to version 3 later. generate_appcast support is upcoming.
* Don't expose SPUDownloadData initializer publicly
* Make SUAppcast -init unavailable
* Fix documented default user agent string
* Improve header documentation for SUAppcast(Item) and comparators
* Update more API documentation headers
Also allow returning nil in -allowedSystemProfileKeysForUpdater:
* Clarify documentation on -allowedSystemProfileKeysForUpdater:
* Rename willIdleScheduling -> notSchedule for delegate method
* Make minor correctness fix for reading info URL
If EdDSA verification passes we don't need to have DSA verification pass, and don't need to require the new update to contain a DSA signature or keys.
Also reject updates if app has EdDSA but no EdDSA signature is provided
Set $USER and $HOME variables when running guided pkg installers
This allows pre/post install scripts to reference the user's environment correctly. The standard pkg installer GUI preserves these two variables.