Skip to content

Normalize strict-invalid Codex runtime signatures - #16

Closed
0thernet wants to merge 1 commit into
mainfrom
codex/hra-codex-signature-normalization
Closed

Normalize strict-invalid Codex runtime signatures#16
0thernet wants to merge 1 commit into
mainfrom
codex/hra-codex-signature-normalization

Conversation

@0thernet

Copy link
Copy Markdown
Contributor

Summary

  • normalize only the two exact pinned Codex 0.144.6 binaries whose upstream Developer ID signatures fail strict verification on the target macOS host
  • preserve independently pinned official source identity through owner-private reversible reconstruction and the unchanged native payload verifier
  • require exact normalized hashes, sizes, identifiers, ad-hoc hardened-runtime signatures, CDHashes, manifest/tree sealing, and tamper regressions

Local acceptance

  • repository source check: passed
  • desktop Direct browser verification: passed
  • web Direct browser verification: passed
  • production build: passed
  • macOS ad-hoc package, reconstruction, tamper, app, copy, and mounted-DMG strict verification: passed

Exact candidate: 1520f71

@vercel

vercel Bot commented Aug 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hra Ready Ready Preview Aug 18, 2026 4:27pm

Request Review

@0thernet

Copy link
Copy Markdown
Contributor Author

Superseded by #21, now merged to main as 5e73f19. The replacement retains the relevant provenance and reconstruction work, fixes cross-host codesign determinism, preserves the required JIT entitlements, and passed the macOS 15/26 package gates.

@0thernet 0thernet closed this Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant