Skip to content

Normalize strict-invalid Codex runtime signatures - #16

Open
0thernet wants to merge 1 commit into
mainfrom
codex/hra-codex-signature-normalization
Open

Normalize strict-invalid Codex runtime signatures#16
0thernet wants to merge 1 commit into
mainfrom
codex/hra-codex-signature-normalization

Conversation

@0thernet

Copy link
Copy Markdown
Contributor

Summary

  • normalize only the two exact pinned Codex 0.144.6 binaries whose upstream Developer ID signatures fail strict verification on the target macOS host
  • preserve independently pinned official source identity through owner-private reversible reconstruction and the unchanged native payload verifier
  • require exact normalized hashes, sizes, identifiers, ad-hoc hardened-runtime signatures, CDHashes, manifest/tree sealing, and tamper regressions

Local acceptance

  • repository source check: passed
  • desktop Direct browser verification: passed
  • web Direct browser verification: passed
  • production build: passed
  • macOS ad-hoc package, reconstruction, tamper, app, copy, and mounted-DMG strict verification: passed

Exact candidate: 1520f71

@vercel

vercel Bot commented Aug 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hra Ready Ready Preview Aug 18, 2026 4:27pm

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant