[Windows] Sign arkcli release binaries for Smart App Control / WDAC compatibility
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
Direzione di ricerca
Inizia individuando la pipeline di release, i passaggi degli artefatti Windows AMD64/ARM64 e la generazione di manifest.json. Traccia il percorso dei binari attraverso il CDN, il pacchetto npm e GitHub Releases, quindi determina dove devono essere collocate la firma e la verifica. Il lavoro è completato quando ogni asset Windows pubblicato è firmato e dotato di timestamp, la relativa firma e catena di attendibilità superano CI e il relativo hash corrisponde a manifest.json.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
The Windows arkcli release binary is not Authenticode-signed. On Windows with Smart App Control enabled, Windows Code Integrity blocks the binary before any CLI command can run.
Microsoft does not provide a per-app bypass for Smart App Control. Asking users to disable this system-wide protection is therefore not an acceptable workaround. Please sign every Windows release binary with a trusted RSA-based code-signing certificate.
Environment
- Windows x64, build
26200, display version25H2 - Smart App Control: enabled and enforced
- Code Integrity policy: enforced for user-mode code
- Installed package:
@volcengine/ark-cli 1.0.13 - Latest package also checked:
@volcengine/ark-cli 1.0.15
Evidence
Both tested Windows binaries report Get-AuthenticodeSignature: NotSigned:
1.0.13SHA-256:EBF8A1BDECDBF96D5A5EB97C78699741B61C5DCEF1FA5B8CDAA9901F68F956291.0.15SHA-256:B2277006BE2408E938FB272A6CD48D468B166931A3E8C4D9B899785CAECBF47E
Windows Code Integrity records block events 3033 and 3077. The process is blocked before argument parsing, so commands such as arkcli --version, authentication status checks, usage queries, and plan queries cannot run.
The npm package downloads the Windows binary from the Volcengine CDN and verifies the SHA-256 listed in manifest.json, but hash verification does not establish a trusted Windows publisher identity and does not satisfy Smart App Control.
Reproduction
- Use Windows with Smart App Control enabled.
- Install
@volcengine/ark-clifrom npm, or download the Windows AMD64 asset from the official release. - Run any
arkclicommand. - Observe that Windows Code Integrity blocks the unsigned executable and records event
3033or3077. - Run
Get-AuthenticodeSignatureagainst the downloaded binary; the result isNotSigned.
Expected result
The official Windows binary should run while Smart App Control remains enabled, with a valid and trusted publisher signature and no related Code Integrity block events.
Requested implementation
Please update the release pipeline to:
- Authenticode-sign every Windows AMD64 and ARM64 production binary with an RSA-based certificate whose chain is trusted by Windows.
- Use a SHA-256 file digest and a trusted RFC 3161 timestamp.
- Sign the final binary before calculating and publishing the SHA-256 in
manifest.json. - Publish the same signed artifact through the Volcengine CDN, npm installation flow, and GitHub Releases.
- Add a release CI gate that fails if
Get-AuthenticodeSignatureis notValid, the signer chain is untrusted, or the signed asset hash differs from the manifest. - Document the expected publisher name and a Windows signature-verification command.
Acceptance criteria
-
Get-AuthenticodeSignature <arkcli-windows-*.exe>returnsValid. - The signer uses an RSA-based certificate trusted by Windows Smart App Control.
-
arkcli --versionruns with Smart App Control enabled. - A read-only command such as authentication status can run without Code Integrity event
3033or3077. - Windows AMD64 and ARM64 assets distributed by CDN, npm, and GitHub Releases are signed consistently.
- Release CI verifies the signature, timestamp, and published SHA-256 for every Windows build.
References
- Microsoft: Smart App Control FAQ — no per-app bypass is available: https://support.microsoft.com/windows/smart-app-control-frequently-asked-questions
- Microsoft: Code signing for Smart App Control: https://learn.microsoft.com/windows/apps/develop/smart-app-control/code-signing-for-smart-app-control
中文摘要
Windows 版 arkcli 当前未进行 Authenticode 签名,在开启 Smart App Control 的 Windows 上会在命令执行前被 Code Integrity 拦截。微软不提供单程序例外,用户只能保留系统保护而无法使用 CLI,或整体关闭保护,两者不应由用户承担。
请为 Windows AMD64/ARM64 正式发布二进制增加受 Windows 信任链认可的 RSA 代码签名和可信时间戳;签名完成后再计算并发布 manifest.json 中的 SHA-256,并在发布 CI 中强制校验签名状态、证书链、时间戳和哈希一致性。CDN、npm 安装流程和 GitHub Releases 应分发同一份已签名产物。
- Lingua principale
- Go
- Stelle
- 139
- Fork
- 15
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di volcengine/ark-cli
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
volcengine/ark-cli#27 ·
-
[BUG] Responses API:tools 含 web_search 声明时,deepseek 将 function_call_output 误读为用户消息,多轮工具对话可形成死循环Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
volcengine/ark-cli#26 · 6 commenti ·
-
[UX] postinstall silently injects 25 arkcli skills into every detected AI agent — should be opt-inAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
volcengine/ark-cli#24 · 1 reazione ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
volcengine/ark-cli#15 · 1 commento ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 64/100
volcengine/ark-cli#10 · 1 commento ·
Tutte le issue di volcengine/ark-cli
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
duplication
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
openvibely/openvibely#1443 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 60/100
canonical/service-mesh#845 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
keyxmakerx/Chronicle#1179 ·
I maintainer di solito rispondono entro 1 giorno