Skip to content

Security package SC: doubt an unvouched publisher, report a changed signed file as tampered - #49

Merged
donislawdev merged 1 commit into
mainfrom
fix/security-package-sc
Oct 6, 2026
Merged

donislawdev merged 1 commit into
mainfrom
fix/security-package-sc

Conversation

@donislawdev

Copy link
Copy Markdown
Owner

Summary

Security package SC: a publisher name is only taken at its word beside a Trusted signature, and a file changed after it was signed is reported as Tampered.

Publisher beside a verdict other than Trusted. The name is read back without walking the chain, so beside Tampered, Expired, UntrustedRoot or Unknown it is only what the certificate claims. !publisher:microsoft used to leave out a Microsoft file changed after signing, with full confidence.

  • BinarySignature.VouchesForPublisher - only Trusted vouches.
  • publisher: with a text value on such a name is unsure, with its own reservation and sentence (window under the search box, command line on stderr): publisher:microsoft leaves the entry out, !publisher:microsoft keeps it. any, none and ? stay certain. An unsigned file is still a certain no.
  • "(not verified)" after the name in the window (cell, details panel, export), in bws show and in the listing's signature cell. JSON and the snapshot file are unchanged.
  • "Trusted" is described as not checked for revocation in the window's suggestions, on the query language page and in the README.

Tampered never arrived for a file with its own signature. The inspector asked WinVerifyTrust with WTD_SAFER_FLAG, which Microsoft documents only as "Not supported". With it, a file whose bytes no longer match its embedded signature comes back as having no signature at all, so it was reported Not signed. Measured on copies of three signed files in a temporary folder: 0x800B0100 with the flag, 0x80096010 without. The flag is removed.

No contract change: no JSON field, switch, exit code or snapshot schema.

Verification

  • Release build of the solution, 0 warnings, 0 errors.
  • Narrow test runs over the classes this touches: core 130, command line 33, window 124 (and 59 after a seam), architecture 185, site 26, integration 6 (including the new TamperedSignatureTests against real WinVerifyTrust).
  • Mutation registry for this package: 27 of 27 caught, plus 1 of 1 for the flag.
  • bws list --json --signatures against the previous build on the machine it was built on: 801 of 801 entries identical, so no verdict on an unchanged file moved.

🤖 Generated with Claude Code

…ed signed file as tampered

A publisher name is read back from the certificate without walking the chain, so
beside any verdict other than Trusted it is only what the certificate claims. A
Microsoft file changed after it was signed keeps a real Microsoft certificate,
and !publisher:microsoft - the audit question the field exists for - left out
exactly that file with full confidence.

- BinarySignature.VouchesForPublisher: only Trusted vouches for the name.
- publisher: with a text value on a name nobody vouches for is unsure, with a
  reservation of its own beside "could not be read" and "ran out of time":
  publisher:microsoft leaves the entry out, !publisher:microsoft keeps it, and
  both say how many entries rest on such a name. any, none and ? stay certain,
  and an unsigned file is still a certain no.
- The name carries "(not verified)" in the window's publisher cell, details
  panel and export, in bws show, and in the listing's signature cell. JSON and
  the snapshot file still carry the bare name.
- Trusted is described as not checked for revocation where fields are described:
  the window's suggestions, the query language page and the README.
- The query reservations of the command line move into Execution.QueryAdmissions
  so a test can hold them, and the window's into Sentences.Unjudged.

Found while checking the above on a real file: the inspector asked WinVerifyTrust
with WTD_SAFER_FLAG, documented by Microsoft only as "Not supported". With it a
file whose bytes no longer match its embedded signature comes back as having no
signature, so Tampered never arrived for such a file and it was reported as Not
signed. The flag is gone. Verdicts over every entry on the machine this was
built on are unchanged against the previous build, and an integration test
changes one byte of a copy of the runtime's core library and expects Tampered.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository UI (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0f824f4d-3bcf-4e48-a314-77d222a9e9da
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@donislawdev
donislawdev merged commit feb77d9 into main Oct 6, 2026
8 checks passed
@donislawdev
donislawdev deleted the fix/security-package-sc branch October 6, 2026 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant