Skip to content

[Feature]: Verify APK identity and release bundle before fresh provisioning #21

Description

@awatchar

Problem

The fresh provisioning path installs minimum-foss.apk without applying the manifest, checksum, package identity, version and signer validation already used by the existing-device updater.

Scope

  • Verify the complete reviewed bundle before any device mutation.
  • Verify RELEASE-MANIFEST.json and the APK checksum binding.
  • Verify package ID, version metadata and APK signer using the bundled/local Android tooling.
  • Fail closed with actionable error codes/messages.
  • Preserve fresh-device support; do not require an installed-signer anchor.
  • Reuse shared updater verification logic where practical without changing updater behavior.

Acceptance

  • Corrupt, incomplete, wrong-package and unsigned/unexpected-signer inputs fail before ADB mutation.
  • A valid reviewed bundle reaches the existing provisioning flow.
  • Pester tests cover success and failure paths without requiring hardware.
  • Physical T56 provisioning remains a later acceptance step when hardware is connected.

Activity

  1. awatchar commented on Aug 24, 2026

    @awatchar
    OwnerAuthor

    Implementation started on branch fix/lab-correctness-batch. The fresh provisioner will verify the complete bundle plus APK identity and signer before any ADB mutation. Coverage will be hardware-free and the existing updater contract will remain unchanged.

  2. awatchar commented on Aug 24, 2026

    @awatchar
    OwnerAuthor

    Implementation update: fresh provisioning now enters fail-closed Release mode when bundle markers are present and verifies the exact manifest allowlist/hashes, APK checksum, package/version, and exactly one manifest-bound signer before resolving ADB or selecting/mutating a device. Release mode rejects local builds and an APK path outside the bundle; source-development APKs are signature/package checked but explicitly not claimed as Release-trusted. PowerShell AST, updater regression (32/32), cellular policy, and new provisioner verification tests (13/13) pass. No hardware/ADB action was performed; physical fresh-provisioning acceptance remains deferred until a device is connected.

  3. awatchar commented on Aug 24, 2026

    @awatchar
    OwnerAuthor

    Implementation is ready in PR #26.

    Fresh Provisioner now fails closed before ADB on incomplete/tampered Release bundles, wrong package/version, signer mismatch, local build in Release mode, or an APK path outside the bundle. It captures APK hash/identity/signer at preflight and repeats the complete binding immediately before native adb install, so post-preflight replacement is refused.

    The signed-release workflow now checks out reviewed main first and authorizes only a tag whose commit exactly equals current origin/main before tag code or signing secrets are used. The separately published outer ZIP checksum is documented as the pre-extraction trust anchor; an in-bundle verifier does not claim to authenticate itself.

    Verification: Fresh Provisioner 16/16, updater 33/33 including a real built APK, PowerShell AST/cellular policy/workflow YAML checks pass. Physical Fresh Provisioner install remains open until hardware is attached.

  4. awatchar commented on Aug 24, 2026

    @awatchar
    OwnerAuthor

    PR #26 is merged and the production portal deployment is healthy. This issue remains open only for its explicitly documented hardware acceptance when a radio is attached.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions