Function: validateSignedManifestShape()
validateSignedManifestShape(
info):string|null
Checks that a manifest has the shape a signed manifest must have for its signature to mean anything,
independent of the key material. Returns a human-readable reason when it does not, or null when it does.
Enforced by verifyManifestSignatures before any signature is checked, and by the build-time signer so that a manifest the updater would reject is never signed in the first place:
versionis a non-empty stringfilesis a non-empty array whose entries have a non-empty stringurlandsha512(and a numericsizewhen present) — a signed manifest must describe its own files, so the updater never consults the unsigned legacy top-levelpath/sha512for itstagingPercentageis a number when present,minimumSystemVersiona string when present- every
packagesentry (NSIS web installer) has a non-empty stringpathandsha512, numericsize/blockMapSizewhen present, and a booleanisAdminRightsRequiredwhen present - no signed string field (including package arch keys) contains a control character (U+0000–U+001F, U+007F)
The canonical encoding is injective on its own (see canonicalizeForSigning), so these checks are a second, independent line of defense: they reject a manifest whose signed fields could only have been crafted to confuse a parser or a version comparison, rather than relying on every downstream consumer to cope.
Parameters
info
Returns
string | null