Skip to main content

Function: validateSignedManifestShape()

validateSignedManifestShape(info): string | null

Checks that a manifest has the shape a signed manifest must have for its signature to mean anything, independent of the key material. Returns a human-readable reason when it does not, or null when it does.

Enforced by verifyManifestSignatures before any signature is checked, and by the build-time signer so that a manifest the updater would reject is never signed in the first place:

  • version is a non-empty string
  • files is a non-empty array whose entries have a non-empty string url and sha512 (and a numeric size when present) — a signed manifest must describe its own files, so the updater never consults the unsigned legacy top-level path/sha512 for it
  • stagingPercentage is a number when present, minimumSystemVersion a string when present
  • every packages entry (NSIS web installer) has a non-empty string path and sha512, numeric size/blockMapSize when present, and a boolean isAdminRightsRequired when present
  • no signed string field (including package arch keys) contains a control character (U+0000–U+001F, U+007F)

The canonical encoding is injective on its own (see canonicalizeForSigning), so these checks are a second, independent line of defense: they reject a manifest whose signed fields could only have been crafted to confuse a parser or a version comparison, rather than relying on every downstream consumer to cope.

Parameters​

info​

UpdateInfo

Returns​

string | null