Fix native App Attest and Windows TLS verification failures - #39
Merged
Merged
Conversation
This was referenced Oct 3, 2026
georgewhewell
added a commit
to hellas-ai/gate
that referenced
this pull request
Oct 3, 2026
Gate uses the merged Work foundation for authorized and paid requests. Imported contact Offers open grant sessions; paid pools use authenticated provider offers and one shared executing chain node. Providers serve both fundings through the SDK and preserve durable quotas and revocations across restarts. The gateway has explicit Responses and HTTP configurations. Responses uses the selected Work target; HTTP retains paid-pool routing, provider assurance and optional body archiving. Shutdown drains accepted work and surfaces SDK failures after closing providers and chain state. Pins Hellas `9c342ba1`, including hellas-ai/hellas#38 (finalized owner publication ordering) and hellas-ai/hellas#39 (current App Attest extensions and the Windows TLS fixture). Native archives use Xcode’s compiler and linker. The shell follows `xcode-select`, with `GATE_DEVELOPER_DIR` for provisioned SDK 27 builds; the signing guide documents the requirement. The release binary has the recursion limit needed by the chain transport futures. Validation: - Linux and native macOS `make check`: 25 tests, bindings, frontend, formatting and strict Clippy passed. - Native macOS release app built and passed bundle validation. - Developer ID signed, provisioned test bundle on `mbp`: Apple enrollment, pinned remote grant session, provider restart and a second session passed. The test uses the installed `ai.hellas.app-attest-spike` profile; production Gate keeps its own bundle ID. - SDK TLS Responses, quota exhaustion, restart and revocation passed on Linux, macOS and Windows. Merge the two Hellas fixes first. Windows support is isolated in #585, based on this PR.
georgewhewell
added a commit
to hellas-ai/gate
that referenced
this pull request
Oct 3, 2026
Ports Gate’s host control and private state to Windows on top of #586. The diff contains the Windows named-pipe listener, private-directory ACLs and bundled SQLite; shared Work/SDK integration lives in the base PR. The Windows diff is 7 files, 101 insertions and 14 deletions. Pins the same Hellas revision as #586, including hellas-ai/hellas#38 and hellas-ai/hellas#39. Published history is preserved with normal merges. Validation: - Linux `make check`: 26 tests, bindings, frontend, formatting and strict Clippy passed. - Windows GNU cross-compilation of the desktop app and test executable passed. - Native `win10` VM: all 9 core tests passed, including authenticated host status over a named pipe, private state, history and grant offer export. - Native SDK TLS Responses/quota/restart/revocation test passed. - Desktop executable with bundled frontend and WebView2 loader launched successfully. Merge #586 first.
georgewhewell
enabled auto-merge
October 3, 2026 03:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Require
0xc0authenticator flags for App Attest credentials and assertions. Use one current-format fixture and reject evidence missing the required flags or CDHash.Give the SDK TLS fixture CA and server distinct subject names so Windows can build the certificate chain correctly.