From 54930b4143288fe20abae05ef0da183d55691f4f Mon Sep 17 00:00:00 2001 From: Dallin Romney Date: Fri, 2 Oct 2026 07:09:25 -0700 Subject: [PATCH] fix(release): trust Dev MSIX signers machine-wide --- .github/workflows/ci.yml | 7 +++++-- tests/OpenClaw.Tray.Tests/ReleaseSigningWorkflowTests.cs | 2 ++ 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 32cbf98bd..4d7e6bbb4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1378,7 +1378,10 @@ jobs: - name: Trust signed Dev MSIX certificates for validation shell: pwsh run: | - $storePath = 'Cert:\CurrentUser\TrustedPeople' + # setup-dev-msix-cert.ps1 validates these self-signed packages through + # LocalMachine trust. Use the same store after artifact download so + # Get-AuthenticodeSignature evaluates the package as Valid. + $storePath = 'Cert:\LocalMachine\TrustedPeople' $thumbprintsPath = "$env:RUNNER_TEMP\openclaw-dev-msix-imported-certs.txt" [IO.File]::WriteAllText($thumbprintsPath, '') foreach ($architecture in @('x64', 'arm64')) { @@ -1424,7 +1427,7 @@ jobs: $thumbprintsPath = "$env:RUNNER_TEMP\openclaw-dev-msix-imported-certs.txt" if (Test-Path -LiteralPath $thumbprintsPath) { foreach ($thumbprint in @(Get-Content -LiteralPath $thumbprintsPath)) { - Get-ChildItem -LiteralPath 'Cert:\CurrentUser\TrustedPeople' | + Get-ChildItem -LiteralPath 'Cert:\LocalMachine\TrustedPeople' | Where-Object Thumbprint -EQ $thumbprint | Remove-Item -Force } diff --git a/tests/OpenClaw.Tray.Tests/ReleaseSigningWorkflowTests.cs b/tests/OpenClaw.Tray.Tests/ReleaseSigningWorkflowTests.cs index 301f458cc..52a2f4258 100644 --- a/tests/OpenClaw.Tray.Tests/ReleaseSigningWorkflowTests.cs +++ b/tests/OpenClaw.Tray.Tests/ReleaseSigningWorkflowTests.cs @@ -139,6 +139,8 @@ public void ReleaseWorkflow_PublishesSignedDevMsixForEveryTag() Assert.Contains("name: Download x64 signed Dev MSIX release artifact", workflow); Assert.Contains("name: Download ARM64 signed Dev MSIX release artifact", workflow); Assert.Contains("name: Trust signed Dev MSIX certificates for validation", workflow); + Assert.Contains(@"$storePath = 'Cert:\LocalMachine\TrustedPeople'", workflow); + Assert.DoesNotContain(@"Cert:\CurrentUser\TrustedPeople", workflow); Assert.Contains("name: Stage signed Dev MSIX release assets", workflow); Assert.Contains("name: Remove trusted Dev MSIX certificates", workflow); Assert.Contains("Get-AuthenticodeSignature -LiteralPath $packagePath", File.ReadAllText(