[qt/qt/qtapplicationmanager]: Summary of bulk changes made
KDE Git Services - Bulk Change <[email protected]>
| Newsgroups | gmane.comp.kde.cvs |
|---|---|
| Message-ID | <[email protected]> |
Git repository change summary for qt/qt/qtapplicationmanager Pushed by mirror-service into branch '6.12'. Changed from 02235924d273f5ed57e3d81cef4ea6fc00e85cca to 60102008496b23dbd38210cdd0063c22b49a4ec5 Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository. This change contains the following new commits: Git commit a6d80c1ad057562ccccb18b864ce128b64262ed8 by Qt Cherry-pick Bot (on behalf of Robert Griebl) on 13/08/2026 at 14:51.. Security review: require store signatures for System UI installs Split the task origin System into SystemDeveloper and SystemUI and derive it in one place from the D-Bus bus type and the development mode. The signature verification in InstallationTask is now purely origin based instead of consulting the development mode: * SystemUI installs always need both a store and a developer signature. Before, enabling development mode also relaxed the store signature requirement for System UI initiated installs. * ApplicationDeveloper installs (via appman-controller) reject store-signed packages and require a developer signature created by the currently set developer certificate, with the package staying within the certificate's bounds. * SystemDeveloper installs (via appman-controller) can sideload store-signed packages; a developer signature is always required. The duplicated developer-certificate bounds checks are now in the checkDeveloperCertificate() helper, which also reports a missing certificate explicitly instead of failing the package-id match against an empty certificate. The signer-binding check moved out of the verification try block, so its errors are no longer re-wrapped as verification failures. The tests install dev-signed packages via the controller origin now and a new test verifies the store signature requirement for System UI installs. Change-Id: I4c18ae36e72b7fa073b0ef62058aea855a332f6e Fixes: QTBUG-149118 Reviewed-by: Thomas Senyk <[email protected]> (cherry picked from commit 54375674bede168249620ffee2f2c5c715686c58) Reviewed-by: Qt Cherry-pick Bot <[email protected]> https://invent.kde.org/qt/qt/qtapplicationmanager/-/commit/a6d80c1ad057562ccccb18b864ce128b64262ed8 Git commit f81a5bfe94cdca20d0abdf5f2e79db0530c2b0a2 by Qt Cherry-pick Bot (on behalf of Robert Griebl) on 13/08/2026 at 14:51.. Doc: improve the taskFinished/taskFailed signals docs Change-Id: I135f163906e21fd46d2fa9cb858b80a94e283202 Reviewed-by: Thomas Senyk <[email protected]> (cherry picked from commit 2734d238fbf706a05afc267470488f4d55ee7d9a) Reviewed-by: Qt Cherry-pick Bot <[email protected]> https://invent.kde.org/qt/qt/qtapplicationmanager/-/commit/f81a5bfe94cdca20d0abdf5f2e79db0530c2b0a2 Git commit 60102008496b23dbd38210cdd0063c22b49a4ec5 by Qt Submodule Update Bot on 13/08/2026 at 15:51.. Update dependencies on '6.12' in qt/qtapplicationmanager Change-Id: Iecf58035074e7f68e012ba1a7293c840b277f4d0 Reviewed-by: Qt Submodule Update Bot <[email protected]> https://invent.kde.org/qt/qt/qtapplicationmanager/-/commit/60102008496b23dbd38210cdd0063c22b49a4ec5