AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 40 Bitcoin

support inline signed manifests in the download verifier by reading hashes from the verified signature content

Public commit record

What the developer wrote

Authored by Craig Raw

55/100 · Thin
support inline signed manifests in the download verifier by reading hashes from the verified signature content
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes how Sparrow Wallet's download verifier reads the list of trusted file hashes. Previously, the verifier read hashes from a separate manifest file on disk. Now, it reads the hashes from the cryptographically signed content itself. This is meant to support 'inline signed manifests' and reduce the chance that an attacker could swap the manifest file after the signature was verified. The change also adds a size limit on the manifest content to prevent memory exhaustion.

Recommended action

Review the drongo submodule bump (3a60bd6453f5428fc81ad3822c35bfae04c581cc) to confirm the new PGPUtils.verify overload correctly binds the signed output stream to the verification process and does not silently ignore it. Verify that MAX_VALID_MANIFEST_SIZE is a reasonable constant and that getManifest() cannot be tricked by malformed inline content. Consider whether the old detached-manifest code path still needs to read manifest.get() at all.

Security signals we found

01

previously trusted manifest was re-read from disk after signature verification, creating a TOCTOU window between signature check and hash lookup

02

new code parses manifest from the cryptographically covered bytes returned by PGP verification

03

manifest size bounded to prevent unbounded memory buffering during verification

04

submodule bump suggests supporting library change in drongo

Risk score

Why this scored 40/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.