rdmsm4x-changelog-20260828-1902-hyperfile-p1-xpc-peer-validation
HyperFile P1 privileged-helper XPC peer validation
Resolved the P1 helper peer-validation gap in an isolated HyperFile worktree: the helper now checks each incoming connection's process code signature against the expected HyperFile client requirement before exposing the privileged XPC interface.
Scope
- Host:
rdmsm4xonly. - Canonical checkout:
/Users/richh/dev/apps/hyperFileremained clean onmainat9a6490008de329427f6a335840a7e0d44ae59b96. - Isolated worktree:
/Users/richh/dev/_worktrees/hyperfile-p1-xpc-peer-validation-20260828. - Branch and commit:
codex/hyperfile-p1-xpc-peer-validation-20260828at0964612a8fc8647b87e573dd8d1dd6abce84b11d.
Changes
- Added
Helper/HelperPeerValidation.swift, which resolves the incomingNSXPCConnection.processIdentifierwithSecCodeCopyGuestWithAttributes(kSecGuestAttributePid:), compiles the one shared client requirement, and callsSecCodeCheckValidity. - Updated
Helper/main.swiftsoServiceDelegaterejects a connection before exporting the privileged protocol or callingresume()when validation fails. - Added the macOS
HyperFileHelperPeerValidationTestsXcode test target and its one focused rejection test. - Regenerated
HyperFile.xcodeproj/project.pbxprojfromproject.ymland verified the validation source is compiled only by the helper and test targets, not by either app target. - Updated
STATUS.md,ISSUES.md,INTERFACES.md, andFEATURE_MATRIX.mdto record P1 and the test-target finding as resolved while preserving all other open items.
Verification
xcodebuild -project HyperFile.xcodeproj -scheme HyperFileHelperPeerValidationTests -destination 'platform=macOS' CODE_SIGNING_ALLOWED=NO test— 1 test, 0 failures.xcodebuild -project HyperFile.xcodeproj -scheme HyperFile-macOS -configuration Debug -destination 'platform=macOS' CODE_SIGNING_ALLOWED=NO build—BUILD SUCCEEDED.xcodebuild -project HyperFile.xcodeproj -scheme com.eastcoastscience.HyperFile.Helper -configuration Debug -destination 'platform=macOS' CODE_SIGNING_ALLOWED=NO build—BUILD SUCCEEDED.xcodegen generate --use-cachepreserved the project file hash, andgit diff --checkwas clean before commit.
Explicitly not performed
- No canonical-main merge or push.
- No code signing, helper registration/installation, launch, deployment, entitlement changes, iOS work, MCP work, or credential use.
Undo / rollback
- Preserve the branch/worktree for review. If this commit is later
integrated and needs reversal, revert
0964612a8fc8647b87e573dd8d1dd6abce84b11din the integration branch. - If the isolated worktree is no longer needed after review, remove it
with
git -C /Users/richh/dev/apps/hyperFile worktree remove /Users/richh/dev/_worktrees/hyperfile-p1-xpc-peer-validation-20260828; this does not affect canonicalmain.
Outstanding owner actions
- Review and integrate the isolated commit when appropriate. P2/P3
items in
ISSUES.mdremain untouched.