chore(agent): drop dev-skip-broker-signature cargo feature - #2019
Merged
Benoît Cortier (CBenoit) merged 2 commits intoSep 30, 2026
Merged
Conversation
The broker client signature bypass is already opt-in through the `skip_broker_signature_validation` debug configuration option, matching how `skip_msi_signature_validation` works. The extra compile-time gate only forced a dedicated CI step to run the policy route authorization tests, which now run as part of the regular workspace test run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Member
Author
|
Implementation notes:
|
Copilot started reviewing on behalf of
Benoît Cortier (CBenoit)
September 30, 2026 15:28
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
A production security bypass needs explicit human acceptance, and the revised test does not verify signature enforcement when the bypass is off.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR removes the development-only Cargo gate for the Agent’s package-broker signature bypass. The debug configuration option now controls the bypass in all builds.
Changes:
- Remove the feature gate and its dedicated CI test step.
- Run policy route authorization tests in the regular workspace test run.
- Update signature-validation tests for the new behavior.
| File | Description |
|---|---|
devolutions-agent/src/service.rs |
Passes the debug bypass setting to the broker. |
devolutions-agent/src/config.rs |
Removes the obsolete feature-gate documentation. |
devolutions-agent/Cargo.toml |
Removes the Agent feature. |
crates/now-package-broker/src/server/mod.rs |
Ungates route authorization tests. |
crates/now-package-broker/src/auth.rs |
Removes the gate and revises authentication tests. |
crates/now-package-broker/Cargo.toml |
Removes the broker feature. |
.github/workflows/ci.yml |
Builds without the feature and removes its dedicated test step. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The previous test failed on the missing trusted-writer guard before the Authenticode check ran. Retain the executable handle and a test-only security guard so the non-bypassed path is proven to reject the unsigned test binary, and cover the bypass in a separate test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Benoît Cortier (CBenoit)
deleted the
claude/remove-broker-signature-flag-078e08
branch
September 30, 2026 16:10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Removes the development-only
dev-skip-broker-signaturecargo feature.Skipping package broker client signature validation is already opt-in through the
__debug__.skip_broker_signature_validationconfiguration option (off by default), the same model asskip_msi_signature_validation.The extra compile-time gate only duplicated that control and required a dedicated CI step to run some tests.
Changes:
now-package-brokeranddevolutions-agent; the debug option is now honored directly (aDEBUG MODEwarning is still logged when the bypass is used).now-package-brokerare no longer feature-gated, so they run with the regularcargo test --workspace.Run policy route authorization testsCI step and build the agent for the policy tester without--features; the tester still enables the bypass through its generatedagent.json.Reviewer note: on a production build, whoever can edit
agent.jsoncan now disable broker client signature validation. The trusted-writer check on the client executable is not affected by the bypass.Follow-up to #1981.
🤖 Generated with Claude Code