Repository navigation
Forward Artifact Signing correlation ID for PowerShell scripts - #41
Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit intoOct 6, 2026
Conversation
## Summary - Pass `--artifact-signing-correlation-id` (or the metadata `CorrelationId`) through the portable-core Artifact Signing provider, so the `:sign` request carries `x-correlation-id` / `x-ms-correlation-id` for PowerShell scripts (and MSIX/AppX) as it already does for PE, CAB and MSI. - Stop rejecting the correlation ID in native-shaped portable signing; signature-algorithm, api-version and authority overrides are still rejected there. Callers use the correlation ID to attribute signing requests in the Artifact Signing diagnostics. Previously, signing a `.ps1` with it set failed with "does not yet support correlation ID". ## Verification - New test `mode_portable_artifact_signing_forwards_correlation_id_for_scripts`: `psign-server --expect-correlation-id` rejects the request without the header; fails before the change, passes after. - `bash scripts/linux-portable-validation.sh` - Signed a PE, an MSI and a `.ps1` against a real Artifact Signing account from Linux: `Get-AuthenticodeSignature` reports `Valid` on Windows, and the service diagnostics show the correlation ID on all requests.
Timotheus Bachinger (TimotheusBachinger)
marked this pull request as ready for review
September 30, 2026 08:59
Marc-André Moreau (mamoreau-devolutions)
approved these changes
Oct 6, 2026
Marc-André Moreau (mamoreau-devolutions)
merged commit Oct 6, 2026
52366ea
into
Devolutions:master
18 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
--artifact-signing-correlation-id(or the metadataCorrelationId)through the portable-core Artifact Signing provider, so the
:signrequest carries
x-correlation-id/x-ms-correlation-idfor PowerShellscripts (and MSIX/AppX) as it already does for PE, CAB and MSI.
signature-algorithm, api-version and authority overrides are still
rejected there.
Callers use the correlation ID to attribute signing requests in the
Artifact Signing diagnostics. Previously, signing a
.ps1with it setfailed with "does not yet support correlation ID".
Verification
mode_portable_artifact_signing_forwards_correlation_id_for_scripts:psign-server --expect-correlation-idrejects the request without theheader; fails before the change, passes after.
bash scripts/linux-portable-validation.sh.ps1against a real Artifact Signing accountfrom Linux:
Get-AuthenticodeSignaturereportsValidon Windows, andthe service diagnostics show the correlation ID on all requests.