mix mob.plugin.sign (mob_dev v0.7.15)

Copy Markdown View Source

Signs the plugin in <dir> (default: cwd) and writes priv/mob_plugin.sig. The signature covers the SHA-256 hashes of priv/mob_plugin.exs and every file the native build reads from the plugin (MobDev.Plugin.Sign.build_inputs/2, MOB-297) — the manifest bytes are one of those files, so tampering with the manifest fails verification. The v2 envelope on disk carries the signed file_hashes list so MobDev.Plugin.Verify.verify_plugin/1 can check integrity before it ever Code.eval_files the manifest (see MOB-74).

mix mob.plugin.sign [--plugin <dir>]

Reads the private key for the plugin's :name from ~/.mob/keys/<name>.priv. Run mix mob.plugin.keygen first if you haven't already.

After signing, the printed fingerprint can be shared with host operators so they can run mix mob.plugin.trust <name> to record trust in their mob.exs.