codepush_protocol

The CodePush wire protocol: what a patch manifest contains, and what a signature covers.

Shared verbatim by the in-app runtime and the publishing CLI. That is the point — before this they were two hand-written copies, one per side, which is the most reliable way to ship a signature scheme that verifies on the machine that wrote it and nowhere else.

Pure Dart, no Flutter.

What the signature covers

The whole manifest, not just the artifact:

codepush.manifest.v1
<platform> <appId> <releaseId> <engineVersion> <versionCode> <versionName>
<sha256> <sizeBytes> <rolloutPercent> <artifactUrl> <patchNumber>

Signing only the patch file would leave every decision around it unsigned. An attacker who could write to the bucket could keep a genuinely signed patch and retarget its releaseId, raise rolloutPercent from 5 to 100, or repoint artifactUrl at a different object. So the signature covers the manifest, and the manifest carries the artifact's hash.

A line-oriented payload rather than canonical JSON, because the two sides are different programs. Canonical JSON means agreeing on key order, number formatting, unicode escaping and whitespace — and any disagreement shows up as "signature invalid" on a user's device, at launch, with the cause invisible. A fixed field list joined by newlines has exactly one encoding and is covered by a golden vector asserted on both sides.

Field order is frozen. Adding a field means a new version and keeping the old builder, because a device running an older build must still be able to verify manifests signed for it.

Use

You do not depend on this directly. codepush re-exports what an app needs.

Libraries

codepush_protocol
The CodePush wire protocol: what a manifest contains and what a signature covers. Shared by the in-app runtime and the publishing CLI.