Skip to main content

Clean-machine install verification

The checklist that decides whether an installer may be released, and the record of each run.

Feature 054-desktop-runtime-shell — T107. SC-022: zero security warnings and zero manual overrides, on both platforms.

Why this is a manual checklist and not a test​

The thing being verified is what a merchant's operating system decides when it sees our installer — Gatekeeper on macOS, SmartScreen on Windows. That verdict depends on the certificate, on notarisation having propagated, and on the machine's default settings. None of it can be asserted from inside the build that produced the artefact.

CI checks what it can: the release workflow refuses to publish a macOS build that fails codesign --verify or spctl --assess, and a Windows build whose Authenticode signature is not Valid. That catches an unsigned artefact. It does not catch the case this checklist exists for — a correctly signed installer that a real machine still warns about, because reputation, notarisation timing, or the certificate chain is not what we assumed.

The rule​

A run that produces any warning is a failed run. Not "a warning we clicked through". SC-022's number is zero, and the reason is not tidiness: an installer that warns teaches merchants that FlowPOS warnings are normal and should be dismissed. That lesson, once learned, is exactly what an attacker needs.

If a run warns, the release does not ship. Record it below as failed, with the exact wording of the warning.

The checklist​

Run on a machine that has never had FlowPOS installed — a fresh VM or a reset computer. A machine that has run FlowPOS before may have already accepted the certificate, which hides the failure this is looking for.

Both platforms​

  • The machine is clean: no prior FlowPOS install, no developer certificates, no security settings changed from default.
  • The installer was downloaded from the FlowPOS website over HTTPS, not copied from a build machine or a shared drive.
  • Record the OS version and the installer's version and channel.

Windows​

  • Double-clicking the installer produces no SmartScreen warning.
  • No "unknown publisher" dialog; the publisher is named.
  • The install completes without an administrator prompt (it installs for the current user).
  • FlowPOS opens from the Start menu with no further warning.
  • Get-AuthenticodeSignature on the installer reports Valid.

macOS​

  • Opening the .dmg produces no Gatekeeper warning.
  • Dragging to Applications and opening FlowPOS produces no "unidentified developer" dialog, and no right-click → Open workaround is needed.
  • spctl --assess --type execute --verbose /Applications/FlowPOS.app reports accepted and source=Notarized Developer ID.
  • stapler validate /Applications/FlowPOS.app succeeds — a notarisation that was not stapled works only while the machine can reach Apple, so an offline shop would see the warning we thought we had removed.

After install, on both​

  • The status window opens and shows both version numbers.
  • The install recommendation about an account password and disk encryption was shown during installation (FR-025i).

Recorded runs​

DateVersionChannelPlatformOS versionWarningsOverridesResultRun by
———————Not yet run—

No run has been recorded. Both platforms are blocked on certificates: the Apple Developer ID Application certificate (T005) and the Windows organisation code-signing identity (T006). Until those exist there is no signed artefact to verify, and a run against an unsigned build would only confirm that unsigned builds warn — which is not what SC-022 asks.

This table is the evidence for SC-022. An empty table means the criterion is not met, and it must not be read as "probably fine": the whole point of a clean-machine run is that nothing in the build can predict its result.