From the deadwax
An Update Is Another Thing Your Mac Has to Trust
Suppose you have spent a weekend correcting covers and dates across a collection of old rips. Private Press offers an update. The release notes mention a fix you want, so you click through and return to your albums.
That small action asks your Mac to trust a new program with access to the same collection. The updater has to establish more than whether a download finished. It needs to connect the release you were offered, the disk image you received, and the application inside it.
Private Press versions 1.5.0 and later verify signed update-feed information as part of that connection. The details explain both what the checks protect and why an older installation may need a manual update.
The offer is part of the trust decision
An update feed describes a release: its version, build number, download address, compatibility, and notes. Private Press signs those details together with the expected disk-image digest, a value calculated from the image’s bytes. This ties the release being advertised to the file the app will download.
A signature over a disk image alone would not prove that the advertised version describes those bytes. Imagine a hypothetical server response labeling an older, legitimately signed image as a newer release. The image’s signature could still verify. Signing the release details and then checking the downloaded image closes that gap.
The app checks the release details’ digital signature using Ed25519 and its configured public key before accepting an item as eligible. The signer and verifier use a fixed representation of those details so they check the same bytes. Unsigned or tampered items and non-HTTPS download or release-notes links are rejected.
Newer has to mean newer
The client requires both the marketing version and build number to move forward. It also checks macOS compatibility and the version you chose to skip. A valid signature on an older release does not make it an eligible update.
If two signed entries claim the same version and build but describe different content, Private Press drops both. Identical duplicates can collapse into one release. That keeps feed order from deciding between conflicting descriptions of the same build.
The download must match the offer
Once the item is verified, the downloaded disk image must match its signed size and SHA-256 digest. The app also verifies the disk image's Ed25519 signature. A valid signature on some other release's image is insufficient when the signed digest names different bytes.
After the handoff, the updater helper checks the staged application's code signature against a requirement pinning the Private Press identifier and Keynell's Developer ID Application identity. This addresses a different question from the feed signature: is the bundle being installed the expected signed application?
Apple provides another part of the system. Gatekeeper checks downloaded software for an identified developer, notarization, and alteration. Apple describes notarization in terms of known malicious content. These platform checks complement the app's own feed and artifact checks; they do not establish that an update has no bugs or will work with every collection.
The remaining trust includes the release signing key, the release process, Apple's frameworks and tools, and the code itself. A signature cannot tell you that a change preserves every tag correctly. It also cannot force a server to offer the latest release: an old valid feed can leave the client seeing no newer update. Authenticity and delivery are separate problems.
The old helper cannot repair itself from a feed
Users running Private Press 1.4.1 or earlier need to install the corrected release manually. The older updater has a defect, and the helper performing an update comes from the already-installed application. Putting a corrected helper inside a new disk image does not replace the helper that the old app is about to launch.
The signed-feed protections described here apply to current clients, starting with version 1.5.0. An older client does not inherit those checks merely because it receives the same feed. If an old helper refuses an update or reports that it is unavailable while offline, that result is not proof that the newer verification ran or that the application was upgraded.
A signed feed that an older client can parse does not resolve the installation problem. Nor can a new release change the button or instructions displayed by an old running binary.
For those affected versions, download the current disk image from the Private Press download page, quit Private Press, open the image, and drag the application to Applications, replacing the existing app. Launch the installed copy from Applications and check its version to confirm the replacement. This migration does not call for deleting your settings, collection database, Keychain entries, or backups.
For a collector, the useful result is an update path that checks the release description as well as the downloaded bytes. Read the release instructions, especially when moving from an older build. Trust becomes easier to assess when an app says exactly what it verifies and gives you a workable route through the versions that need special handling.
See how signed update information is checked.
See the update security notesFrom the deadwax
Subscribe to Deadwax
New posts on music collections, artwork quality, and the tech behind Private Press.
We respect your privacy. Unsubscribe anytime.