Skip to content

Remove CLI hash verification and path allowlist - #15

Merged
0xeb merged 1 commit into
mainfrom
remove-cli-verification
Feb 11, 2026
Merged

0xeb merged 1 commit into
mainfrom
remove-cli-verification

Conversation

@0xeb

@0xeb 0xeb commented Feb 11, 2026

Copy link
Copy Markdown
Owner

Summary

  • Remove CLI binary integrity verification (SHA-256 hash check) and path allowlist features added in v0.1.11
  • Remove hard dependency on OpenSSL (Linux/macOS) and crypt32 (Windows)
  • Aligns with Python reference SDK which has no equivalent features

Details

The hash check validated against a user-supplied value with no trust anchor (no official hash distribution channel), providing questionable security benefit while adding a platform-specific crypto dependency.

Files removed

  • src/internal/transport/cli_verification.cpp
  • src/internal/transport/cli_verification.hpp

Fields removed from ClaudeOptions

  • allowed_cli_paths
  • cli_hash_sha256

Test plan

  • Build passes (MSVC, Release)
  • All tests pass (2/2)
  • No remaining references to removed symbols

These features (v0.1.11+) are not present in the Python reference SDK and
added a hard dependency on OpenSSL (Linux/macOS) / crypt32 (Windows) for
questionable benefit — the hash was validated against a user-supplied value
with no trust anchor.

Removed:
- cli_verification.cpp/.hpp (SHA-256 compute, hash verify, path allowlist)
- allowed_cli_paths and cli_hash_sha256 fields from ClaudeOptions
- Crypto library linking from CMakeLists.txt
- Verification calls from both subprocess transport implementations
@0xeb
0xeb merged commit 627f2b9 into main Feb 11, 2026
6 of 7 checks passed
@0xeb
0xeb deleted the remove-cli-verification branch February 11, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant