Add APPX_SIP_CLIENT_DATA and SIGNER_SIGN_EX2/EX3_PARAMS - #2353
Open
Victor Irzak (virzak) wants to merge 1 commit into
Open
Victor Irzak (virzak) wants to merge 1 commit into
Victor Irzak (virzak) wants to merge 1 commit into
Conversation
Victor Irzak (virzak)
requested review from
a team,
Jevan Saks (jevansaks) and
Vineeth Thomas Alex (vineeththomasalex)
as code owners
October 3, 2026 11:02
Signing app packages with SignerSignEx2/SignerSignEx3 requires passing an APPX_SIP_CLIENT_DATA through pSipData, which points to a SIGNER_SIGN_EX2_PARAMS (or SIGNER_SIGN_EX3_PARAMS for SignerSignEx3). None of these are declared in the Windows SDK headers. Also apply SIGNER_SIGN_FLAGS and SIGNER_TIMESTAMP_FLAGS to the matching struct fields. Fixes microsoft#2307 Generated with Claude Code
Victor Irzak (virzak)
force-pushed
the
appx-sip-client-data
branch
from
October 3, 2026 11:06
b331255 to
712a7fa
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2307
Signing an app package (.appx/.msix and bundles) with
SignerSignEx2/SignerSignEx3requires passing anAPPX_SIP_CLIENT_DATAthroughpSipData, which points to aSIGNER_SIGN_EX2_PARAMS(orSIGNER_SIGN_EX3_PARAMSforSignerSignEx3). None of these are in the Windows SDK headers, so CsWin32 users have to declare them by hand (for example, AzureSignTool'sInterop/mssign32.cs).Changes
mssign.h(AdditionalHeadersand itsRecompiledIdlHeaders/umcopy): add the three structs.SIGNER_SIGN_EX2_PARAMSandAPPX_SIP_CLIENT_DATAfollow How to programmatically sign an app package.SIGNER_SIGN_EX3_PARAMSis undocumented; its layout matches the one AzureSignTool uses in production againstmssign32.dll. The callback field is typedPSIGNER_DIGEST_SIGN_INFO, matchingSignerSignEx3'spDigestSignInfoparameter.pCryptoPolicyis typedPCERT_STRONG_SIGN_PARAin both, matching the function signatures.enums.json: applySIGNER_SIGN_FLAGSandSIGNER_TIMESTAMP_FLAGSto thedwFlags/dwTimestampFlagsfields of both param structs.Validation
./DoAll.ps1 -ExcludePackages -ExcludeSamplesbuilds cleanly. The winmd diff showsAPPX_SIP_CLIENT_DATA,SIGNER_SIGN_EX2_PARAMSandSIGNER_SIGN_EX3_PARAMSadded toWindows.Win32.Security.Cryptography, with the flag enums applied to their fields.static_asserts on struct sizes and the offset of the callback field.🤖 Generated with Claude Code