flea: drop the source-grep security gate and update to 0.3.5
The upstream hook refused v0.3.5 as missing a required security fix. It
was not missing: copy_file_at now opens through
open_if_regular_with_meta(src.at, O_NOFOLLOW), which open_if_regular
wraps, and the gate's regex wanted '(' right after open_if_regular.
The gate dates from 0.1.x, when Omarchy carried four upstream security
patches and needed releases to prove they had absorbed them. Every
release since 0.1.5 has, and matching literal source lines has since
caught only renames (#488 and this one), never a regression. Keep the
real checks -- SHASUMS256.txt match, tarball root, minimum release age
-- and drop the greps.
Update written by bin/sync-upstream; the checksum matches upstream's
SHASUMS256.txt.
This commit is contained in:
1 parent
e2bc7586e2
commit
0cbcd890fd
2 files changed
+9
-35
No files matched your search
@@ -1,6 +1,12 @@
|
||||
#!/bin/bash
|
||||
# Verify Flea's published source archive against its checksum manifest when a
|
||||
# newer stable release exists, then check its root and required security fixes.
|
||||
# newer stable release exists, then check its root.
|
||||
#
|
||||
# Through 0.1.x this also grepped the source for the upstream security fixes
|
||||
# Omarchy once carried as patches, so the package could not move to a release
|
||||
# that lacked them. Every release since 0.1.5 has had them, and matching
|
||||
# literal source lines only ever caught renames (#488, 0.3.5's
|
||||
# open_if_regular_with_meta), never a regression.
|
||||
set -euo pipefail
|
||||
|
||||
REPO='thisisgm/flea'
|
||||
@@ -74,38 +80,6 @@ if [[ $served_roots != "$expected_root" ]]; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
archive_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archive.rs")
|
||||
archiveops_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archiveops.rs")
|
||||
run_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/run.rs")
|
||||
archivereq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivereq.rs")
|
||||
archivework_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivework.rs")
|
||||
mediaprobe_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/mediaprobe.rs")
|
||||
metareq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/metareq.rs")
|
||||
sharelink_qml=$(tar -xOzf "$tarball" "$expected_root/ui/ShareLink.qml")
|
||||
copyfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/copyfile.rs")
|
||||
regfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/regfile.rs")
|
||||
|
||||
# Every check below pins a literal line except the O_NOFOLLOW one. That check
|
||||
# guards a property -- the copy opens its source with O_NOFOLLOW, so a symlink
|
||||
# swapped in cannot redirect the read -- and pinning the exact call expression
|
||||
# made it assert the spelling instead. v0.3.0 moved the first argument from
|
||||
# `src` to `src.at` when directory-relative opens landed, kept O_NOFOLLOW, and
|
||||
# hardened symlink handling further; the literal still refused it. Match the
|
||||
# call and the flag together so a rename cannot read as a removed fix, while
|
||||
# dropping O_NOFOLLOW still fails.
|
||||
if ! grep -Fq 'a.push("--".to_string());' <<<"$archive_rs" ||
|
||||
! grep -Fq 'let input = std::fs::canonicalize(input)' <<<"$archiveops_rs" ||
|
||||
! grep -Fq 'if op != "compress" && op != "extract"' <<<"$run_rs$archivereq_rs" ||
|
||||
! grep -Fq 'the sandbox is unavailable: bwrap or prlimit is not on PATH' <<<"$archivework_rs" ||
|
||||
! grep -Fq 'if !sandbox::available()' <<<"$mediaprobe_rs" ||
|
||||
! grep -Fq 'if !sandbox::available()' <<<"$metareq_rs" ||
|
||||
! grep -Fq 'copyToClipboard.command = ["wl-copy", url]' <<<"$sharelink_qml" ||
|
||||
! grep -Eq 'open_if_regular\(.*O_NOFOLLOW' <<<"$copyfile_rs" ||
|
||||
! grep -Fq '.custom_flags(O_NONBLOCK | extra_flags)' <<<"$regfile_rs"; then
|
||||
printf 'Release %s does not contain every required upstream security fix\n' "$best_tag" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
jq -n \
|
||||
--arg pkgver "$best_version" \
|
||||
--arg published_at "$best_published_at" \
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Maintainer: GM <gianmarcomorales@icloud.com>
|
||||
|
||||
pkgname=flea
|
||||
pkgver=0.3.4
|
||||
pkgver=0.3.5
|
||||
pkgrel=1
|
||||
pkgdesc='Fast, keyboard-first file manager for Omarchy'
|
||||
arch=('x86_64' 'aarch64')
|
||||
@@ -52,7 +52,7 @@ options=('!debug')
|
||||
source=(
|
||||
"$url/releases/download/v$pkgver/$pkgname-v$pkgver.tar.gz"
|
||||
)
|
||||
sha256sums=('e5ad258126ae796d262b51254bfbd4a768416ae4d02da772663e6e24c90cdfe4')
|
||||
sha256sums=('947bd1ad17238e6402af044f848662a4c20e9a82e5a61062ef2e10bb6c2d4cfe')
|
||||
|
||||
build() {
|
||||
cd "$pkgname-$pkgver"
|
||||
|
||||
Reference in new issue
Block a user