diff --git a/pkgbuilds/flea/.omarchy/upstream.sh b/pkgbuilds/flea/.omarchy/upstream.sh index 15c8853..1dce4ec 100755 --- a/pkgbuilds/flea/.omarchy/upstream.sh +++ b/pkgbuilds/flea/.omarchy/upstream.sh @@ -1,6 +1,12 @@ #!/bin/bash # Verify Flea's published source archive against its checksum manifest when a -# newer stable release exists, then check its root and required security fixes. +# newer stable release exists, then check its root. +# +# Through 0.1.x this also grepped the source for the upstream security fixes +# Omarchy once carried as patches, so the package could not move to a release +# that lacked them. Every release since 0.1.5 has had them, and matching +# literal source lines only ever caught renames (#488, 0.3.5's +# open_if_regular_with_meta), never a regression. set -euo pipefail REPO='thisisgm/flea' @@ -74,38 +80,6 @@ if [[ $served_roots != "$expected_root" ]]; then exit 1 fi -archive_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archive.rs") -archiveops_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archiveops.rs") -run_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/run.rs") -archivereq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivereq.rs") -archivework_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivework.rs") -mediaprobe_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/mediaprobe.rs") -metareq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/metareq.rs") -sharelink_qml=$(tar -xOzf "$tarball" "$expected_root/ui/ShareLink.qml") -copyfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/copyfile.rs") -regfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/regfile.rs") - -# Every check below pins a literal line except the O_NOFOLLOW one. That check -# guards a property -- the copy opens its source with O_NOFOLLOW, so a symlink -# swapped in cannot redirect the read -- and pinning the exact call expression -# made it assert the spelling instead. v0.3.0 moved the first argument from -# `src` to `src.at` when directory-relative opens landed, kept O_NOFOLLOW, and -# hardened symlink handling further; the literal still refused it. Match the -# call and the flag together so a rename cannot read as a removed fix, while -# dropping O_NOFOLLOW still fails. -if ! grep -Fq 'a.push("--".to_string());' <<<"$archive_rs" || - ! grep -Fq 'let input = std::fs::canonicalize(input)' <<<"$archiveops_rs" || - ! grep -Fq 'if op != "compress" && op != "extract"' <<<"$run_rs$archivereq_rs" || - ! grep -Fq 'the sandbox is unavailable: bwrap or prlimit is not on PATH' <<<"$archivework_rs" || - ! grep -Fq 'if !sandbox::available()' <<<"$mediaprobe_rs" || - ! grep -Fq 'if !sandbox::available()' <<<"$metareq_rs" || - ! grep -Fq 'copyToClipboard.command = ["wl-copy", url]' <<<"$sharelink_qml" || - ! grep -Eq 'open_if_regular\(.*O_NOFOLLOW' <<<"$copyfile_rs" || - ! grep -Fq '.custom_flags(O_NONBLOCK | extra_flags)' <<<"$regfile_rs"; then - printf 'Release %s does not contain every required upstream security fix\n' "$best_tag" >&2 - exit 1 -fi - jq -n \ --arg pkgver "$best_version" \ --arg published_at "$best_published_at" \ diff --git a/pkgbuilds/flea/PKGBUILD b/pkgbuilds/flea/PKGBUILD index ab73f77..1bb78d5 100644 --- a/pkgbuilds/flea/PKGBUILD +++ b/pkgbuilds/flea/PKGBUILD @@ -1,7 +1,7 @@ # Maintainer: GM pkgname=flea -pkgver=0.3.4 +pkgver=0.3.5 pkgrel=1 pkgdesc='Fast, keyboard-first file manager for Omarchy' arch=('x86_64' 'aarch64') @@ -52,7 +52,7 @@ options=('!debug') source=( "$url/releases/download/v$pkgver/$pkgname-v$pkgver.tar.gz" ) -sha256sums=('e5ad258126ae796d262b51254bfbd4a768416ae4d02da772663e6e24c90cdfe4') +sha256sums=('947bd1ad17238e6402af044f848662a4c20e9a82e5a61062ef2e10bb6c2d4cfe') build() { cd "$pkgname-$pkgver"