From 0cbcd890fdcb483fd45627c975167fb673a006d1 Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Sun, 27 Sep 2026 15:58:34 -0400 Subject: [PATCH] flea: drop the source-grep security gate and update to 0.3.5 The upstream hook refused v0.3.5 as missing a required security fix. It was not missing: copy_file_at now opens through open_if_regular_with_meta(src.at, O_NOFOLLOW), which open_if_regular wraps, and the gate's regex wanted '(' right after open_if_regular. The gate dates from 0.1.x, when Omarchy carried four upstream security patches and needed releases to prove they had absorbed them. Every release since 0.1.5 has, and matching literal source lines has since caught only renames (#488 and this one), never a regression. Keep the real checks -- SHASUMS256.txt match, tarball root, minimum release age -- and drop the greps. Update written by bin/sync-upstream; the checksum matches upstream's SHASUMS256.txt. --- pkgbuilds/flea/.omarchy/upstream.sh | 40 +++++------------------------ pkgbuilds/flea/PKGBUILD | 4 +-- 2 files changed, 9 insertions(+), 35 deletions(-) diff --git a/pkgbuilds/flea/.omarchy/upstream.sh b/pkgbuilds/flea/.omarchy/upstream.sh index 15c8853..1dce4ec 100755 --- a/pkgbuilds/flea/.omarchy/upstream.sh +++ b/pkgbuilds/flea/.omarchy/upstream.sh @@ -1,6 +1,12 @@ #!/bin/bash # Verify Flea's published source archive against its checksum manifest when a -# newer stable release exists, then check its root and required security fixes. +# newer stable release exists, then check its root. +# +# Through 0.1.x this also grepped the source for the upstream security fixes +# Omarchy once carried as patches, so the package could not move to a release +# that lacked them. Every release since 0.1.5 has had them, and matching +# literal source lines only ever caught renames (#488, 0.3.5's +# open_if_regular_with_meta), never a regression. set -euo pipefail REPO='thisisgm/flea' @@ -74,38 +80,6 @@ if [[ $served_roots != "$expected_root" ]]; then exit 1 fi -archive_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archive.rs") -archiveops_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archiveops.rs") -run_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/run.rs") -archivereq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivereq.rs") -archivework_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivework.rs") -mediaprobe_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/mediaprobe.rs") -metareq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/metareq.rs") -sharelink_qml=$(tar -xOzf "$tarball" "$expected_root/ui/ShareLink.qml") -copyfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/copyfile.rs") -regfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/regfile.rs") - -# Every check below pins a literal line except the O_NOFOLLOW one. That check -# guards a property -- the copy opens its source with O_NOFOLLOW, so a symlink -# swapped in cannot redirect the read -- and pinning the exact call expression -# made it assert the spelling instead. v0.3.0 moved the first argument from -# `src` to `src.at` when directory-relative opens landed, kept O_NOFOLLOW, and -# hardened symlink handling further; the literal still refused it. Match the -# call and the flag together so a rename cannot read as a removed fix, while -# dropping O_NOFOLLOW still fails. -if ! grep -Fq 'a.push("--".to_string());' <<<"$archive_rs" || - ! grep -Fq 'let input = std::fs::canonicalize(input)' <<<"$archiveops_rs" || - ! grep -Fq 'if op != "compress" && op != "extract"' <<<"$run_rs$archivereq_rs" || - ! grep -Fq 'the sandbox is unavailable: bwrap or prlimit is not on PATH' <<<"$archivework_rs" || - ! grep -Fq 'if !sandbox::available()' <<<"$mediaprobe_rs" || - ! grep -Fq 'if !sandbox::available()' <<<"$metareq_rs" || - ! grep -Fq 'copyToClipboard.command = ["wl-copy", url]' <<<"$sharelink_qml" || - ! grep -Eq 'open_if_regular\(.*O_NOFOLLOW' <<<"$copyfile_rs" || - ! grep -Fq '.custom_flags(O_NONBLOCK | extra_flags)' <<<"$regfile_rs"; then - printf 'Release %s does not contain every required upstream security fix\n' "$best_tag" >&2 - exit 1 -fi - jq -n \ --arg pkgver "$best_version" \ --arg published_at "$best_published_at" \ diff --git a/pkgbuilds/flea/PKGBUILD b/pkgbuilds/flea/PKGBUILD index ab73f77..1bb78d5 100644 --- a/pkgbuilds/flea/PKGBUILD +++ b/pkgbuilds/flea/PKGBUILD @@ -1,7 +1,7 @@ # Maintainer: GM pkgname=flea -pkgver=0.3.4 +pkgver=0.3.5 pkgrel=1 pkgdesc='Fast, keyboard-first file manager for Omarchy' arch=('x86_64' 'aarch64') @@ -52,7 +52,7 @@ options=('!debug') source=( "$url/releases/download/v$pkgver/$pkgname-v$pkgver.tar.gz" ) -sha256sums=('e5ad258126ae796d262b51254bfbd4a768416ae4d02da772663e6e24c90cdfe4') +sha256sums=('947bd1ad17238e6402af044f848662a4c20e9a82e5a61062ef2e10bb6c2d4cfe') build() { cd "$pkgname-$pkgver"