From 0cbcd890fdcb483fd45627c975167fb673a006d1 Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Sun, 27 Sep 2026 15:58:34 -0400 Subject: [PATCH 1/3] flea: drop the source-grep security gate and update to 0.3.5 The upstream hook refused v0.3.5 as missing a required security fix. It was not missing: copy_file_at now opens through open_if_regular_with_meta(src.at, O_NOFOLLOW), which open_if_regular wraps, and the gate's regex wanted '(' right after open_if_regular. The gate dates from 0.1.x, when Omarchy carried four upstream security patches and needed releases to prove they had absorbed them. Every release since 0.1.5 has, and matching literal source lines has since caught only renames (#488 and this one), never a regression. Keep the real checks -- SHASUMS256.txt match, tarball root, minimum release age -- and drop the greps. Update written by bin/sync-upstream; the checksum matches upstream's SHASUMS256.txt. --- pkgbuilds/flea/.omarchy/upstream.sh | 40 +++++------------------------ pkgbuilds/flea/PKGBUILD | 4 +-- 2 files changed, 9 insertions(+), 35 deletions(-) diff --git a/pkgbuilds/flea/.omarchy/upstream.sh b/pkgbuilds/flea/.omarchy/upstream.sh index 15c8853..1dce4ec 100755 --- a/pkgbuilds/flea/.omarchy/upstream.sh +++ b/pkgbuilds/flea/.omarchy/upstream.sh @@ -1,6 +1,12 @@ #!/bin/bash # Verify Flea's published source archive against its checksum manifest when a -# newer stable release exists, then check its root and required security fixes. +# newer stable release exists, then check its root. +# +# Through 0.1.x this also grepped the source for the upstream security fixes +# Omarchy once carried as patches, so the package could not move to a release +# that lacked them. Every release since 0.1.5 has had them, and matching +# literal source lines only ever caught renames (#488, 0.3.5's +# open_if_regular_with_meta), never a regression. set -euo pipefail REPO='thisisgm/flea' @@ -74,38 +80,6 @@ if [[ $served_roots != "$expected_root" ]]; then exit 1 fi -archive_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archive.rs") -archiveops_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archiveops.rs") -run_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/run.rs") -archivereq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivereq.rs") -archivework_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivework.rs") -mediaprobe_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/mediaprobe.rs") -metareq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/metareq.rs") -sharelink_qml=$(tar -xOzf "$tarball" "$expected_root/ui/ShareLink.qml") -copyfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/copyfile.rs") -regfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/regfile.rs") - -# Every check below pins a literal line except the O_NOFOLLOW one. That check -# guards a property -- the copy opens its source with O_NOFOLLOW, so a symlink -# swapped in cannot redirect the read -- and pinning the exact call expression -# made it assert the spelling instead. v0.3.0 moved the first argument from -# `src` to `src.at` when directory-relative opens landed, kept O_NOFOLLOW, and -# hardened symlink handling further; the literal still refused it. Match the -# call and the flag together so a rename cannot read as a removed fix, while -# dropping O_NOFOLLOW still fails. -if ! grep -Fq 'a.push("--".to_string());' <<<"$archive_rs" || - ! grep -Fq 'let input = std::fs::canonicalize(input)' <<<"$archiveops_rs" || - ! grep -Fq 'if op != "compress" && op != "extract"' <<<"$run_rs$archivereq_rs" || - ! grep -Fq 'the sandbox is unavailable: bwrap or prlimit is not on PATH' <<<"$archivework_rs" || - ! grep -Fq 'if !sandbox::available()' <<<"$mediaprobe_rs" || - ! grep -Fq 'if !sandbox::available()' <<<"$metareq_rs" || - ! grep -Fq 'copyToClipboard.command = ["wl-copy", url]' <<<"$sharelink_qml" || - ! grep -Eq 'open_if_regular\(.*O_NOFOLLOW' <<<"$copyfile_rs" || - ! grep -Fq '.custom_flags(O_NONBLOCK | extra_flags)' <<<"$regfile_rs"; then - printf 'Release %s does not contain every required upstream security fix\n' "$best_tag" >&2 - exit 1 -fi - jq -n \ --arg pkgver "$best_version" \ --arg published_at "$best_published_at" \ diff --git a/pkgbuilds/flea/PKGBUILD b/pkgbuilds/flea/PKGBUILD index ab73f77..1bb78d5 100644 --- a/pkgbuilds/flea/PKGBUILD +++ b/pkgbuilds/flea/PKGBUILD @@ -1,7 +1,7 @@ # Maintainer: GM pkgname=flea -pkgver=0.3.4 +pkgver=0.3.5 pkgrel=1 pkgdesc='Fast, keyboard-first file manager for Omarchy' arch=('x86_64' 'aarch64') @@ -52,7 +52,7 @@ options=('!debug') source=( "$url/releases/download/v$pkgver/$pkgname-v$pkgver.tar.gz" ) -sha256sums=('e5ad258126ae796d262b51254bfbd4a768416ae4d02da772663e6e24c90cdfe4') +sha256sums=('947bd1ad17238e6402af044f848662a4c20e9a82e5a61062ef2e10bb6c2d4cfe') build() { cd "$pkgname-$pkgver" From 0059492899ec403c90298abb3f44d332c7eba8ca Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Sun, 27 Sep 2026 16:09:38 -0400 Subject: [PATCH 2/3] flea: run copymanifest's tests on tmpfs 0.3.5's copymanifest::tests::a_garbage_stream_falls_back_... opens its anonymous (O_TMPFILE) manifest directly in its /tmp test dir, which the x86_64 builder's /tmp refuses with EOPNOTSUPP. The sibling tests pass because Writer::create falls back across directories. Same reason the other filesystem_tests already run on /dev/shm; none of these spawn. --- pkgbuilds/flea/PKGBUILD | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgbuilds/flea/PKGBUILD b/pkgbuilds/flea/PKGBUILD index 1bb78d5..77365f5 100644 --- a/pkgbuilds/flea/PKGBUILD +++ b/pkgbuilds/flea/PKGBUILD @@ -116,6 +116,7 @@ check() { # identical and undo walks it back. tmpfs allocates inode numbers from a # counter and never reuses one, which is what the test assumes. local -a filesystem_tests=( + backend::copymanifest::tests:: backend::menu_actions::tests:: backend::menudelete::tests:: backend::redo::tests:: From 45ae938a58418dde912406e782e21236ef52f700 Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Sun, 27 Sep 2026 20:01:44 -0400 Subject: [PATCH 3/3] flea: put only copymanifest's O_TMPFILE test on tmpfs Moving the whole module broke the rest of it: Writer::create needs a runtime directory on a different filesystem from the copy, and with the test root on /dev/shm none qualifies. Only a_garbage_stream_falls_back_with_the_tree_untouched opens its manifest in its own test dir, which the builder's /tmp refuses (EOPNOTSUPP). --- pkgbuilds/flea/PKGBUILD | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pkgbuilds/flea/PKGBUILD b/pkgbuilds/flea/PKGBUILD index 77365f5..23c3674 100644 --- a/pkgbuilds/flea/PKGBUILD +++ b/pkgbuilds/flea/PKGBUILD @@ -115,8 +115,12 @@ check() { # back to the next create, so on the builder's /tmp the stranger is # identical and undo walks it back. tmpfs allocates inode numbers from a # counter and never reuses one, which is what the test assumes. + # copymanifest's garbage-stream test opens its O_TMPFILE manifest in its + # own test dir; the module's other tests must stay off tmpfs, because + # Writer::create wants a runtime dir on a different filesystem from the + # copy and finds none when both live on /dev/shm. local -a filesystem_tests=( - backend::copymanifest::tests:: + backend::copymanifest::tests::a_garbage_stream_falls_back_with_the_tree_untouched backend::menu_actions::tests:: backend::menudelete::tests:: backend::redo::tests::