Make the upstream rewrite verify its own result
A second review pass found the PKGBUILD rewriting could still go wrong in ways the pattern matching did not anticipate: an array element carrying a ")" in a comment left the tail of the old array behind, and jq's "$" also matches before a trailing newline, so a pkgver of "1.0\n" passed validation and then broke sed after the checksum arrays had already been written. Rather than chase each shape, prove the result. Every edit now lands on a scratch copy that is parsed with bash -n and read back to confirm it holds the version and checksums we meant to write, and only then replaces the PKGBUILD in a single rename. Corruption that slips past the matching fails loudly with the original untouched instead of landing in a pull request. The validation anchors are \A and \z accordingly, empty checksum lists are rejected rather than written as '', and the hook picks the newest stanza with vercmp so it agrees with the comparator the updater uses. Also stop the launcher probing /.config when HOME and XDG_CONFIG_HOME are both unset, and require a regular file, so a directory at that path is skipped instead of crashing the app on startup. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
1a61278911
commit
f92de9c440
@@ -9,17 +9,28 @@ set -euo pipefail
|
||||
BASE_URL="https://persistent.oaistatic.com/codex-app-prod/linux/deb"
|
||||
declare -A DEB_ARCHES=([x86_64]=amd64 [aarch64]=arm64)
|
||||
|
||||
# Print "<version> <sha256>" for the newest stanza in a Packages index.
|
||||
# Print "<version> <sha256>" for the newest stanza in a Packages index. Newest
|
||||
# is vercmp's opinion, which is the one bin/sync-upstream and pacman both use;
|
||||
# sort -V disagrees with it over versions like 1.0a.
|
||||
newest_release() {
|
||||
local index="$1"
|
||||
local version sha256 best_version="" best_sha256=""
|
||||
|
||||
awk '
|
||||
while read -r version sha256; do
|
||||
if [[ -z "$best_version" ]] || [[ "$(vercmp "$version" "$best_version")" -gt 0 ]]; then
|
||||
best_version="$version"
|
||||
best_sha256="$sha256"
|
||||
fi
|
||||
done < <(awk '
|
||||
{ sub(/\r$/, "") }
|
||||
/^Version:/ { version = $2 }
|
||||
/^SHA256:/ { sha256 = $2 }
|
||||
/^$/ { if (version && sha256) print version, sha256; version = sha256 = "" }
|
||||
END { if (version && sha256) print version, sha256 }
|
||||
' <<<"$index" | sort -V | tail -n 1
|
||||
' <<<"$index")
|
||||
|
||||
[[ -n "$best_version" ]] || return 1
|
||||
echo "$best_version $best_sha256"
|
||||
}
|
||||
|
||||
versions=()
|
||||
|
||||
@@ -70,7 +70,7 @@ _pool="https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/cha
|
||||
source_x86_64=("${_deb_x86_64}::${_pool}/${_deb_x86_64}")
|
||||
source_aarch64=("${_deb_aarch64}::${_pool}/${_deb_aarch64}")
|
||||
noextract=("${_deb_x86_64}" "${_deb_aarch64}")
|
||||
sha256sums=('fc70527cd961f3a660e2a9d0a2d62b1e3f7a61d8482ee1935a6b25307da278eb')
|
||||
sha256sums=('b3a4503b5931f102444bc7015c3cf4e40266cf034e0d682bd2a407dc5b3ee58c')
|
||||
sha256sums_x86_64=('708a15a1bb76e2bb7f0e376e5145391fa277ad3a64057c1d32537bdc2a1b4e6e')
|
||||
sha256sums_aarch64=('6ebea681b1e494d218a199f638b4bc886e94e1458dd61079b1e390a6fb98fdd2')
|
||||
|
||||
|
||||
@@ -2,9 +2,11 @@
|
||||
set -euo pipefail
|
||||
|
||||
user_flags=()
|
||||
flags_file="${XDG_CONFIG_HOME:-${HOME:-}/.config}/codex-flags.conf"
|
||||
config_home="${XDG_CONFIG_HOME:-}"
|
||||
[[ -n "$config_home" || -z "${HOME:-}" ]] || config_home="$HOME/.config"
|
||||
flags_file="${config_home:+$config_home/codex-flags.conf}"
|
||||
|
||||
if [[ -r "$flags_file" ]]; then
|
||||
if [[ -n "$flags_file" && -f "$flags_file" && -r "$flags_file" ]]; then
|
||||
while IFS= read -r line || [[ -n "$line" ]]; do
|
||||
line="${line%%#*}"
|
||||
[[ -n "${line//[[:space:]]/}" ]] || continue
|
||||
|
||||
Reference in New Issue
Block a user