The root-run package hook changed ownership of paths below a user-controlled home directory. A config symlink could redirect chown to an arbitrary root-owned file during installation or upgrade. Run the config writer as the target desktop user and remove the privileged ownership changes. This also prevents the missing-config path from writing through a user-controlled pathname as root. Add regression coverage and bump the package release. Reported-by: piratemoo (Esther) <22439214+piratemoo@users.noreply.github.com> Link: https://github.com/piratemoo/Arbitrary-File-Ownership-Change-via-Symlink-LPE
52 lines
1.5 KiB
YAML
52 lines
1.5 KiB
YAML
name: Tests
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches: [master]
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
build-isolation:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
- name: Prepare fixture builder
|
|
run: docker build -t omarchy-build-isolation-test -f tests/build-isolation.Dockerfile tests
|
|
- name: Verify isolated builds with real pacman transactions
|
|
env:
|
|
CONTAINER_ENGINE: docker
|
|
TEST_BUILDER_IMAGE: omarchy-build-isolation-test
|
|
run: tests/build-isolation.sh
|
|
|
|
self-tests:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# An Arch container for vercmp: version ordering has to be decided by
|
|
# the same comparator pacman uses on users' machines.
|
|
- name: Run self-tests
|
|
run: |
|
|
docker run --rm \
|
|
-v "$PWD:/workspace:ro" \
|
|
-w /workspace \
|
|
archlinux:base-devel bash -lc '
|
|
set -euo pipefail
|
|
pacman -Syu --noconfirm git jq python libarchive
|
|
python tests/upstream-watch.py
|
|
./bin/sync-upstream self-test
|
|
./bin/sync-rebuilds --self-test
|
|
./bin/omarchy-pkgs self-test
|
|
./bin/omarchy-release self-test
|
|
./tests/dell-xps-touchpad-haptics-install.sh
|
|
./tests/partial-release.sh
|
|
./tests/published-build-plan.sh
|
|
'
|