fix: verify staged vendor payloads before install - #528
codeforester merged 2 commits into
Conversation
|
Multi-angle review of this PR (fix: verify staged vendor payloads before install). This is a security-hardening PR, so I pushed hard on it — five findings, ranked by severity: 1. Path traversal isn't actually rejected in the new manifest-driven copy path. 2. The new checks only lstat the final path component, not intermediate directories — a gap the same PR explicitly defends against elsewhere. The PR adds a test ("standalone refuses leaf and parent symlink swaps during payload copy") proving parent-directory symlink swaps matter for application-payload copying, and 3. 4. Several of the new tamper-detection branches fail silently, unlike every sibling check in the same function. The new pre-loop guard ( 5. Root cause tying 1, 2, and 4 together: this is now the third independent reimplementation of "hash every file against MANIFEST.sha256" in this script/repo, alongside |
|
Two more concrete issues surfaced by a follow-up pass, additional to the five above: 6. 7. The two |
|
Addressed in 3f2893a. The vendor path now uses a shared manifest validator (safe relative paths and every path component free of symlinks), snapshots and validates manifest entries with diagnostics, and fully verifies both standalone framework copies. Their manifest identities are compared before application payload restoration; framework_lock now binds the canonical nested copy; and the root manifest refreshes its intentional application VERSION override before final verification. Added regression coverage and updated the standalone workflow documentation. Local ./tests/validate.sh passed all 683 tests and contract stages. |
|
Confirmed fixed — re-verified with live reproductions, not just reading the diff (worktree at
|
Summary
Issue
Fixes #526
Validation
bats tests/vendor.bats(10 tests passed)../tests/validate.sh(683 tests passed; artifact, release, concurrency, and quality contracts passed).shellcheck --shell=bash --severity=warning scripts/vendor tests/vendor.batsbash -n scripts/vendorgit diff --checkSecurity Notes
The install now rejects source mutation, copied-byte mismatch, and manifest mismatch before replacing the destination. Incomplete staging trees are cleaned up and no network or bundle-data evaluation was introduced.