Skip to content

Commit 925dfcb

Browse files
committed
Match the exempted config URLs as exact literals
`*f=config.guess*` also matches `f=config.guess.backdoor`, so the exemption still skipped verification on unrelated downloads. Second time a wildcard in this exemption has been wider than intended — a domain glob before, a filename prefix now — so drop wildcards entirely and match the two URLs as literals. There is nothing left to widen: the definitions reference exactly these two fixed strings, anything else is checked. Quoted so `?` and `;` are matched literally rather than as glob and case-clause syntax. If the URLs ever change shape, this list has to be updated by hand, which is the intended cost of skipping verification on a download. Verified the two real URLs still pass and four bypass shapes are caught: config.guess.backdoor, config.subversion, an altered hb parameter, and the same path on another host.
1 parent 15867ed commit 925dfcb

1 file changed

Lines changed: 13 additions & 9 deletions

File tree

‎bin/ci‎

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -132,16 +132,20 @@ lint_checksums() {
132132
while IFS= read -r url; do
133133
url=$(trim_url "$url")
134134
case "$url" in
135-
# The sole exemption, and deliberately spelled out to the exact file rather than
136-
# by domain: config.guess and config.sub come from GNU's git web view, which serves
137-
# a moving HEAD with no release tarball and no published digest. They only teach
138-
# ancient configure scripts about modern architectures and are never linked into
139-
# the built Ruby.
135+
# The only exempt downloads, matched as exact literals. config.guess and config.sub
136+
# come from GNU's git web view, which serves a moving HEAD with no release tarball
137+
# and no published digest. They only teach ancient configure scripts about modern
138+
# architectures and are never linked into the built Ruby.
140139
#
141-
# A domain wildcard here would quietly exempt any other unverified download from
142-
# the same host — re-opening the false-green path this check exists to close.
143-
*git.savannah.gnu.org/gitweb/?p=config.git*f=config.guess*|\
144-
*git.savannah.gnu.org/gitweb/?p=config.git*f=config.sub*) continue ;;
140+
# Literals, not patterns, because every wildcard here is a hole: a domain glob
141+
# exempts anything from the host, and `*f=config.guess*` also exempts
142+
# `f=config.guess.anything`. Both were tried, both were wrong. Quoted so `?` and
143+
# `;` are matched literally rather than as glob and case-clause syntax.
144+
#
145+
# If these URLs ever change shape, this list must be updated by hand — that is the
146+
# intended cost of skipping verification on a download.
147+
"https://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.guess;hb=HEAD"|\
148+
"https://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.sub;hb=HEAD") continue ;;
145149
esac
146150
found=$(( found + 1 ))
147151
[[ $url =~ \#[0-9a-f]{64}$ ]] || { fail "$f: no sha256 on ${url%%\#*}"; ok=false; }

0 commit comments

Comments
 (0)