WIP: Paused over-hardening fix wave (boot checkout verification, double-read package manifest)
This commit is contained in:
@@ -53,7 +53,12 @@ if [[ "${PANAMA_NVIDIA:-no}" == yes ]]; then
|
||||
warn "Secure Boot question, or disable Secure Boot first."
|
||||
else
|
||||
log "Installing the NVIDIA driver"
|
||||
if sudo dnf install -y akmod-nvidia xorg-x11-drv-nvidia-cuda; then
|
||||
if sudo dnf install -y \
|
||||
--repo=fedora --repo=updates \
|
||||
--repo=rpmfusion-free --repo=rpmfusion-free-updates \
|
||||
--repo=rpmfusion-nonfree --repo=rpmfusion-nonfree-updates \
|
||||
--from-repo=rpmfusion-nonfree,rpmfusion-nonfree-updates \
|
||||
akmod-nvidia xorg-x11-drv-nvidia-cuda; then
|
||||
# nouveau has to be out of the way before the kernel would otherwise
|
||||
# bind it, which is why these are kernel arguments and not a modprobe
|
||||
# drop-in. modeset=1 is what makes the Wayland session work at all.
|
||||
|
||||
+699
-174
File diff suppressed because it is too large
Load Diff
@@ -6,6 +6,75 @@
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
_collect_vicinae_inputs() {
|
||||
local extension="$1" output="$2"
|
||||
[[ -d "$extension" && ! -L "$extension" \
|
||||
&& -f "$extension/package.json" && ! -L "$extension/package.json" \
|
||||
&& -f "$extension/package-lock.json" && ! -L "$extension/package-lock.json" ]] \
|
||||
|| return 1
|
||||
|
||||
# Everything authored below the extension affects its build. npm's
|
||||
# dependency tree is the sole exception and is reproduced from the lock.
|
||||
find "$extension" -mindepth 1 \
|
||||
\( -path "$extension/node_modules" -prune \) -o \
|
||||
! -type d -print0 >"$output" || return 1
|
||||
LC_ALL=C sort -z -o "$output" "$output" || return 1
|
||||
}
|
||||
|
||||
_write_vicinae_manifest() {
|
||||
local extension="$1" inputs="$2" output="$3"
|
||||
local input relative digest
|
||||
: >"$output" || return 1
|
||||
while IFS= read -r -d '' input; do
|
||||
[[ -f "$input" && ! -L "$input" && -r "$input" ]] || return 1
|
||||
relative="${input#"$extension"/}"
|
||||
[[ "$relative" != "$input" && -n "$relative" ]] || return 1
|
||||
digest="$(sha256sum -- "$input" | awk '{ print $1 }')" || return 1
|
||||
[[ "$digest" =~ ^[0-9a-f]{64}$ ]] || return 1
|
||||
printf '%s\0%s\0' "$relative" "$digest" >>"$output" || return 1
|
||||
done <"$inputs"
|
||||
}
|
||||
|
||||
_vicinae_extension_digest() (
|
||||
local extension="${1%/}" work=""
|
||||
trap '[[ -z "$work" ]] || rm -rf -- "$work"' EXIT
|
||||
trap 'exit 130' INT
|
||||
trap 'exit 143' TERM
|
||||
work="$(mktemp -u -d -t panama-vicinae-digest.XXXXXX)" || exit 1
|
||||
if ! mkdir -m 700 -- "$work"; then
|
||||
work=""
|
||||
exit 1
|
||||
fi
|
||||
|
||||
_collect_vicinae_inputs "$extension" "$work/inputs.before" || exit 1
|
||||
_write_vicinae_manifest \
|
||||
"$extension" "$work/inputs.before" "$work/manifest.before" || exit 1
|
||||
_collect_vicinae_inputs "$extension" "$work/inputs.after" || exit 1
|
||||
_write_vicinae_manifest \
|
||||
"$extension" "$work/inputs.after" "$work/manifest.after" || exit 1
|
||||
cmp -s -- "$work/inputs.before" "$work/inputs.after" || exit 1
|
||||
cmp -s -- "$work/manifest.before" "$work/manifest.after" || exit 1
|
||||
sha256sum -- "$work/manifest.before" | awk '{ print $1 }'
|
||||
)
|
||||
|
||||
_record_vicinae_digest() (
|
||||
local built="$1" digest="$2" receipt temporary=""
|
||||
trap '[[ -z "$temporary" ]] || rm -f -- "$temporary"' EXIT
|
||||
trap 'exit 130' INT
|
||||
trap 'exit 143' TERM
|
||||
[[ -d "$built" && ! -L "$built" ]] || exit 1
|
||||
receipt="$built/.panama-source-sha256"
|
||||
temporary="$(mktemp -u "$built/.panama-source-sha256.XXXXXX")" || exit 1
|
||||
umask 077
|
||||
if ! (set -o noclobber; : >"$temporary") 2>/dev/null; then
|
||||
temporary=""
|
||||
exit 1
|
||||
fi
|
||||
printf '%s\n' "$digest" >"$temporary" || exit 1
|
||||
mv -f -- "$temporary" "$receipt" || exit 1
|
||||
temporary=""
|
||||
)
|
||||
|
||||
panama_path="${PANAMA_PATH:-$HOME/.local/share/Panama}"
|
||||
vicinae_data_dir="${VICINAE_DATA_DIR:-$HOME/.local/share/vicinae}"
|
||||
source_dir="$panama_path/config/local/share/vicinae/scripts"
|
||||
@@ -81,18 +150,36 @@ if [[ -d "$extensions_source" ]] && command -v npm >/dev/null 2>&1; then
|
||||
[[ -f "$extension/package.json" ]] || continue
|
||||
name="$(basename "$extension")"
|
||||
|
||||
# Skip a build that would produce what is already there. `npm ci`
|
||||
# alone takes long enough to be worth not repeating on every re-run of
|
||||
# a stage that is otherwise nearly instant.
|
||||
# Skip only when a prior successful build records the digest of both
|
||||
# manifests and every source byte. Directory mtimes do not change when
|
||||
# an existing source file is edited.
|
||||
built="$vicinae_data_dir/extensions/$name"
|
||||
if [[ -d "$built" && "$extension/src" -ot "$built" ]]; then
|
||||
receipt="$built/.panama-source-sha256"
|
||||
if ! source_digest="$(_vicinae_extension_digest "$extension")"; then
|
||||
printf 'Vicinae extension %s inputs could not be verified; skipping\n' \
|
||||
"$name" >&2
|
||||
continue
|
||||
fi
|
||||
if [[ -f "$receipt" && ! -L "$receipt" ]] \
|
||||
&& cmp -s <(printf '%s\n' "$source_digest") "$receipt"; then
|
||||
printf 'Vicinae extension %s is already built\n' "$name"
|
||||
continue
|
||||
fi
|
||||
|
||||
printf 'Building Vicinae extension %s\n' "$name"
|
||||
if ! (cd "$extension" && npm ci --silent >/dev/null 2>&1 && npm run build >/dev/null 2>&1); then
|
||||
if ! (cd "$extension" && npm ci --silent >/dev/null 2>&1 \
|
||||
&& npm run build >/dev/null 2>&1); then
|
||||
printf 'Vicinae extension %s did not build; skipping\n' "$name" >&2
|
||||
continue
|
||||
fi
|
||||
if ! final_digest="$(_vicinae_extension_digest "$extension")" \
|
||||
|| [[ "$final_digest" != "$source_digest" ]]; then
|
||||
printf 'Vicinae extension %s changed while building; receipt withheld\n' \
|
||||
"$name" >&2
|
||||
continue
|
||||
fi
|
||||
if ! _record_vicinae_digest "$built" "$source_digest"; then
|
||||
printf 'Vicinae extension %s receipt could not be recorded\n' "$name" >&2
|
||||
fi
|
||||
done
|
||||
elif [[ -d "$extensions_source" ]]; then
|
||||
|
||||
Reference in New Issue
Block a user