Repository navigation
security(upgrade): harden self-update and installer verification - #572
Merged
Merged
Conversation
Exact-match checksum lookup, random 0700 temp dir, extract only the regular-file binary entry (reject symlink/hardlink), request timeouts and size caps, no-redirect version probe with tag validation, and require an explicit ack to skip checksums. install.sh now fails closed on missing checksums, falls back to shasum, and rejects link entries. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
This was referenced Oct 8, 2026
ajianaz
added a commit
that referenced
this pull request
Oct 8, 2026
) Covers security hardening (#563, #572, #573), fixes (#553, #561, #562, #564, #565, #574-#576), and the ignore-pattern semantic changes from #577 that can alter which files existing configs exclude. Signed-off-by: ajianaz <ajianaz@users.noreply.github.com> Co-authored-by: ajianaz <ajianaz@users.noreply.github.com> Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
This was referenced Oct 8, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Hardens
cora upgradeandinstall.sh: exact checksum matching, safe temp dir and extraction, bounded/time-limited downloads, and no silent checksum skip.Why
Security review found several weak spots in the update path: substring checksum matching, a predictable
/tmp/cora-update-{version}dir, full-archiveunpack(symlink/hardlink entries), no timeouts or size caps, a single env var that silently disabled verification, and an installer that failed open when checksums were missing.How
parse_checksum: exact filename equality after trimming a leading*or./(no morecontains).tempfile::tempdir()(random, 0700, cleaned on drop).tempfilemoved from dev-dependencies to dependencies.extract_binary: rejects any symlink/hardlink or unsafe-path entry, extracts only the single regular-filecoraentry (size capped).connect_timeout+timeout, streamed body with a hard size cap (256 MiB archive, 1 MiB checksums/API JSON),redirect(Policy::none())for the/releases/latestLocation probe, and release tags validated (vX.Y.Z..., safe chars) before being used in URLs.CORA_UPGRADE_SKIP_CHECKSUMnow errors unlessCORA_UPGRADE_I_UNDERSTAND=1is also set; when both are set a loud warning is printed. Not removed.install.sh: verification is mandatory (missing checksums file or entry is fatal) unlessCORA_SKIP_CHECKSUM=1; exact filename match;shasum -a 256fallback; rejects symlink/hardlink entries; extracts only the binary entry.Follow-up (not in this PR): signature verification (cosign/minisign) once there is key infrastructure.
Testing
cargo test --features tree-sitterpassescargo fmt --all -- --checkpassescargo clippy --all-targets --features tree-sitter -- -D warningspassescargo build --release --features tree-sitterpasses (not run; local disk was full)sh -n install.sh, awk checksum extraction checked against*nameand.siglinesNew unit tests: exact checksum matching, skip-checksum gating, tag validation, tar extraction (regular file only, symlink/hardlink rejection, symlink named
cora, missing binary). Network paths are not unit tested.Related Issues
None.
Checklist
security/)develop🤖 Generated with Claude Code