fix(selfupdate): verify the archive before replacing the binary
`mdrs selfupdate` replaced the running binary with whatever the release endpoint returned, checking only that the transport succeeded. Nothing proved the archive was the one the release publishes. - Compare the downloaded archive against the release's `.sha256` asset and abort the update on a mismatch. - Report a release that publishes no checksum as unverified, rather than letting its absence pass for a verified download. - Exclude `.sha256` assets when matching the archive for the build target: those assets carry the target name too. - Write and upload a checksum beside every archive, from the Gitea release workflow and the three local build scripts.
This commit is contained in:
@@ -58,7 +58,10 @@ for TARGET in "${TARGETS[@]}"; do
|
||||
|
||||
ARCHIVE="mdrs-${VERSION}-${TARGET}.tar.gz"
|
||||
tar -czf "${ARCHIVE}" -C "target/${TARGET}/release" mdrs
|
||||
ARCHIVES+=("${ARCHIVE}")
|
||||
# Uploaded alongside the archive so `mdrs selfupdate` can check what it fetched.
|
||||
sha256sum "${ARCHIVE}" > "${ARCHIVE}.sha256" 2>/dev/null \
|
||||
|| shasum -a 256 "${ARCHIVE}" > "${ARCHIVE}.sha256"
|
||||
ARCHIVES+=("${ARCHIVE}" "${ARCHIVE}.sha256")
|
||||
echo " Created: ${ARCHIVE}"
|
||||
done
|
||||
|
||||
|
||||
Reference in New Issue
Block a user