fix(install): reject empty or non-hex #sha256= annotations - #56
Merged
Conversation
A present-but-empty '#sha256=' pin previously set BASHDEP_DEP_SHA empty, which download_url treats as 'no pin' — silently skipping the verification the caller asked for. _classify_dep now rejects an empty or non-hex annotation up front (returning non-zero, propagated by _install_one), so a malformed pin fails loudly instead of installing unverified. Follow-up to the checksum-verification feature.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the opt-in checksum feature (#38), flagged by the weak-typing audit as a deferred footgun.
A present-but-empty pin —
https://example.com/tool#sha256=— setBASHDEP_DEP_SHA="", whichdownload_urlreads as no pin and silently skips verification the caller explicitly requested._classify_depnow validates the annotation: empty or non-hex → error + non-zero (propagated by_install_one), so a malformed pin fails before download instead of installing unverified. (Non-hex previously fail-safed at the mismatch stage; now it's rejected earlier, and empty is caught too.)Test plan
install_rejects_bad_checksum_annotationstill passes (now rejected at classify — rc 1, no file)make sa+make lintclean; behavior.md + CHANGELOG (unreleased checksum bullet) updated