Review fixes (19 findings)
All findings from the v0.0.10-v0.0.12 code review addressed.
Security
| Fix |
Extension |
Module name validation (^[a-zA-Z0-9_-]+$) |
kernelmodule |
| Cron newline/null injection validation |
cron |
| HTTP redirect restriction (3 max, cross-host blocked) |
file (remote mode) |
gpgcheck=1 default for dnf/yum repos |
repository |
COM errors.As for OleError type safety |
cron (Windows) |
Correctness
| Fix |
Extension |
| Content+URL mutual exclusion error |
file |
Case-insensitive checksum (strings.EqualFold) |
file (remote mode) |
applyBlock respects Mode field |
file (block mode) |
| Exact block marker matching (no TrimSpace) |
file (block mode) |
isModuleLoaded error propagated in Apply |
kernelmodule |
isModuleBlacklisted returns (bool, error) |
kernelmodule |
errors.Is(fs.ErrNotExist) consistency |
kernelmodule |
ShellParams=[]string{} gets defaults |
exec |
resolveShell returns 3 values (no double resolution) |
exec |
Shared alreadySet() guard: skip Apply when hostname matches |
hostname |
Test coverage
| Extension |
Tests added |
| file (remote mode) |
7 tests: check missing/match/mismatch, apply+verify, checksum reject, requires checksum, mutual exclusion |
| file (block mode) |
9 tests: check missing/sync/drift, converges, insert, update, remove, missing end marker, mode |
| file (helpers) |
3 table-driven: extractBlock, upsertBlock, removeBlock |
| kernelmodule |
9 validation cases: valid names, path traversal, injection, empty |
Docs
| Change |
| Nested navigation links at top of examples.md |
| design.md: hardcoded extension list replaced with directory link |
What's Changed
- Propagate native exe exit codes from PowerShell by @TsekNet in #23
- Fix all review findings from v0.0.10-v0.0.12 by @TsekNet in #25
Full Changelog: v0.0.12...v0.0.13