Skip to content

Decksmith v0.1.0-preview.2 — security hardening

Pre-release
Pre-release

Choose a tag to compare

@infamous-pattern infamous-pattern released this 22 Sep 16:57

Security-hardened follow-up to the first public preview. Preview.1 remains available for traceability; new installations should use preview.2.

Fixes

  • Require complete checksum coverage before executing downloaded installer files; reject incomplete, duplicate and malformed manifests.
  • Reject SVG document types at the XML parser level, including UTF-16 encodings.
  • Restrict website-icon redirects to anonymous HTTP(S) requests.
  • Require authorization for the optional Homebridge panel entry page and state endpoint.
  • Remove private build-machine paths from release executables; enforce this during packaging.

Install (Fedora x86_64)

curl -fsSL https://raw.githubusercontent.com/infamous-pattern/decksmith/v0.1.0-preview.2/scripts/install.sh | sh

The installer preserves layouts and leaves login startup unchanged. It asks DNF to install missing dependencies. Review the script or use the manual INSTALL.md instructions if preferred.

Review evidence

The release includes SECURITY-REVIEW.md and dependency-inventory.json. Main Rust dependency auditing, the optional companion's retained Rust source audit, and its pinned WebSocket dependency audit reported no known vulnerabilities. Native tests cover malformed downloads, XML encodings, redirect restrictions and real loopback HTTP authorization. Published binaries have PIE, full RELRO and non-executable stacks. The rebuilt runtime passed Fedora 44 installation and resource checks.

The experimental Homebridge companion is installed and updated separately. Updating the main app does not update an existing companion; its authorization fix must be included in a companion rebuild. General plugin support remains planned for V1.5.

This engineering review is not an independent penetration-test certification. Releases remain unsigned, Fedora manages system libraries, and plugins run with desktop-user permissions. See the full review for scope and remaining boundaries.

Report a vulnerability privately · Support Decksmith