Skip to content

Releases: katoptra/lib

v2.2.1

Choose a tag to compare

@jshvn jshvn released this 01 Oct 04:32
f7b2a87

What's Changed

  • fix(rsync): fetch the file a re-signed sha512 names by @jshvn in #13

Full Changelog: v2.2.0...v2.2.1

v2.2.0

Choose a tag to compare

@jshvn jshvn released this 01 Oct 04:32
fe81623

What's Changed

  • docs(readme): open with the katoptra mark, linked to the org by @jshvn in #9
  • docs: name katoptra/dispatch as the scheduler by @jshvn in #10
  • chore(deps): bump the actions group with 3 updates by @dependabot[bot] in #11
  • feat(toolbox): reconcile by the age of the last one, not the hour by @jshvn in #12

New Contributors

Full Changelog: v2.1.3...v2.2.0

v2.1.3

Choose a tag to compare

@jshvn jshvn released this 01 Oct 04:32
f6343cd

What's Changed

  • fix(sync): chain names the caller's file, the @ref cut before the path by @jshvn in #8

Full Changelog: v2.1.2...v2.1.3

v2.1.2

Choose a tag to compare

@jshvn jshvn released this 01 Oct 04:32
46abc9d

What's Changed

  • chore(docker): gpgv alone, no pip, botocore trimmed, gha build cache by @jshvn in #7

Full Changelog: v2.1.1...v2.1.2

v2.1.1

Choose a tag to compare

@jshvn jshvn released this 01 Oct 04:31
d9f16ac

What's Changed

  • docs(readme): the manual, with every stage drawn by @jshvn in #5
  • fix(engine): retry passes rsync exit 23, a dangling symlink under -L by @jshvn in #6

Full Changelog: v2.1.0...v2.1.1

v2.1.0

Choose a tag to compare

@jshvn jshvn released this 01 Oct 04:31
a6825c6

What's Changed

  • docs: point examples at katoptra.org hosts by @jshvn in #3
  • feat(engine): the proton engine, and git in the proton image by @jshvn in #4

Full Changelog: v2.0.1...v2.1.0

v2.0.1

Choose a tag to compare

@jshvn jshvn released this 09 Sep 05:47
7b7d117

Two supply-chain fixes from the security review of 2026-09-08.

The AWS CLI is verified before it is installed. It was the only tool in
toolchain.lock.toml carrying no checksum, installed with curl, unzip and
./aws/install as root, and it is the binary that receives the R2 credentials on every
upload. AWS publishes no checksum for the v2 Linux installer, only a detached PGP
signature, so the fetch stage now verifies that signature through the same
GOODSIG-and-VALIDSIG gate the engine uses for TeX Live, against the key committed at
docker/aws-cli.pub and the fingerprint pinned in the lock. gpgv's own verdict is not
the gate: a zip signed by any other valid key still reports a good signature, and only
the fingerprint comparison refuses it.

That key expires 2027-07-01. An expired key is EXPKEYSIG, not GOODSIG, so builds
after that date fail closed until docker/aws-cli.pub is refreshed from the AWS CLI
User Guide.

The sync workflow refuses a hostile vars input. Its words become go-task call
variables, which the engine splices into shell as raw text, so a crafted RECONCILE or
BATCH_GB could run arbitrary commands in the step that had already exported every
inherited secret, including the R2 credentials and OP_SERVICE_ACCOUNT_TOKEN. A word
that is not a bare upper-case key and a plain value is now refused at the boundary, in a
step that holds no secrets. reconcile's status quotes its value as well. BATCH_GB
lands inside $(( )), where a quoted operand is a syntax error, so it stays bare and
carries a ponytail: comment naming what protects it.

Each guard's own cases run in CI and prove what it refuses; the image build proves what
the signature gate accepts.

No mirror needs a change. Neither fix alters a rendered command, so render.txt in
ctan and tlnet still matches, and the rollout is the v2 tag as usual.