fix: NUL-delimit verify-build's dist walk so no path escapes the check (closes #223)
All checks were successful
check / check (push) Successful in 43s
All checks were successful
check / check (push) Successful in 43s
check_unlisted_bundles read dist/ line by line, so two unlisted paths carrying a debug marker went unchecked while the script still exited 0: a name with a trailing space (read stripped it and the remnant matched a manifest line) and a name containing a newline (find printed it as a listed path plus an empty one). The walk is now find -print0 into a temporary listing, checked for find's exit status as before, and xargs -0 hands the paths back to this script as arguments, where the same is_listed and has_marker run on them. is_listed also answers "not listed" for any path containing a newline without asking grep, which would otherwise read such a path as two patterns and match on the first half — the escape survives NUL delimiting on its own. dist/ being a symlink is now its own check with its own message. It failed before only because GNU grep exits 2 on a directory, so a grep that exits 1 instead would have turned the whole cross-check into a pass. The comment claiming every file under dist/ is searched now says what is actually guaranteed: every regular file and every symlink, with the four properties that coverage rests on stated as enforced rather than assumed.
This commit is contained in:
4
TODO.md
4
TODO.md
@@ -44,6 +44,10 @@ undefined identifiers, which is how
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-11: `script/verify-build` now walks `dist/` NUL-delimited and asserts
|
||||
`dist/` is a real directory, so a path with a trailing space or a newline can
|
||||
no longer carry a debug marker past the unlisted-bundle check
|
||||
([#223](https://git.eeqj.de/sneak/AutistMask/issues/223)).
|
||||
- 2026-08-11: A dust threshold of `0` now means "hide nothing" instead of
|
||||
falling back to the 100,000 gwei default, and every address comparison in
|
||||
`src/shared/transactions.js` goes through one case-normalising helper so a
|
||||
|
||||
Reference in New Issue
Block a user