Compare commits

..
Author SHA1 Message Date
Pierre Dubouilh b8bfc21902 mpr 2024-08-30 14:41:03 +02:00
Pierre Dubouilh cd6122b393 bump go to 1.23.0 & fixup build reproducibility 2024-08-30 14:40:50 +02:00
8 changed files with 104 additions and 76 deletions
+9 -4
View File
@@ -6,15 +6,20 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@v1
with:
go-version: 1.23.0
id: go
- name: deps
run: npm i -g standard
- name: Check out code into the Go module directory
uses: actions/checkout@v1
with:
submodules: true
- name: Run
run: make ci
+17 -11
View File
@@ -10,25 +10,33 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v1
with:
submodules: true
- name: Set up Go
uses: actions/setup-go@v1
with:
go-version: 1.23.0
id: go
- name: Set env
run: echo "GIT_TAG=`echo $(git describe --tags --abbrev=0)`" >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@v1.2.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1.6.0
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@v1.10.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and release on dockerhub
uses: docker/build-push-action@v6
uses: docker/build-push-action@v2.7.0
with:
file: support/build.Dockerfile
push: true
@@ -39,19 +47,17 @@ jobs:
run: make build-all
- name: "Release gh release versioned"
uses: ncipollo/release-action@v1
uses: ncipollo/release-action@58ae73b360456532aafd58ee170c045abbeaee37
with:
allowUpdates: true
artifacts: "builds/*"
bodyFile: "builds/buildout"
token: ${{ secrets.GITHUB_TOKEN }}
- name: "Release gh release latest"
uses: ncipollo/release-action@v1
uses: ncipollo/release-action@58ae73b360456532aafd58ee170c045abbeaee37
with:
tag: latest
name: Latest
allowUpdates: true
artifacts: "builds/*"
bodyFile: "builds/buildout"
token: ${{ secrets.GITHUB_TOKEN }}
+39
View File
@@ -0,0 +1,39 @@
name: rc
on:
push:
branches:
- 'rc/**'
jobs:
build:
name: Build
runs-on: ubuntu-latest
steps:
- name: Set up Go
uses: actions/setup-go@v1
with:
go-version: 1.23.0
id: go
- name: Check out code into the Go module directory
uses: actions/checkout@v1
with:
submodules: true
- name: Run
run: make ci
- name: Build all artifacts
run: make build-all
- name: "Release gh release prerelease"
uses: ncipollo/release-action@58ae73b360456532aafd58ee170c045abbeaee37
with:
allowUpdates: true
prerelease: true
tag: "rc"
artifacts: "builds/*"
token: ${{ secrets.GITHUB_TOKEN }}
+5 -2
View File
@@ -17,7 +17,10 @@ run-ro::
run-extra::
./gossa -verb=true -prefix="/fancy-path/" -k=false -symlinks=true test-fixture
ci:: build-all test
lint-js::
standard
ci:: build-all test lint-js
echo "done"
test::
@@ -63,7 +66,7 @@ build-all:: build
${NOCGO} GOOS=darwin GOARCH=amd64 go build ${FLAGS} -o builds/gossa-mac-x64
${NOCGO} GOOS=darwin GOARCH=arm64 go build ${FLAGS} -o builds/gossa-mac-arm64
${NOCGO} GOOS=windows GOARCH=amd64 go build ${FLAGS} -o builds/gossa-windows.exe
sha256sum builds/* | tee builds/buildout
sha256sum builds/*
clean::
rm -f gossa
+20 -32
View File
@@ -45,6 +45,11 @@ var verb = flag.Bool("verb", false, "verbosity")
var skipHidden = flag.Bool("k", true, "\nskip hidden files")
var ro = flag.Bool("ro", false, "read only mode (no upload, rename, move, etc...)")
type rpcCall struct {
Call string `json:"call"`
Args []string `json:"args"`
}
var rootPath = ""
var handler http.Handler
@@ -129,7 +134,7 @@ func replyList(w http.ResponseWriter, r *http.Request, fullPath string, path str
if strings.Contains(r.Header.Get("Accept-Encoding"), "gzip") {
w.Header().Set("Content-Type", "text/html")
w.Header().Add("Content-Encoding", "gzip")
gz, err := gzip.NewWriterLevel(w, gzip.BestSpeed) // BestSpeed is Much Faster than default - base on a very unscientific local test
gz, err := gzip.NewWriterLevel(w, gzip.BestSpeed) // BestSpeed is Much Faster than default - base on a very unscientific local test, and only ~30% larger (compression remains still very effective, ~6x)
check(err)
defer gz.Close()
tmpl.Execute(gz, p)
@@ -146,8 +151,7 @@ func doContent(w http.ResponseWriter, r *http.Request) {
path := html.UnescapeString(r.URL.Path)
defer exitPath(w, "get content", path)
fullPath, err := enforcePath(path)
check(err)
fullPath := enforcePath(path)
stat, errStat := os.Stat(fullPath)
check(errStat)
@@ -170,9 +174,7 @@ func upload(w http.ResponseWriter, r *http.Request) {
if err != nil && err != io.EOF { // errs EOF when no more parts to process
check(err)
}
path, err = enforcePath(path)
check(err)
dst, err := os.Create(path)
dst, err := os.Create(enforcePath(path))
check(err)
io.Copy(dst, part)
w.Write([]byte("ok"))
@@ -182,9 +184,8 @@ func zipRPC(w http.ResponseWriter, r *http.Request) {
zipPath := r.URL.Query().Get("zipPath")
zipName := r.URL.Query().Get("zipName")
defer exitPath(w, "zip", zipPath)
zipFullPath, err := enforcePath(zipPath)
check(err)
_, err = os.Lstat(zipFullPath)
zipFullPath := enforcePath(zipPath)
_, err := os.Lstat(zipFullPath)
check(err)
w.Header().Add("Content-Disposition", "attachment; filename=\""+zipName+".zip\"")
zipWriter := zip.NewWriter(w)
@@ -202,7 +203,7 @@ func zipRPC(w http.ResponseWriter, r *http.Request) {
return nil // hidden files not allowed
}
if f.Mode()&os.ModeSymlink != 0 {
check(errors.New("symlink not allowed in zip downloads")) // filepath.Walk doesnt support symlinks
panic(errors.New("symlink not allowed in zip downloads")) // filepath.Walk doesnt support symlinks
}
header, err := zip.FileInfoHeader(f)
@@ -223,52 +224,39 @@ func zipRPC(w http.ResponseWriter, r *http.Request) {
}
func rpc(w http.ResponseWriter, r *http.Request) {
type rpcCall struct {
Call string `json:"call"`
Args []string `json:"args"`
}
var err error
var rpc rpcCall
defer exitPath(w, "rpc", rpc)
bodyBytes, err := io.ReadAll(r.Body)
check(err)
json.Unmarshal(bodyBytes, &rpc)
path0, err := enforcePath(rpc.Args[0])
path1 := ""
check(err)
if len(rpc.Args) > 1 {
path1, err = enforcePath(rpc.Args[1])
check(err)
}
if rpc.Call == "mkdirp" {
err = os.MkdirAll(path0, os.ModePerm)
} else if rpc.Call == "mv" && len(rpc.Args) == 2 {
err = os.Rename(path0, path1)
err = os.MkdirAll(enforcePath(rpc.Args[0]), os.ModePerm)
} else if rpc.Call == "mv" {
err = os.Rename(enforcePath(rpc.Args[0]), enforcePath(rpc.Args[1]))
} else if rpc.Call == "rm" {
err = os.RemoveAll(path0)
} else {
err = errors.New("invalid rpc call")
err = os.RemoveAll(enforcePath(rpc.Args[0]))
}
check(err)
w.Write([]byte("ok"))
}
func enforcePath(p string) (string, error) {
func enforcePath(p string) string {
joined := filepath.Join(rootPath, strings.TrimPrefix(p, *extraPath))
fp, err := filepath.Abs(joined)
sl, _ := filepath.EvalSymlinks(fp) // err skipped as it would error for inexistent files (RPC check). The actual behaviour is tested below
sl, _ := filepath.EvalSymlinks(fp) // err skipped as it would error for unexistent files (RPC check). The actual behaviour is tested below
// panic if we had a error getting absolute path,
// ... or if path doesnt contain the prefix path we expect,
// ... or if we're skipping hidden folders, and one is requested,
// ... or if we're skipping symlinks, path exists, and a symlink out of bound requested
if err != nil || !strings.HasPrefix(fp, rootPath) || *skipHidden && strings.Contains(p, "/.") || !*symlinks && len(sl) > 0 && !strings.HasPrefix(sl, rootPath) {
return "", errors.New("invalid path")
panic(errors.New("invalid path"))
}
return fp, nil
return fp
}
func main() {
+1 -2
View File
@@ -1,5 +1,4 @@
FROM docker.io/library/golang:1.23.0-alpine AS builder
RUN apk add --no-cache make
FROM golang:1.23.0 as builder
WORKDIR /gossaSrc
COPY . /gossaSrc
RUN make
+1 -2
View File
@@ -1,2 +1 @@
B!!!
test
B!!!
+12 -23
View File
@@ -153,11 +153,8 @@ function rpc (call, args, cb) {
xhr.open('POST', location.origin + window.extraPath + '/rpc')
xhr.setRequestHeader('Content-Type', 'application/json;charset=UTF-8')
xhr.send(JSON.stringify({ call, args }))
xhr.onload = () => cb(false)
xhr.onerror = () => {
flicker(sadBadge)
cb(true)
}
xhr.onload = cb
xhr.onerror = () => flicker(sadBadge)
}
const mkdirCall = (path, cb) => rpc('mkdirp', [prependPath(path)], cb)
@@ -318,36 +315,28 @@ const textTypes = ['.txt', '.rtf', '.md', '.markdown', '.log', '.yaml', '.yml']
const isTextFile = src => src && textTypes.find(type => src.toLocaleLowerCase().includes(type))
let fileEdited
function saveText (cb) {
function saveText (quitting) {
const formData = new FormData()
formData.append(fileEdited, editor.value)
const fname = fileEdited + ".swp"
const path = encodeURIComponent(decodeURI(location.pathname) + fname)
const path = encodeURIComponent(decodeURI(location.pathname) + fileEdited)
upload(0, formData, path, () => {
toast.style.display = 'none'
cb()
if (!quitting) return
clearInterval(window.padTimer)
window.onbeforeunload = null
resetView()
softPrev()
refresh()
}, () => {
toast.style.display = 'block'
if (!quitting) return
alert('cant save!\r\nleave window open to resume saving\r\nwhen connection back up')
})
}
function padOff () {
if (!isEditorMode()) { return }
const swapfile = fileEdited + ".swp"
saveText(() => {
mvCall(prependPath(swapfile), prependPath(fileEdited), err => {
if (err) {
alert('cant save!\r\nleave window open to resume saving\r\nwhen connection back up')
return
}
clearInterval(window.padTimer)
window.onbeforeunload = null
resetView()
softPrev()
refresh()
})
})
saveText(true)
return true
}