V0.8.x-Hardening: XDG-Browser-Kette (#33/#34, #47), deb-Depends (#35), argv-feste Python-Helfer (#43/#48), Cockpit-/Roadmap-Doku (#37/#38) - #118
Open
Toqsick wants to merge 8 commits into
Conversation
…ted binary Launch chain (V0.8.2, #33/#34): preferred_browser (allowlist-validated, WP-B1/#47 — trim, kKnownBrowsers membership, paths rejected at the use site) → XDG default browser (xdg-settings + .desktop existence check over XDG_DATA_HOME/XDG_DATA_DIRS, then detached gtk-launch, xdg-open for URLs) → kKnownBrowsers list as last fallback. Hub snackbars: info only on the list fallback, error on total failure; docs updated to the new chain. TDD: RED compile gate (outputReader) → GREEN 23/23 launcher tests; suite 198/198, analyze 0, python 49/49, check-versions ok. Co-Authored-By: ZCode <noreply@z.ai>
The XDG launcher stage added in V0.8.2 calls xdg-settings, gtk-launch and gsettings; declare the packages that provide them so apt pulls them in with the .deb. README and Getting-Started list the same runtime set. Co-Authored-By: ZCode <noreply@z.ai>
…mand WP-P1 (#43): copy_file spliced both paths into an os.system cp call. The only caller passes constant paths today, but the helper is importable by every root script — shutil.copy2 keeps the copy in-process and preserves the metadata the cp invocation promised. Co-Authored-By: ZCode <noreply@z.ai>
WP-P2 (#48): download_file and unzip_file interpolated URLs and paths into command strings that run_command shlex-splits — a space split the value across arguments and a leading-dash URL became wget options (CWE-88). run_command now accepts an argv list unchanged; the wget call puts the link behind an option fence. unzip gets no fence: after it, -d would be read as a member name. Co-Authored-By: ZCode <noreply@z.ai>
…x frozen Fork note and reference system (Zorin OS 18.1) in MANIFEST; Core now includes the shipped hub tools and never foreign backends; the distro matrix in features.csv is frozen at upstream state. The four hub tools enter the CSV as Core (verified on the reference system only), AGENTS.md points at the frozen columns. Co-Authored-By: ZCode <noreply@z.ai>
DR reference line (report stays outside the repo), V0.8.0 tagged, V0.8.X item 3 done and item 4 scoped, new items 9/10, a 'Nach V0.8.X' section (gsettings hotkey, browser status, agent tile, gate automation spike), Tokentelemetrie replaced by the agent tile, Gateway Manager and Kanban Watcher dropped with a note, tier counts 24/17/4, a parked table for DR 4.1/4.4/4.6/4.8-4.11 and a binding never-list with the upstream tasks marked for Basti. Co-Authored-By: ZCode <noreply@z.ai>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Browser fallback and XDG default handling have correctness gaps, while unzip still permits leading-dash argument injection.
Review effort: Balanced
Findings: 1
Open (3)
What changed in this PR
Hardens browser launching, Debian dependencies, privileged Python helpers, tests, and project documentation.
Changes:
- Adds validated preferred/XDG browser resolution with binary fallbacks.
- Replaces shell/string-based Python commands with safer file and argv APIs.
- Updates package dependencies, tests, feature scope, and roadmap documentation.
| File | Description |
|---|---|
test/app_launcher_test.dart |
Tests browser resolution and validation. |
README.md |
Documents runtime dependencies. |
MANIFEST.md |
Defines reference-system scope. |
lib/services/app_launcher.dart |
Implements the XDG browser chain. |
lib/layouts/hub/hub_shell.dart |
Updates browser-launch feedback. |
features.csv |
Adds Hub tools to the matrix. |
docs/wiki/Getting-Started.md |
Documents added packages. |
docs/wiki/Admin-Hub.md |
Documents browser behavior. |
docs/handoff/roadmap.md |
Incorporates research decisions. |
docs/handoff/panels/hub-shell.md |
Updates Hub handoff details. |
docs/design/feature-spec-admin-hub.md |
Marks the original launcher design obsolete. |
docs/design/admin-hub-followups.md |
Updates manual browser checks. |
deb/DEBIAN/control |
Declares XDG/GTK runtime dependencies. |
AGENTS.md |
Records distro-matrix guidance. |
additional/python/tests/test_jfiles.py |
Tests shell-free file copying. |
additional/python/tests/test_jessentials.py |
Tests argv-based command helpers. |
additional/python/jfiles.py |
Uses shutil.copy2. |
additional/python/jessentials.py |
Introduces argv-list execution. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+184
to
+186
| # No `--` fence here: after it, unzip would read `-d` as a member name. | ||
| run_command(["mkdir", path + file_name], False) | ||
| run_command(["unzip", "-o", file_path, "-d", path + file_name], False) |
Comment on lines
+200
to
203
| final fallback = await detectBrowser(); | ||
| if (fallback != null && await _starter(fallback, args)) { | ||
| return BrowserLaunchResult.launchedFallback; | ||
| } |
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Toqsick <178702703+Toqsick@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


V0.8.x-Hardening: XDG-Browser-Kette (#33/#34, #47) · deb-Depends (#35) · argv-feste Python-Helfer (#43/#48) · Cockpit-/Roadmap-Doku (#37/#38)
Bringt die V0.8.x-Hardening-Strecke dieses Branches nach
main— 6 Commits auf Basis92bef60, 18 Dateien, +558/−104 (vom 24./25.09.).388811dpreferred_browser→ XDG-Default (.desktop-Prüfung) → bekannte-Browser-Liste als Fallback; Hub-Snackbars (Info nur beim Listen-Fallback, Fehler bei Totalausfall)c4047eb.debdeklariertxdg-utils,libgtk-3-bin,libglib2.0-bin7099c68copy_filenutztshutil.copy2stattos.system cp39847eadownload_file/unzip_fileübergeben argv-Listen (kein shlex-Split, CWE-88)e5cda25716ca53Gates (im Launcher-Commit dokumentiert)
RED → GREEN 23/23 Launcher-Tests · Suite 198/198 ·
flutter analyze0 · Python 49/49 ·check-versionsok.Vorprüfung
main(de0026d): konfliktfrei (merge-tree, rc=0)tool/sync-wiki.sh --push(docs/wiki im Branch berührt)Merge erst nach Review/Freigabe (kein Auto-Merge).
🤖 Generated with Claude Code