Skip to content

V0.8.x-Hardening: XDG-Browser-Kette (#33/#34, #47), deb-Depends (#35), argv-feste Python-Helfer (#43/#48), Cockpit-/Roadmap-Doku (#37/#38) - #118

Open
Toqsick wants to merge 8 commits into
mainfrom
hardening/0.8.x-browser-xdg
Open

Toqsick wants to merge 8 commits into
mainfrom
hardening/0.8.x-browser-xdg

Conversation

@Toqsick

@Toqsick Toqsick commented Oct 2, 2026

Copy link
Copy Markdown
Owner

V0.8.x-Hardening: XDG-Browser-Kette (#33/#34, #47) · deb-Depends (#35) · argv-feste Python-Helfer (#43/#48) · Cockpit-/Roadmap-Doku (#37/#38)

Bringt die V0.8.x-Hardening-Strecke dieses Branches nach main — 6 Commits auf Basis 92bef60, 18 Dateien, +558/−104 (vom 24./25.09.).

Commit Inhalt Issue
388811d Launcher startet die XDG-Default-Browser-Kette: validiertes preferred_browser → XDG-Default (.desktop-Prüfung) → bekannte-Browser-Liste als Fallback; Hub-Snackbars (Info nur beim Listen-Fallback, Fehler bei Totalausfall) #33/#34, WP-B1 #47
c4047eb .deb deklariert xdg-utils, libgtk-3-bin, libglib2.0-bin #35
7099c68 copy_file nutzt shutil.copy2 statt os.system cp WP-P1 #43
39847ea download_file/unzip_file übergeben argv-Listen (kein shlex-Split, CWE-88) WP-P2 #48
e5cda25 Cockpit-Scope in MANIFEST.md / features.csv / AGENTS.md #37
716ca53 Roadmap um die DR-Review ergänzt (Geparkt-Tabelle, Nie-Liste) #38

Gates (im Launcher-Commit dokumentiert)

RED → GREEN 23/23 Launcher-Tests · Suite 198/198 · flutter analyze 0 · Python 49/49 · check-versions ok.

Vorprüfung

  • Leak-Grep über den Branch-Diff: sauber (1 Fehlalarm: eine entfernte Roadmap-Zeile „API-Key-Rotation-Reminder")
  • Merge gegen main (de0026d): konfliktfrei (merge-tree, rc=0)
  • Nach Merge: tool/sync-wiki.sh --push (docs/wiki im Branch berührt)

Merge erst nach Review/Freigabe (kein Auto-Merge).

🤖 Generated with Claude Code

Toqsick and others added 6 commits September 24, 2026 19:05
…ted binary

Launch chain (V0.8.2, #33/#34): preferred_browser (allowlist-validated,
WP-B1/#47 — trim, kKnownBrowsers membership, paths rejected at the use
site) → XDG default browser (xdg-settings + .desktop existence check over
XDG_DATA_HOME/XDG_DATA_DIRS, then detached gtk-launch, xdg-open for URLs)
→ kKnownBrowsers list as last fallback. Hub snackbars: info only on the
list fallback, error on total failure; docs updated to the new chain.

TDD: RED compile gate (outputReader) → GREEN 23/23 launcher tests;
suite 198/198, analyze 0, python 49/49, check-versions ok.

Co-Authored-By: ZCode <noreply@z.ai>
The XDG launcher stage added in V0.8.2 calls xdg-settings, gtk-launch and
gsettings; declare the packages that provide them so apt pulls them in with
the .deb. README and Getting-Started list the same runtime set.

Co-Authored-By: ZCode <noreply@z.ai>
…mand

WP-P1 (#43): copy_file spliced both paths into an os.system cp call. The
only caller passes constant paths today, but the helper is importable by
every root script — shutil.copy2 keeps the copy in-process and preserves
the metadata the cp invocation promised.

Co-Authored-By: ZCode <noreply@z.ai>
WP-P2 (#48): download_file and unzip_file interpolated URLs and paths into
command strings that run_command shlex-splits — a space split the value
across arguments and a leading-dash URL became wget options (CWE-88).
run_command now accepts an argv list unchanged; the wget call puts the link
behind an option fence. unzip gets no fence: after it, -d would be read as
a member name.

Co-Authored-By: ZCode <noreply@z.ai>
…x frozen

Fork note and reference system (Zorin OS 18.1) in MANIFEST; Core now
includes the shipped hub tools and never foreign backends; the distro
matrix in features.csv is frozen at upstream state. The four hub tools
enter the CSV as Core (verified on the reference system only), AGENTS.md
points at the frozen columns.

Co-Authored-By: ZCode <noreply@z.ai>
DR reference line (report stays outside the repo), V0.8.0 tagged,
V0.8.X item 3 done and item 4 scoped, new items 9/10, a 'Nach V0.8.X'
section (gsettings hotkey, browser status, agent tile, gate automation
spike), Tokentelemetrie replaced by the agent tile, Gateway Manager and
Kanban Watcher dropped with a note, tier counts 24/17/4, a parked table
for DR 4.1/4.4/4.6/4.8-4.11 and a binding never-list with the upstream
tasks marked for Basti.

Co-Authored-By: ZCode <noreply@z.ai>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 08:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Browser fallback and XDG default handling have correctness gaps, while unzip still permits leading-dash argument injection.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Hardens browser launching, Debian dependencies, privileged Python helpers, tests, and project documentation.

Changes:

  • Adds validated preferred/XDG browser resolution with binary fallbacks.
  • Replaces shell/string-based Python commands with safer file and argv APIs.
  • Updates package dependencies, tests, feature scope, and roadmap documentation.
File Description
test/​app_launcher_test.dart Tests browser resolution and validation.
README.md Documents runtime dependencies.
MANIFEST.md Defines reference-system scope.
lib/​services/​app_launcher.dart Implements the XDG browser chain.
lib/​layouts/​hub/​hub_shell.dart Updates browser-launch feedback.
features.csv Adds Hub tools to the matrix.
docs/​wiki/​Getting-Started.md Documents added packages.
docs/​wiki/​Admin-Hub.md Documents browser behavior.
docs/​handoff/​roadmap.md Incorporates research decisions.
docs/​handoff/​panels/​hub-shell.md Updates Hub handoff details.
docs/​design/​feature-spec-admin-hub.md Marks the original launcher design obsolete.
docs/​design/​admin-hub-followups.md Updates manual browser checks.
deb/​DEBIAN/​control Declares XDG/GTK runtime dependencies.
AGENTS.md Records distro-matrix guidance.
additional/​python/​tests/​test_jfiles.py Tests shell-free file copying.
additional/​python/​tests/​test_jessentials.py Tests argv-based command helpers.
additional/​python/​jfiles.py Uses shutil.copy2.
additional/​python/​jessentials.py Introduces argv-list execution.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +184 to +186
# No `--` fence here: after it, unzip would read `-d` as a member name.
run_command(["mkdir", path + file_name], False)
run_command(["unzip", "-o", file_path, "-d", path + file_name], False)
Comment on lines +200 to 203
final fallback = await detectBrowser();
if (fallback != null && await _starter(fallback, args)) {
return BrowserLaunchResult.launchedFallback;
}
Comment thread lib/services/app_launcher.dart Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Toqsick <178702703+Toqsick@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants