fix: validate catalog reads and bundle signatures, isolate master writes - #15
Closed
nichinichisou0609 wants to merge 2 commits into
Closed
nichinichisou0609 wants to merge 2 commits into
nichinichisou0609 wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Corrupt Addressables buffers can read past the input or loop while resolving linked strings. Bundle downloads and cache hits can also reuse bytes without a complete UnityFS signature, and concurrent master downloads in the same process can collide on PID-based temporary paths.
This change adds bounds and complete-record checks, rejects cyclic string chains, validates the full UnityFS signature before publishing or reusing decrypted bundles, and routes master tables and manifest receipts through the existing atomic writer with independent temporary files, cleanup, and Windows retry handling.
Only three Python source files and two regression test files change. The original checkout's uncommitted CLI/UI changes and private data are excluded.
Validation
GOLDENS_STRICT=1.b1e12c4plus this repair: 1335 passed, 1 skipped. The PR source tree is identical to the locally tested repair tree.ba93a830plus the compatible repair: 27 new regressions passed, then 1232 passed, 1 skipped in its full suite, using its existing native extension matchingCargo.lock.6a50d85plus the compatible repair: 27 new regressions passed in a separate isolated copy. This is targeted downstream coverage, not its full suite.cri.movie,sprite.crop,unity.export) all pass in both pinned full runs.pyflakes src testsandgit diff --checkpassed. The optional story-font tests are skipped because freetype is unavailable.No Rust/native source or dependency constraints change, and no native rebuild was performed locally. Existing native extensions matching each checkout were reused. Other OS/Python combinations, the original dirty CLI/UI combination, and the full StarMoe suite were not run locally.
Bundle validation checks the complete UnityFS signature; it does not add full-body integrity hashes or change raw-cache behavior.