Skip to content

fix: validate catalog reads and bundle signatures, isolate master writes - #15

Closed
nichinichisou0609 wants to merge 2 commits into
mainfrom
codex/nnnotes-resource-boundaries-20261001
Closed

nichinichisou0609 wants to merge 2 commits into
mainfrom
codex/nnnotes-resource-boundaries-20261001

Conversation

@nichinichisou0609

Copy link
Copy Markdown
Collaborator

Corrupt Addressables buffers can read past the input or loop while resolving linked strings. Bundle downloads and cache hits can also reuse bytes without a complete UnityFS signature, and concurrent master downloads in the same process can collide on PID-based temporary paths.

This change adds bounds and complete-record checks, rejects cyclic string chains, validates the full UnityFS signature before publishing or reusing decrypted bundles, and routes master tables and manifest receipts through the existing atomic writer with independent temporary files, cleanup, and Windows retry handling.

Only three Python source files and two regression test files change. The original checkout's uncommitted CLI/UI changes and private data are excluded.

Validation

  • Windows / CPython 3.13.13, with the golden dependency versions pinned (including NumPy 2.4.6) and GOLDENS_STRICT=1.
  • Current upstream base b1e12c4 plus this repair: 1335 passed, 1 skipped. The PR source tree is identical to the locally tested repair tree.
  • Older local checkout ba93a830 plus the compatible repair: 27 new regressions passed, then 1232 passed, 1 skipped in its full suite, using its existing native extension matching Cargo.lock.
  • StarMoe integration checkout 6a50d85 plus the compatible repair: 27 new regressions passed in a separate isolated copy. This is targeted downstream coverage, not its full suite.
  • The three golden records that failed with NumPy 2.5.3 (cri.movie, sprite.crop, unity.export) all pass in both pinned full runs.
  • pyflakes src tests and git diff --check passed. The optional story-font tests are skipped because freetype is unavailable.

No Rust/native source or dependency constraints change, and no native rebuild was performed locally. Existing native extensions matching each checkout were reused. Other OS/Python combinations, the original dirty CLI/UI combination, and the full StarMoe suite were not run locally.

Bundle validation checks the complete UnityFS signature; it does not add full-body integrity hashes or change raw-cache behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant