Skip to content

fix: reject insecure release download redirects - #2007

Merged
joeykchen merged 1 commit into
goplus:devfrom
joeykchen:fix/release-download-redirects
Sep 28, 2026
Merged

joeykchen merged 1 commit into
goplus:devfrom
joeykchen:fix/release-download-redirects

Conversation

@joeykchen

Copy link
Copy Markdown
Contributor

Release downloads could follow an HTTPS-to-HTTP redirect and accept plaintext manifest bytes. Reuse the existing buildctl redirect policy for launchpack, rejecting downgrades before a plaintext request is sent. The rejection remains a terminal security error and does not trigger source-mode fallback.

The second cleanup moves the policy and its tests to one internal/httpclient.Do implementation and removes the temporary forwarding layer. Callers retain request construction, cancellation, parsing errors, timeouts, and download/error handling.

Validation: a local TLS-to-HTTP regression failed on the old implementation and now passes without contacting the plaintext endpoint. HTTPS redirects still work. Launchpack/buildctl consumer tests and httpclient/launchpack race tests pass with Go 1.26.5; existing redirect callback, final-URL, limit, and client-preservation tests remain covered.

The source patch also combines cleanly with the pending buildctl cleanup in #1987.

Combined validation of all five fixes passed with Go 1.26.5: 79 host packages, codegen and interpreter submodules, pure/wasm root compilation, and actual Web binding wasm tests. Two full generation runs produced identical diffs; all six external Godot outputs were unchanged.

@fennoai fennoai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The redirect behavior is covered and the affected packages pass both normal and race tests, but the new httpclient dependency is omitted from the runtime build-recipe inputs. Future security-policy changes in that package would not invalidate the published runtime asset provenance, allowing stale assets to be reused.

"time"

"github.com/goplus/spx/v3/internal/base/fileutil"
"github.com/goplus/spx/v3/internal/httpclient"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Include httpclient in the runtime build recipe inputs

The runtime build recipe hash is selected by internal/release/runtime_pack_source.go and currently includes files.go but not the new internal/httpclient/http.go dependency. If the redirect policy is fixed or changed later only in that package, RuntimeBuildRecipeSHA256 will remain unchanged, so release resolution can reuse an asset built with the stale policy; add this package/path to the recipe selector and its coverage test.

@joeykchen
joeykchen force-pushed the fix/release-download-redirects branch from df3d6df to 967fddb Compare September 28, 2026 03:26
@joeykchen
joeykchen merged commit bb3c586 into goplus:dev Sep 28, 2026
11 checks passed
@joeykchen
joeykchen deleted the fix/release-download-redirects branch September 28, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants