fix: reject insecure release download redirects - #2007
Conversation
There was a problem hiding this comment.
The redirect behavior is covered and the affected packages pass both normal and race tests, but the new httpclient dependency is omitted from the runtime build-recipe inputs. Future security-policy changes in that package would not invalidate the published runtime asset provenance, allowing stale assets to be reused.
| "time" | ||
|
|
||
| "github.com/goplus/spx/v3/internal/base/fileutil" | ||
| "github.com/goplus/spx/v3/internal/httpclient" |
There was a problem hiding this comment.
[P2] Include httpclient in the runtime build recipe inputs
The runtime build recipe hash is selected by internal/release/runtime_pack_source.go and currently includes files.go but not the new internal/httpclient/http.go dependency. If the redirect policy is fixed or changed later only in that package, RuntimeBuildRecipeSHA256 will remain unchanged, so release resolution can reuse an asset built with the stale policy; add this package/path to the recipe selector and its coverage test.
df3d6df to
967fddb
Compare
Release downloads could follow an HTTPS-to-HTTP redirect and accept plaintext manifest bytes. Reuse the existing buildctl redirect policy for launchpack, rejecting downgrades before a plaintext request is sent. The rejection remains a terminal security error and does not trigger source-mode fallback.
The second cleanup moves the policy and its tests to one
internal/httpclient.Doimplementation and removes the temporary forwarding layer. Callers retain request construction, cancellation, parsing errors, timeouts, and download/error handling.Validation: a local TLS-to-HTTP regression failed on the old implementation and now passes without contacting the plaintext endpoint. HTTPS redirects still work. Launchpack/buildctl consumer tests and httpclient/launchpack race tests pass with Go 1.26.5; existing redirect callback, final-URL, limit, and client-preservation tests remain covered.
The source patch also combines cleanly with the pending buildctl cleanup in #1987.
Combined validation of all five fixes passed with Go 1.26.5: 79 host packages, codegen and interpreter submodules, pure/wasm root compilation, and actual Web binding wasm tests. Two full generation runs produced identical diffs; all six external Godot outputs were unchanged.