fix: reject stale first-boot scripts in OTA release payloads

This commit is contained in:
archipelago
2026-10-05 18:44:46 -04:00
parent d9775ac144
commit ccf823590a
6 changed files with 193 additions and 0 deletions
+34
View File
@@ -0,0 +1,34 @@
#!/usr/bin/env python3
"""Reject OTA archives that would overwrite the qualified first-boot repair."""
import argparse
import pathlib
import tarfile
def check(archive, source):
member_name = 'archipelago-runtime/scripts/first-boot-containers.sh'
with tarfile.open(archive, 'r:gz') as package:
matches = [m for m in package.getmembers()
if m.name.removeprefix('./') == member_name]
if len(matches) != 1 or not matches[0].isfile():
raise ValueError('OTA must contain exactly one regular first-boot script')
with package.extractfile(matches[0]) as stream:
actual = stream.read()
if actual != source.read_bytes():
raise ValueError('OTA first-boot script differs from qualified source; repackage before signing')
def main():
parser = argparse.ArgumentParser(description=__doc__)
parser.add_argument('archive', type=pathlib.Path)
args = parser.parse_args()
try:
check(args.archive, pathlib.Path(__file__).resolve().parents[1] /
'scripts/first-boot-containers.sh')
except (OSError, ValueError, tarfile.TarError) as error:
parser.exit(1, f'FAIL: {error}\n')
print('PASS: OTA first-boot script matches qualified source')
if __name__ == '__main__':
main()
+4
View File
@@ -114,6 +114,10 @@ for i in $(seq 0 $((COMPONENT_COUNT - 1))); do
if [ "$ACTUAL_SIZE" != "$DECLARED_SIZE" ]; then
fail "component '$NAME' size mismatch (declared=$DECLARED_SIZE actual=$ACTUAL_SIZE)"
fi
if [[ "$NAME" == *frontend*.tar.gz ]]; then
python3 "$REPO_ROOT/scripts/check-ota-runtime.py" "$FILE" \
|| fail "frontend runtime payload is stale or incomplete"
fi
ok "component '$NAME': sha256 + size match on-disk artifact"
done