Skip to content

fix: address applicable security findings - #599

Open
grazzolini wants to merge 1 commit into
mainfrom
fix/security-findings-584
Open

grazzolini wants to merge 1 commit into
mainfrom
fix/security-findings-584

Conversation

@grazzolini

Copy link
Copy Markdown
Owner

Summary

  • Update vulnerable JavaScript, Python, and Rust dependency resolutions; scope the shell-quote override to concurrently 10.0.5.
  • Replace backtracking tab delimiter parsing with linear scans while preserving the accepted grammar and chord positions.
  • Add synthetic regression coverage for malformed tabs, sync traversal/symlink rejection, and secret-safe Android packaging diagnostics.

Motivation

Refs #584. The assessed 58 records comprise 33 dependency findings with remediated version resolutions, 3 source-remediated parser findings, 18 source-reviewed exceptions, the GLib exception below, and 3 private draft evidence gaps that remain maintainer-owned. This PR does not close the issue or assert that every security record is resolved.

GLib exception

GLib 0.18.5 remains unpatched for RUSTSEC-2024-0429 (GHSA-wrw7-89jp-8q8g). It is excluded from this PR's remediation claims.

Source assessment on 2026-10-06 found no production call sites of the affected VariantStrIter methods or its public array_iter_str factory in the complete resolved Linux x86_64 default/custom-protocol graph: 613 production packages, 16,092 Rust/TOML source files, and zero missing package sources. Identified references were definitions, documentation, and tests. Private fields prevent direct construction outside GLib; source inspection identified array_iter_str as the only caller of the crate-visible constructor. Generic VariantIter and Vec FromVariant conversion use separate paths. Inspection of 17 generated Rust files found no affected references; this was not exhaustive macro-expansion tracing.

Both cargo check --release --locked configurations passed on 2026-10-06 with Rust 1.98.0 in the pinned ghcr.io/grazzolini/tuneforge-ci@sha256:01e4207497cab9110b1857a32fcb38596c001e346296181c47405439f77c995c Linux/amd64 CI image, emulated on ARM64 Docker. The reviewer agreed that bounded non-applicability is supported for the assessed configurations. Compilation did not execute the affected iterator or the GUI; these checks do not establish runtime behavior, native Linux execution, or universal unreachability. The supplemental headless baseline/fix comparison was never executed because tool access was restricted.

Assessment lockfile SHA-256: 4dc79b33f31754ed277b29a80bb5df88b32799e04360f785ddf6bcdfdbf56f8e. Reassess if dependency versions, resolved graph, features, or callers change.

Testing

Recorded checks from 2026-10-06 are reused for the unchanged source tree committed as 5848351. Test runs used fresh isolated data and transport roots. Platform prerequisites were established for native checks; environment-specific path values are omitted below. Temporary full logs are no longer available.

  • Workspace: pnpm lint, pnpm typecheck, and pnpm test passed; the latter included 553 native and 915 backend tests.
  • Contracts: pnpm contracts:generate produced no committed contract drift.
  • Backend, from apps/backend: uv run --python 3.14 ruff check ., uv run --python 3.14 mypy app, and uv run --python 3.14 pytest -q passed; 95 source files type-checked and 915 tests passed.
  • Focused backend: uv run --python 3.14 pytest tests/test_tab_import_flow.py tests/test_projects.py tests/test_sync_manifest.py tests/test_sync_staging.py tests/test_sync_staging_api.py -q passed 149 tests.
  • Packaging: node --test scripts/package-android.test.mjs passed 36 tests.
  • Focused native sync, from apps/desktop/src-tauri: cargo test --locked sync_transport -- --test-threads=1 passed 152 tests. An earlier parallel run had one timing-sensitive failure; the serial run and workspace native suite passed without source changes.
  • Native compilation passed on macOS; Linux passed cargo check --release --locked and cargo check --release --locked --features custom-protocol from apps/desktop/src-tauri under the emulation boundary above.
  • Android, from the repository root: bash scripts/android-arm64-env.sh cargo check --manifest-path apps/desktop/src-tauri/Cargo.toml --target aarch64-linux-android --locked passed.
  • iOS simulator, from the repository root: rustup run stable cargo check --manifest-path apps/desktop/src-tauri/Cargo.toml --target aarch64-apple-ios-sim --locked passed with the existing stable target and selected Xcode developer directory.
  • Exact resolved dependency ranges, package licenses, and the Flatpak runtime dependency closure were checked. Packaged launches, real devices, and cross-device transport were not verified.

Checklist

  • PR title follows Conventional Commits.
  • Workspace lint, typecheck, and test gates passed.
  • Generated contracts checked; no drift.
  • No secrets, credentials, copyrighted audio, or generated release artifacts added.

Update vulnerable dependency resolutions and parse tabs in linear time.
Add regression coverage for traversal, symlinks, and packaging logs.

Refs #584

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant