fix: settle a contributed path before reading it

validate_pr.py inspects paths chosen by whoever opened the pull
request, and it hashed the file before deciding whether it was a
symlink. A link to /dev/zero was read until the job timed out, and a
link out of the checkout was hashed and reported as though its target
had been contributed. The shape is now settled first, and a test that
used to hang the run covers it.

The gate had no tests at all, and neither did the 3DS crypto reached
by dynamic import from validation.py: RSA PKCS#1 v1.5, AES-128-CBC and
ECDSA over GF(2^233), all written by hand. Coverage goes from 0 to 95%
on the curve, 0 to 55% on the gate, 9 to 35% on the rest. The curve
tests check against the published SEC 2 parameters rather than against
the module: the generator satisfies the curve equation and the group
order takes it to infinity.
This commit is contained in:
Abdessamad Derraz committed 2026-08-11 01:39:29 +02:00
1 parent e41b0dab9c
commit 0b5c534af4
3 files changed
+573 -3

No files matched your search

+13 -3
View File
@@ -137,10 +137,22 @@ def validate_file(
"""Run all validation checks on a file."""
result = ValidationResult(filepath)
# Whoever opened the pull request chose this path, so its shape is
# settled before anything is read. A symlink to an endless device would
# otherwise be hashed until the job timed out, and a symlink out of the
# checkout would be reported as though its target had been contributed.
if os.path.islink(filepath):
result.add_check(False, "Symlinks are not allowed")
return result
if not os.path.exists(filepath):
result.add_check(False, f"File not found: {filepath}")
return result
if not os.path.isfile(filepath):
result.add_check(False, "Not a regular file")
return result
result.size = os.path.getsize(filepath)
hashes = compute_hashes(filepath)
result.sha1 = hashes["sha1"]
@@ -188,9 +200,7 @@ def validate_file(
)
normalized = os.path.normpath(filepath)
if os.path.islink(filepath):
result.add_check(False, "Symlinks are not allowed")
elif normalized.startswith("bios" + os.sep):
if normalized.startswith("bios" + os.sep):
parts = normalized.split(os.sep)
if len(parts) >= 4:
result.add_check(True, f"Correct placement: bios/{parts[1]}/{parts[2]}/")