mirror of
https://github.com/Abdess/retroarch_system.git
synced 2026-10-10 21:43:23 -05:00
fix: group region candidates once for both sides
The builder and the coverage report each grouped their own candidates before asking which regional alternatives to withdraw. The builder grouped the platform files and the core extras; the report grouped the platform files alone, and keyed them on an unsanitized destination. So a region run withdrew 73 files from a recalbox pack while the report withdrew 14, and described the other 59 as covered by a pack that would not carry them. platform_region_groups builds the grouping once and both sides read it. The extras it returns are keyed by emulator, name and path: Dolphin declares three IPL.bin that differ by path alone, and a name-keyed map withdraws the wrong one. Manifests are byte-identical before and after.
This commit is contained in:
1 parent
7a84764348
commit
b33d045175
4 files changed
+267
-118
No files matched your search
@@ -1505,6 +1505,17 @@ def fetch_large_file(
|
||||
|
||||
|
||||
MAX_ZIP_MEMBERS = 100_000
|
||||
def sanitize_pack_path(raw: str) -> str:
|
||||
"""Strip traversal components from a relative destination.
|
||||
|
||||
The builder and the coverage report key their region grouping on this
|
||||
value, so they have to derive it the same way: a destination normalized on
|
||||
one side only would be looked up under a key the other side never emits.
|
||||
"""
|
||||
raw = raw.replace("\\", "/")
|
||||
return "/".join(p for p in raw.split("/") if p and p not in ("..", "."))
|
||||
|
||||
|
||||
MAX_ZIP_MEMBER_SIZE = 8 * 1024 * 1024 * 1024
|
||||
# The largest generated pack is already ~5 GB uncompressed and the collection
|
||||
# only grows; this bounds a malicious archive without capping a real one.
|
||||
|
||||
Reference in new issue
Block a user