Commit Graph
13 Commits
Author SHA1 Message Date
Abdessamad Derraz 771c38ab09 fix: say nothing was run when the fingerprint differs 2026-09-05 07:50:18 +02:00
Abdessamad Derraz 22d7e4aa9f feat: end the install run on what happened 2026-09-05 07:39:50 +02:00
Abdessamad Derraz f864613f11 feat: detect android in the installer 2026-09-05 07:00:12 +02:00
Abdessamad Derraz 3adb34d322 fix: let a run name its host os 2026-09-04 02:57:46 +02:00
Abdessamad Derraz 3d9df87dd0 fix: follow linked dirs and ask for a platform 2026-09-03 17:51:08 +02:00
Abdessamad Derraz 34619c778f fix: publish target aliases and refuse an unknown one
The pack builder accepts the aliases declared in the target overrides,
so --target switch works there, but the installer's target manifests
carried only canonical names. The documented word was the one that
failed, and the installer then carried on with every file: 1911 files
and 4.1 GB where the user had asked for the 863 that target needs.

Aliases are emitted beside their canonical target, and an unknown
target now stops the run and lists what is available. A filter is
applied or refused, never ignored.
2026-08-12 06:13:21 +02:00
Abdessamad Derraz 185cf47bbc fix: hold manifest paths inside the trust boundary
Every other manifest field was treated as hostile input, but
standalone_copies targets were only length-checked before being
expanded and written to: a traversal component or a symlink already
sitting at the destination sent the copy outside the directory the
user opted into. Targets are now validated like the other paths and a
symlinked destination is never followed.

RETROBIOS_BASE_URL serves the manifest and the files it declares, so
it now has to be HTTPS the way both bootstraps already require of the
installer URL; loopback stays open for the end-to-end tests.

install.ps1 left TLS at the Windows PowerShell 5.1 default, which
GitHub refuses, so the download failed before any hash was checked.

check_local read every file once per declared digest, single threaded.
One read now feeds both, across the same pool the downloads use.

RetroPie had no manifest, so the one-line installer answered 'unknown
platform' for a frontend whose packs do ship.
2026-08-11 00:54:27 +02:00
Abdessamad Derraz 9001ebb992 feat: harden the installer boundary
The manifest is untrusted input. It is now read under a size limit and
validated before use: destinations are contained below the BIOS root,
repo_path stays inside bios/, release_asset is a basename, hashes match
their shape, declared totals match their lists, and every entry has a
download source.

Downloads stream against the declared size, are checked by SHA-256 then
SHA-1, land in a per-process temporary file and are installed with
os.replace. Copies into standalone-emulator directories are opt-in with
--standalone-copies so a detection never writes outside the selected
tree.

Both bootstraps verify install.py against an embedded SHA-256 before
running it, and require the Python version install.py actually needs.

A target that publishes no core list is a target with no filter, not a
broken manifest: rejecting it disabled --target for the whole platform.
2026-08-10 13:36:52 +02:00
Abdessamad Derraz 69d53c97c9 feat: add launchbox detection to installer 2026-08-08 04:24:17 +02:00
Abdessamad Derraz 227ad27b15 feat: validate platform input in installers 2026-08-07 16:23:15 +02:00
Abdessamad Derraz 86229a84cd feat: verify downloads in powershell installer 2026-08-07 15:30:37 +02:00
Abdessamad Derraz 8f93ee2239 feat: flatten zips, standalone copies, retropie grouping 2026-04-03 12:04:55 +02:00
Abdessamad Derraz 8fe32103e6 feat: add install.ps1 powershell installer 2026-03-28 18:09:13 +01:00