Commit Graph
17 Commits
Author SHA1 Message Date
Abdessamad Derraz d2a61b4a89 refactor: name the new exceptions as errors 2026-10-10 05:29:38 +02:00
Abdessamad Derraz 6fca4149f5 feat: offer the files no platform system owns 2026-10-10 04:42:11 +02:00
Abdessamad Derraz ece2c06aaf feat: choose systems, cores and regions to install 2026-10-10 04:31:57 +02:00
Abdessamad Derraz bfa741a9c9 fix: accept the slug omission in the installer 2026-10-10 03:59:23 +02:00
Abdessamad Derraz 6a80f3ed08 fix: hand the terminal to a piped installer 2026-10-10 03:54:26 +02:00
Abdessamad Derraz 4a30cbf882 fix: count a refused standalone copy as an error 2026-10-09 22:57:15 +02:00
Abdessamad Derraz ed7e83e99b fix: default each platform to the folder it reads 2026-10-06 12:46:35 +02:00
Abdessamad Derraz 2a56fccc85 fix: refuse targets when their list cannot be read 2026-10-06 01:39:31 +02:00
Abdessamad Derraz 771c38ab09 fix: say nothing was run when the fingerprint differs 2026-09-05 07:50:18 +02:00
Abdessamad Derraz 22d7e4aa9f feat: end the install run on what happened 2026-09-05 07:39:50 +02:00
Abdessamad Derraz f864613f11 feat: detect android in the installer 2026-09-05 07:00:12 +02:00
Abdessamad Derraz 3adb34d322 fix: let a run name its host os 2026-09-04 02:57:46 +02:00
Abdessamad Derraz 3d9df87dd0 fix: follow linked dirs and ask for a platform 2026-09-03 17:51:08 +02:00
Abdessamad Derraz 34619c778f fix: publish target aliases and refuse an unknown one
The pack builder accepts the aliases declared in the target overrides,
so --target switch works there, but the installer's target manifests
carried only canonical names. The documented word was the one that
failed, and the installer then carried on with every file: 1911 files
and 4.1 GB where the user had asked for the 863 that target needs.

Aliases are emitted beside their canonical target, and an unknown
target now stops the run and lists what is available. A filter is
applied or refused, never ignored.
2026-08-12 06:13:21 +02:00
Abdessamad Derraz 185cf47bbc fix: hold manifest paths inside the trust boundary
Every other manifest field was treated as hostile input, but
standalone_copies targets were only length-checked before being
expanded and written to: a traversal component or a symlink already
sitting at the destination sent the copy outside the directory the
user opted into. Targets are now validated like the other paths and a
symlinked destination is never followed.

RETROBIOS_BASE_URL serves the manifest and the files it declares, so
it now has to be HTTPS the way both bootstraps already require of the
installer URL; loopback stays open for the end-to-end tests.

install.ps1 left TLS at the Windows PowerShell 5.1 default, which
GitHub refuses, so the download failed before any hash was checked.

check_local read every file once per declared digest, single threaded.
One read now feeds both, across the same pool the downloads use.

RetroPie had no manifest, so the one-line installer answered 'unknown
platform' for a frontend whose packs do ship.
2026-08-11 00:54:27 +02:00
Abdessamad Derraz 9001ebb992 feat: harden the installer boundary
The manifest is untrusted input. It is now read under a size limit and
validated before use: destinations are contained below the BIOS root,
repo_path stays inside bios/, release_asset is a basename, hashes match
their shape, declared totals match their lists, and every entry has a
download source.

Downloads stream against the declared size, are checked by SHA-256 then
SHA-1, land in a per-process temporary file and are installed with
os.replace. Copies into standalone-emulator directories are opt-in with
--standalone-copies so a detection never writes outside the selected
tree.

Both bootstraps verify install.py against an embedded SHA-256 before
running it, and require the Python version install.py actually needs.

A target that publishes no core list is a target with no filter, not a
broken manifest: rejecting it disabled --target for the whole platform.
2026-08-10 13:36:52 +02:00
Abdessamad Derraz 1a0eef563b feat: add install.sh posix bootstrap 2026-03-28 18:04:08 +01:00