mirror of
https://github.com/Abdess/retroarch_system.git
synced 2026-10-10 21:43:23 -05:00
Every other manifest field was treated as hostile input, but standalone_copies targets were only length-checked before being expanded and written to: a traversal component or a symlink already sitting at the destination sent the copy outside the directory the user opted into. Targets are now validated like the other paths and a symlinked destination is never followed. RETROBIOS_BASE_URL serves the manifest and the files it declares, so it now has to be HTTPS the way both bootstraps already require of the installer URL; loopback stays open for the end-to-end tests. install.ps1 left TLS at the Windows PowerShell 5.1 default, which GitHub refuses, so the download failed before any hash was checked. check_local read every file once per declared digest, single threaded. One read now feeds both, across the same pool the downloads use. RetroPie had no manifest, so the one-line installer answered 'unknown platform' for a frontend whose packs do ship.