Fix audit findings: path traversal, exec shell, glob dup, dead bread-sync, version drift

- modules_mgmt.rs: reject module names containing path separators, `..`,
  or absolute paths before joining onto modules_dir (install_from_local,
  remove_module, read_module_manifest); adds canonicalized containment
  check as defense in depth. Manifest-supplied names and CLI args were
  previously joined unsanitized, allowing path traversal on install/remove.
- breadd/src/lua/mod.rs: bread.exec now runs via `sh -c` instead of
  `sh -lc`; no documented reason was found for login-shell semantics.
- Unify the two independently hand-written glob matchers (subscription
  dispatch in breadd/src/core/subscriptions.rs vs. the CLI --filter path
  in breadd/src/ipc/mod.rs) into one implementation in
  bread-shared/src/glob.rs, used by both call sites.
- Remove the dead bread-sync/ tree (already excluded from the workspace
  and fully unreferenced) and its stale PKGBUILD deps (libgit2, git
  optdepend) and packaging docs mention.
- Correct the version-number transposition bug ("6.2.0" instead of
  "0.6.2"/"0.6.6") across bread-shared, breadd, and bread-cli Cargo.toml,
  and fix PKGBUILD's stale pkgver, so Cargo.toml/doctor/PKGBUILD all agree
  with the latest git tag (v0.6.6).
This commit is contained in:
Breadway 2026-07-17 03:20:14 +08:00
parent 1fda781b4c
commit 89c5849539
25 changed files with 319 additions and 3085 deletions

View file

@ -1,7 +1,7 @@
# Maintainer: Breadway <rileyhorsham@gmail.com>
pkgname=bread
pkgver=0.6.0
pkgver=0.6.6
pkgrel=1
pkgdesc="A reactive automation fabric for Linux desktops"
arch=('x86_64')
@ -11,11 +11,10 @@ license=('MIT')
# emit GCC LTO bitcode into liblua5.4.a, which the Rust (lld) link can't read,
# leaving all lua_* symbols undefined. Disable LTO for a clean static link.
options=(!lto !debug)
depends=('glibc' 'libgit2')
depends=('glibc')
optdepends=(
'libnotify: desktop notifications via bread.notify()'
'upower: D-Bus battery events (sysfs polling used otherwise)'
'git: bread sync push/pull operations'
)
makedepends=('rust' 'cargo')
source=("${pkgname}-${pkgver}.tar.gz")