Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -265,6 +265,41 @@ jobs:
CARGO_BUILD_TARGET: ${{ matrix.triple }}
run: cargo packager --release -f deb -f appimage --target ${{ matrix.triple }}

# cargo-packager ships AppRun as 0744, and the AppImage stores every
# file as root-owned, so for anyone but root AppRun is read-only. The
# AppImage runtime's FUSE mount tolerates that; a kernel squashfs mount
# doesn't — firejail (the AppImage catalog's test harness) refuses to
# start it ("AppRun: Permission denied"). Re-pack with AppRun 0755, and
# fail the build if any executable is left owner-only. appimagetool
# only publishes a `continuous` tag, so there's no version to pin; with
# neither -u nor -g it embeds no update information.
- name: Make AppRun executable for every user
run: |
set -e
APPIMAGE=$(find "target/${{ matrix.triple }}/release" -maxdepth 1 -name '*.AppImage' | head -1)
if [ -z "$APPIMAGE" ]; then
echo "::error::no .AppImage produced by cargo-packager"
exit 1
fi
ARCH="${{ matrix.rpm_arch }}"

curl -fsSL -o appimagetool \
"https://github.com/AppImage/appimagetool/releases/download/continuous/appimagetool-${ARCH}.AppImage"
chmod +x appimagetool
TOOL="$PWD/appimagetool"

cd "$(dirname "$APPIMAGE")"
NAME=$(basename "$APPIMAGE")
rm -rf squashfs-root
"./$NAME" --appimage-extract >/dev/null
chmod 0755 squashfs-root/AppRun
if find squashfs-root -type f -perm -u=x ! -perm -o=x | grep .; then
echo "::error::executables above aren't runnable by other users"
exit 1
fi
ARCH="$ARCH" "$TOOL" squashfs-root "$NAME"
rm -rf squashfs-root

# cargo-packager 0.11 doesn't expose .deb postinst hooks, so
# we patch the freshly-built .deb to inject one that reloads
# udev rules + retriggers attached USB devices. Without this,
Expand Down
18 changes: 12 additions & 6 deletions src/uefi/fv.rs
Original file line number Diff line number Diff line change
Expand Up @@ -107,8 +107,10 @@ fn scan_fv_offsets(buf: &[u8]) -> Vec<usize> {
continue;
};
let sum: u16 = full_header
.chunks_exact(2)
.map(|c| u16::from_le_bytes([c[0], c[1]]))
.as_chunks::<2>()
.0
.iter()
.map(|c| u16::from_le_bytes(*c))
.fold(0u16, |a, v| a.wrapping_add(v));
if sum == 0 {
out.push(start);
Expand Down Expand Up @@ -352,8 +354,10 @@ fn find(haystack: &[u8], needle: &[u8]) -> Option<usize> {
/// Decode a NUL-terminated little-endian UCS-2 string.
fn ucs2_to_string(data: &[u8]) -> String {
let units: Vec<u16> = data
.chunks_exact(2)
.map(|c| u16::from_le_bytes([c[0], c[1]]))
.as_chunks::<2>()
.0
.iter()
.map(|c| u16::from_le_bytes(*c))
.take_while(|&u| u != 0)
.collect();
String::from_utf16_lossy(&units)
Expand Down Expand Up @@ -451,8 +455,10 @@ mod tests {
h[55] = 2; // revision
// Fix up the header checksum so the u16 sum is zero.
let sum: u16 = h
.chunks_exact(2)
.map(|c| u16::from_le_bytes([c[0], c[1]]))
.as_chunks::<2>()
.0
.iter()
.map(|c| u16::from_le_bytes(*c))
.fold(0u16, |a, v| a.wrapping_add(v));
h[50..52].copy_from_slice(&(0u16.wrapping_sub(sum)).to_le_bytes());

Expand Down
16 changes: 10 additions & 6 deletions src/uefi/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -197,8 +197,8 @@ fn boot_from_nvram(nvram: &HashMap<String, Vec<u8>>) -> Vec<BootEntry> {
return Vec::new();
};
let mut out = Vec::new();
for chunk in order.chunks_exact(2) {
let num = u16::from_le_bytes([chunk[0], chunk[1]]);
for chunk in order.as_chunks::<2>().0 {
let num = u16::from_le_bytes(*chunk);
let slot = format!("Boot{num:04X}");
if let Some(data) = nvram.get(&slot)
&& let Some(entry) = parse_load_option(&slot, data)
Expand Down Expand Up @@ -230,8 +230,10 @@ fn parse_load_option(slot: &str, data: &[u8]) -> Option<BootEntry> {
/// Decode a NUL-terminated little-endian UCS-2 string.
fn ucs2_z(b: &[u8]) -> String {
let units: Vec<u16> = b
.chunks_exact(2)
.map(|c| u16::from_le_bytes([c[0], c[1]]))
.as_chunks::<2>()
.0
.iter()
.map(|c| u16::from_le_bytes(*c))
.take_while(|&u| u != 0)
.collect();
String::from_utf16_lossy(&units)
Expand Down Expand Up @@ -488,8 +490,10 @@ fn ucs2_at(data: &[u8], offset: usize, max_chars: usize) -> Option<String> {
let end = (offset + max_chars * 2).min(data.len());
let slice = data.get(offset..end)?;
let units: Vec<u16> = slice
.chunks_exact(2)
.map(|c| u16::from_le_bytes([c[0], c[1]]))
.as_chunks::<2>()
.0
.iter()
.map(|c| u16::from_le_bytes(*c))
.take_while(|&u| u != 0)
.collect();
let s = String::from_utf16_lossy(&units);
Expand Down
6 changes: 4 additions & 2 deletions src/uefi/nvram.rs
Original file line number Diff line number Diff line change
Expand Up @@ -115,8 +115,10 @@ fn parse_vss_vars(image: &[u8], mut p: usize, end: usize, vars: &mut HashMap<Str
/// Decode a NUL-terminated little-endian UCS-2 name.
fn ucs2z(b: &[u8]) -> String {
let units: Vec<u16> = b
.chunks_exact(2)
.map(|c| u16::from_le_bytes([c[0], c[1]]))
.as_chunks::<2>()
.0
.iter()
.map(|c| u16::from_le_bytes(*c))
.take_while(|&u| u != 0)
.collect();
String::from_utf16_lossy(&units)
Expand Down
Loading