fix(integrity): restore bootstrap runtime protection

This commit is contained in:
Comely
2026-07-12 17:36:53 -07:00
parent c5e8f34f75
commit b098792001
4 changed files with 45 additions and 35 deletions
+1
View File
@@ -7,6 +7,7 @@ set(_common_sources
ConfigHelper.cpp
InitialStatePolicy.h
ManifestBootstrapPolicy.h
RuntimeProtectionPolicy.h
PolicyHelper.h
PolicyHelper.cpp
LocalStateHelper.h
+3 -15
View File
@@ -1,5 +1,6 @@
#include "IntegrityHelper.h"
#include "ConfigHelper.h"
#include "RuntimeProtectionPolicy.h"
#include <QCryptographicHash>
#include <QDir>
#include <QDirIterator>
@@ -33,21 +34,8 @@ bool IntegrityHelper::safeRelativePath(const QString& path) const
bool IntegrityHelper::runtimeProtectedPath(const QString& path) const
{
const QString p = QDir::fromNativeSeparators(path).toCaseFolded();
QSet<QString> protectedPaths{
"client.ini", "config/app_config.json", "config/local_state.json",
"config/client_identity.dat", "config/version_policy.dat"
};
const QString runtimePrefix = ConfigHelper::instance().runtimeRelativePath().toCaseFolded();
if (!runtimePrefix.isEmpty()) {
const QStringList runtimeProtected{
"client.ini", "config/app_config.json", "config/local_state.json",
"config/client_identity.dat", "config/version_policy.dat"
};
for (const QString& protectedPath : runtimeProtected)
protectedPaths.insert(runtimePrefix + "/" + protectedPath);
}
return protectedPaths.contains(p);
return UpdateClient::isRuntimeProtectedPath(
path, ConfigHelper::instance().runtimeRelativePath());
}
QString IntegrityHelper::sha256(const QString& filePath) const
+38
View File
@@ -0,0 +1,38 @@
#pragma once
#include <QDir>
#include <QSet>
#include <QString>
namespace UpdateClient
{
inline bool isRuntimeProtectedPath(const QString& path,
const QString& runtimeRelativePath)
{
const QString normalizedPath =
QDir::cleanPath(QDir::fromNativeSeparators(path)).toCaseFolded();
static const QSet<QString> protectedPaths{
QStringLiteral("bootstrap.exe"),
QStringLiteral("client.ini"),
QStringLiteral("config/app_config.json"),
QStringLiteral("config/local_state.json"),
QStringLiteral("config/client_identity.dat"),
QStringLiteral("config/version_policy.dat")
};
if (protectedPaths.contains(normalizedPath))
return true;
QString runtimePrefix = QDir::cleanPath(
QDir::fromNativeSeparators(runtimeRelativePath)).toCaseFolded();
if (runtimePrefix.isEmpty() || runtimePrefix == QStringLiteral("."))
return false;
while (runtimePrefix.startsWith(QStringLiteral("./")))
runtimePrefix.remove(0, 2);
for (const QString& protectedPath : protectedPaths) {
if (normalizedPath == runtimePrefix + QLatin1Char('/') + protectedPath)
return true;
}
return false;
}
}