| Author | Andy Green <andy@warmcat.com> 2026-08-23 17:58 UTC | | Committer | Andy Green <andy@warmcat.com> 2026-08-23 18:06 UTC | | Tree | 89ef3c164b6d1fec344423601ea901f356fff0ba Raw Patch | | | REPO_FETCH_URL_BASE="https://libwebsockets.org/repo" REPO_WEBURL_BASE="... | REPO_FETCH_URL_BASE="https://libwebsockets.org/repo"
REPO_WEBURL_BASE="https://libwebsockets.org/git"
json_escape() {
printf '%s' "$1" | sed \
-e 's/\\/\\\\/g' \
-e 's/"/\\"/g' \
-e 's/ /\\t/g' \
-e ':a' -e 'N' -e '$!ba' -e 's/\n/\\n/g' \
-e 's/\r/\\r/g'
}
if [ $(git rev-parse --is-bare-repository) = true ]
then
RN=$(basename "$PWD")
else
RN=$(basename $(readlink -nf "$PWD"/..))
fi
RN=${RN%.git}
echo sai update hook $RN...
rm -f .sai.json .sai.json.b64
git show $3 -- .sai.json | patch -p1 --merge
cat .sai.json
cat .sai.json | base64 -w0 > .sai.json.b64
SJL=`stat .sai.json.b64 -c %s`
if [ -z $SJL -o $SJL = "0" ] ; then
cat /home/sai/.sai.json | base64 -w0 > .sai.json.b64
SJL=`stat .sai.json.b64 -c %s`
fi
TF=`mktemp`
RN_E=$(json_escape "$RN")
REF_E=$(json_escape "$1")
HASH_E=$(json_escape "$3")
echo "{\"schema\":\"com-warmcat-sai-notification\"," > $TF
echo " \"action\":\"repo-update\"," >> $TF
echo " \"repository\":{" >> $TF
echo " \"name\":\"$RN_E\"," >> $TF
echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/$RN_E\"," >> $TF
echo " \"weburl\":\"$REPO_WEBURL_BASE/$RN_E\"" >> $TF
echo " }," >> $TF
echo " \"nonce\":\"`dd if=/dev/urandom bs=32 count=1 | sha256sum | cut -d' ' -f1`\"," >> $TF
echo " \"ref\":\"$REF_E\"," >> $TF
echo " \"hash\":\"$HASH_E\"," >> $TF
echo " \"saifile_len\":$SJL," >> $TF
echo -n " \"saifile\":\"" >> $TF
cat .sai.json.b64 >> $TF
echo "\"" >> $TF
echo "}" >> $TF
HM=`cat $TF | sha256hmac -k /etc/sai/private/lws-sai-notification-token | cut -d' ' -f1`
if [ $SJL = "0" ] ; then
echo "No saifile"
exit 0
fi
cat $TF
echo $HM
curl --header "authorization: sai sha256=$HM" \
-F"file=@$TF;type=application/json" \
-A "sai-notifier" \
https://warmcat.com/sai/update-hook
rm -f $TF
exit 0
|
diff --git a/hooks/sai.sh b/hooks/sai.sh
index 0ab44e6..9bd9cec 100755
--- a/hooks/sai.sh
+++ b/hooks/sai.sh
@@ -1,13 +1,7 @@
-#!/bin/bash
-
-# this is a hook to run on your gitolite server when you push a branch
-# it usually goes in ./local/VREF in your gitohashi config
-
-REPO_URL_BASE="https://libwebsockets.org"
-REPO_FETCH_URL_BASE="${REPO_URL_BASE}/repo"
-REPO_WEB_URL_BASE="${REPO_URL_BASE}/git"
-SAI_SERVER_BASE="https://libwebsockets.org:4444/sai/update-hook"
+#!/bin/sh
+REPO_FETCH_URL_BASE="https://libwebsockets.org/repo"
+REPO_WEBURL_BASE="https://libwebsockets.org/git"
# json_escape <string>: emit a JSON string literal body with \, ", and control
# bytes escaped. Git ref names and repository names can legally contain ", \,
@@ -15,7 +9,6 @@ SAI_SERVER_BASE="https://libwebsockets.org:4444/sai/update-hook"
# would allow JSON injection (a pushed branch named foo","extra":"... could
# inject fields). The whole payload is HMAC-signed afterwards, but escaping
# here keeps the structure unambiguous regardless of parser quirks.
-
json_escape() {
printf '%s' "$1" | sed \
-e 's/\\/\\\\/g' \
@@ -34,48 +27,46 @@ fi
RN=${RN%.git}
-# Pre-escape attacker-influenced fields once. RN is derived from the repo
-# directory name; $1 is the git ref; $3 is the new commit hash.
-
-RN_E=$(json_escape "$RN")
-REF_E=$(json_escape "$1")
-HASH_E=$(json_escape "$3")
-
-
-
-pwd
+echo sai update hook $RN...
+rm -f .sai.json .sai.json.b64
+git show $3 -- .sai.json | patch -p1 --merge
+cat .sai.json
+cat .sai.json | base64 -w0 > .sai.json.b64
+SJL=`stat .sai.json.b64 -c %s`
-echo sai update hook $1 $RN_E...
-if [ ! -z "`echo $1 | grep /_`" ] ; then
- echo "Detected temp ref starting with _, not passing to Sai"
- exit 0
+if [ -z $SJL -o $SJL = "0" ] ; then
+ cat /home/sai/.sai.json | base64 -w0 > .sai.json.b64
+ SJL=`stat .sai.json.b64 -c %s`
fi
-rm -f .sai.json .sai.json.b64
-git show $3:.sai.json | base64 -w0 > .sai.json.b64
-SJL=`stat .sai.json.b64 -c %s`
TF=`mktemp`
+# Pre-escape attacker-influenced fields once. RN is derived from the repo
+# directory name; $1 is the git ref; $3 is the new commit hash.
+RN_E=$(json_escape "$RN")
+REF_E=$(json_escape "$1")
+HASH_E=$(json_escape "$3")
+
echo "{\"schema\":\"com-warmcat-sai-notification\"," > $TF
echo " \"action\":\"repo-update\"," >> $TF
echo " \"repository\":{" >> $TF
-echo " \"name\":\"${RN_E}\"," >> $TF
-echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/${RN_E}\"," >> $TF
-echo " \"weburl\":\"$REPO_WEB_URL_BASE/${RN_E}\"" >> $TF
+echo " \"name\":\"$RN_E\"," >> $TF
+echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/$RN_E\"," >> $TF
+echo " \"weburl\":\"$REPO_WEBURL_BASE/$RN_E\"" >> $TF
echo " }," >> $TF
echo " \"nonce\":\"`dd if=/dev/urandom bs=32 count=1 | sha256sum | cut -d' ' -f1`\"," >> $TF
echo " \"ref\":\"$REF_E\"," >> $TF
echo " \"hash\":\"$HASH_E\"," >> $TF
-echo " \"saifile_len\":${SJL}," >> $TF
+echo " \"saifile_len\":$SJL," >> $TF
echo -n " \"saifile\":\"" >> $TF
# disallow any nested JSON monkey business by base64-encoding it
cat .sai.json.b64 >> $TF
echo "\"" >> $TF
echo "}" >> $TF
-HM=`cat $TF | openssl dgst -sha256 -hmac $(cat /etc/sai/private/lws-sai-notification-token2) | cut -d' ' -f2`
+HM=`cat $TF | sha256hmac -k /etc/sai/private/lws-sai-notification-token | cut -d' ' -f1`
if [ $SJL = "0" ] ; then
echo "No saifile"
@@ -84,15 +75,14 @@ fi
cat $TF
echo $HM
-echo badline: -F"file=@${TF};type=application/json"
curl --header "authorization: sai sha256=$HM" \
- -F"file=@${TF};type=application/json" \
- -A "sai-notifier" -m 30 \
- ${SAI_SERVER_BASE}
+ -F"file=@$TF;type=application/json" \
+ -A "sai-notifier" \
+ https://warmcat.com/sai/update-hook
+#curl --header "X-Sai-Signature: sha256=$HM" -F"file=@$TF;name=notification;type=application/json" -A "sai-notifier" http://127.0.0.1:4444
rm -f $TF
exit 0
-
diff --git a/src/builder/b-nspawn.c b/src/builder/b-nspawn.c
index 6e06f27..b27286d 100644
--- a/src/builder/b-nspawn.c
+++ b/src/builder/b-nspawn.c
@@ -369,7 +369,7 @@ sai_lsp_reap_cb(void *opaque, const lws_spawn_resource_us_t *res, siginfo_t *si,
if (saib_srv_queue_json_fragments_helper(ns->spm->ss,
lsm_schema_map_build_metric,
- LWS_ARRAY_SIZE(lsm_schema_build_metric), &m))
+ LWS_ARRAY_SIZE(lsm_schema_map_build_metric), &m))
return;
skip:
diff --git a/src/common/include/private.h b/src/common/include/private.h
index ccec1a6..ef1ce91 100644
--- a/src/common/include/private.h
+++ b/src/common/include/private.h
@@ -878,7 +878,7 @@ extern const lws_struct_map_t
lsm_schema_sq3_map_artifact[1],
lsm_schema_map_ta[1],
lsm_schema_map_plat_simple[1],
- lsm_event[12],
+ lsm_event[13],
lsm_task[32],
lsm_log[8],
lsm_artifact[9],
@@ -901,11 +901,10 @@ extern const lws_struct_map_t
lsm_schema_ptydata[1],
lsm_rebuild[1],
lsm_schema_rebuild[1],
- lsm_schema_build_metric[1],
lsm_schema_map_build_metric[1],
lsm_schema_sq3_map_build_metric[1],
lsm_load_report_members[9],
- lsm_schema_json_task_rej[5],
+ lsm_schema_json_task_rej[1],
lsm_stay_state_update[2],
lsm_schema_stay_state_update[1],
lsm_build_metric[14],
@@ -923,7 +922,7 @@ extern const lws_struct_map_t
lsm_watcher_rule[6],
lsm_watcher_ui_rule[4],
lsm_watcher_service[6],
- lsm_watcher[9],
+ lsm_watcher[8],
lsm_schema_sq3_map_watcher[1],
lsm_schema_json_map_watcher[1],
lsm_watcher_conf[1],
|