mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-13 00:19:03 +02:00
fix: hash with sha256sum before shasum on Linux (config slugs + setup verify)
shasum is perl/macOS; coreutils-only Linux ships sha256sum. Two call sites hard-coded shasum: gstack-config's sha8_of/sha16 (so resolve-user-slug exited 127 for any Linux user with a git email, the Layer-3 fallback) and the generated bun-installer checksum snippet in the browse/qa NEEDS_SETUP flow (spurious "checksum mismatch" on the same distros). Both now resolve sha256sum first and fall back to shasum -a 256. New shim-PATH tests pin BOTH hasher branches of sha8_of to a known vector and cover the sha8->sha16 collision escalation end to end.
This commit is contained in:
+14
-2
@@ -193,8 +193,16 @@ lookup_default() {
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
# Compute sha8 of a string. Used for endpoint hashing.
|
||||
# shasum is macOS/perl; most Linux distros ship only coreutils sha256sum —
|
||||
# resolve whichever exists (same fallback chain as the codex-probe timeout
|
||||
# wrapper). Without this, any Linux user with a git email hit exit 127 in
|
||||
# resolve-user-slug's Layer-3 fallback.
|
||||
sha8_of() {
|
||||
printf '%s' "$1" | shasum -a 256 | cut -c1-8
|
||||
if command -v sha256sum >/dev/null 2>&1; then
|
||||
printf '%s' "$1" | sha256sum | cut -c1-8
|
||||
else
|
||||
printf '%s' "$1" | shasum -a 256 | cut -c1-8
|
||||
fi
|
||||
}
|
||||
|
||||
# Detect the active brain endpoint hash. Reads ~/.claude.json for the gbrain
|
||||
@@ -228,7 +236,11 @@ endpoint_hash_with_collision_check() {
|
||||
_claude_json="$HOME/.claude.json"
|
||||
if [ -n "$_matching" ] && [ -f "$_claude_json" ] && command -v jq >/dev/null 2>&1; then
|
||||
_url=$(jq -r '.mcpServers.gbrain.url // .mcpServers.gbrain.transport.url // empty' "$_claude_json" 2>/dev/null)
|
||||
_sha16=$(printf '%s' "$_url" | shasum -a 256 | cut -c1-16)
|
||||
if command -v sha256sum >/dev/null 2>&1; then
|
||||
_sha16=$(printf '%s' "$_url" | sha256sum | cut -c1-16)
|
||||
else
|
||||
_sha16=$(printf '%s' "$_url" | shasum -a 256 | cut -c1-16)
|
||||
fi
|
||||
# Look for any sha16-namespaced key that conflicts. If a stored sha16 exists
|
||||
# and differs from current sha16, that's the collision evidence; emit sha16.
|
||||
_stored16=$(grep -E "^(brain_trust_policy|user_slug_at)@${_sha16}" "$CONFIG_FILE" 2>/dev/null | head -1 || true)
|
||||
|
||||
Reference in New Issue
Block a user