fix: hash with sha256sum before shasum on Linux (config slugs + setup verify)

shasum is perl/macOS; coreutils-only Linux ships sha256sum. Two call
sites hard-coded shasum: gstack-config's sha8_of/sha16 (so
resolve-user-slug exited 127 for any Linux user with a git email, the
Layer-3 fallback) and the generated bun-installer checksum snippet in
the browse/qa NEEDS_SETUP flow (spurious "checksum mismatch" on the
same distros). Both now resolve sha256sum first and fall back to
shasum -a 256.

New shim-PATH tests pin BOTH hasher branches of sha8_of to a known
vector and cover the sha8->sha16 collision escalation end to end.
This commit is contained in:
Garry Tan
2026-08-28 04:47:09 +00:00
parent be509bfab4
commit c5d849aaad
5 changed files with 145 additions and 6 deletions
+14 -2
View File
@@ -193,8 +193,16 @@ lookup_default() {
# ──────────────────────────────────────────────────────────────────────
# Compute sha8 of a string. Used for endpoint hashing.
# shasum is macOS/perl; most Linux distros ship only coreutils sha256sum —
# resolve whichever exists (same fallback chain as the codex-probe timeout
# wrapper). Without this, any Linux user with a git email hit exit 127 in
# resolve-user-slug's Layer-3 fallback.
sha8_of() {
printf '%s' "$1" | shasum -a 256 | cut -c1-8
if command -v sha256sum >/dev/null 2>&1; then
printf '%s' "$1" | sha256sum | cut -c1-8
else
printf '%s' "$1" | shasum -a 256 | cut -c1-8
fi
}
# Detect the active brain endpoint hash. Reads ~/.claude.json for the gbrain
@@ -228,7 +236,11 @@ endpoint_hash_with_collision_check() {
_claude_json="$HOME/.claude.json"
if [ -n "$_matching" ] && [ -f "$_claude_json" ] && command -v jq >/dev/null 2>&1; then
_url=$(jq -r '.mcpServers.gbrain.url // .mcpServers.gbrain.transport.url // empty' "$_claude_json" 2>/dev/null)
_sha16=$(printf '%s' "$_url" | shasum -a 256 | cut -c1-16)
if command -v sha256sum >/dev/null 2>&1; then
_sha16=$(printf '%s' "$_url" | sha256sum | cut -c1-16)
else
_sha16=$(printf '%s' "$_url" | shasum -a 256 | cut -c1-16)
fi
# Look for any sha16-namespaced key that conflicts. If a stored sha16 exists
# and differs from current sha16, that's the collision evidence; emit sha16.
_stored16=$(grep -E "^(brain_trust_policy|user_slug_at)@${_sha16}" "$CONFIG_FILE" 2>/dev/null | head -1 || true)