The checks that exist actually run - #97
Merged
Merged
Conversation
Six things, all of them a guard that was written and then did not fire. **The GTK check never ran on Debian.** It was wrapped in `command -v ldconfig`, and Debian keeps `ldconfig` in /usr/sbin, which it does not put on a normal user's PATH. So on one of the three distributions this project names as supported, the check that stops you downloading an app your machine cannot run silently did not happen: a verified download, "Installed Notary", and then nothing when it starts. Reproduced in a clean debian:13 container, fixed, and reproduced again as a clean refusal. It looks for ldconfig by absolute path now, and searches the library directories if there is none at all, and reports "cannot tell" rather than guessing. **The floor is checked before GTK presence.** An Ubuntu 22.04 machine has GTK 4.6, so a presence check passes there and then tells the reader nothing, while the floor is the actual reason their machine cannot run this. **The SHA-256 check installed anyway when the digest could not be fetched.** A verification step that any bad minute switches off is not one. It also requires both digests to be non-empty before comparing: two empty strings compare equal and the check then reports success over nothing at all. I hit exactly that bug in my own verification script this week, which is why it is guarded here. **A first start that fails now says so.** The app was launched with its output thrown away, so a window that died on a missing library was indistinguishable from one that opened behind something. On the app that holds your key, that silence is the worst available failure mode. **A second Notary on one key said nothing at all.** The daemon takes an exclusive lock on the key file and answers the second process 409 with "another Notary already has this key open". The window threw that away and re-synced, which lands back on the unlock screen with no error: the right passphrase, the spinner stops, nothing happens, forever. Two ordinary paths reach it, installing Plaza and then Notary, and re-running the installer while Notary is open. It distinguishes the two things 409 means now, and a daemon test pins the wording the window matches on, because the two binaries cannot import each other. Probed: changing that wording fails the test by name. **Two message buffers were too small for their messages.** `setExitNote` formats with `catch return`, so a note one byte too long was not truncated, it was dropped: a dead window with nothing at all where the explanation goes. Also: "This Mac holds the only copy" beside the backup button now says "this computer". 0.10.7's notes claimed that sweep covered everywhere it appeared. It had missed the one sentence that tells a Linux reader why losing this machine loses their identity. A failed signer no longer says "check SIGNER_BIN", a developer override documented only in gui/README.md that nobody who used the installer has ever set. `tar` failures, unknown arguments and `--help` produce messages and the right exit codes; the EXIT trap was returning the status of its own failed test, so `--help` exited 1. And two empty files named `no-such-key.ncryptsec` are deleted. A test opens that path expecting it to be absent and was reading the working directory, so the file it is named for existed. It uses its own temp directory now. Notary is 0.10.10.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Six things, all the same shape: a guard that was written and then did not fire.
The GTK check never ran on Debian
It was wrapped in
command -v ldconfig, and Debian keepsldconfigin/usr/sbin, which it does not put on a normal user's PATH. So on one of the three distributions this project names as supported, the check that stops you downloading an app your machine cannot run silently did not happen.Reproduced in a clean
debian:13container before the fix:and after it, on the same image:
It looks for
ldconfigby absolute path now, searches the library directories if there is none at all, and reports "cannot tell" rather than guessing, so an unusual layout is a warning and not a refused install.Worth saying plainly: a real Debian 13 desktop always has GTK 4 (
task-gnome-desktop,task-xfce-desktopandtask-kde-desktopall pull inlibgtk-4-1), so almost nobody was hitting this. It is a safety net that was not there, not a broken distro.The rest
The floor is checked before GTK presence. An Ubuntu 22.04 machine has GTK 4.6, so a presence check passes there and tells the reader nothing, while the floor is the actual reason their machine cannot run this.
The SHA-256 check installed anyway when the digest could not be fetched. A verification step that any bad minute switches off is not one. It also requires both digests to be non-empty before comparing, because two empty strings compare equal and the check then reports success over nothing at all. I hit exactly that in my own verification script this week, which is why it is guarded here.
A first start that fails now says so. The app was launched with its output thrown away, so a window that died on a missing library was indistinguishable from one that opened behind something.
A second Notary on one key said nothing at all. The daemon takes an exclusive lock on the key file and answers the second process
409withanother Notary already has this key open. The window discarded that and re-synced, landing back on the unlock screen with no error: the right passphrase, the spinner stops, nothing happens, forever. Two ordinary paths reach it, installing Plaza and then Notary, and re-running the installer while Notary is open. A daemon test pins the wording the window matches on, because the two binaries cannot import each other. Probed: changing that wording fails the test by name.Two message buffers were too small for their messages.
setExitNoteformats withcatch return, so a note one byte too long was not truncated, it was dropped, leaving a dead window with nothing where the explanation goes."This Mac holds the only copy" beside the backup button now says "this computer". v0.10.7's notes claimed that sweep covered everywhere it appeared; it had missed the one sentence telling a Linux reader why losing this machine loses their identity.
A failed signer no longer says "check
SIGNER_BIN", a developer override documented only ingui/README.mdthat nobody who used the installer has ever set.tarfailures, unknown arguments and--helpnow produce messages and the right exit codes. TheEXITtrap was returning the status of its own failed test, so--helpexited 1.Two empty files named
no-such-key.ncryptsecare deleted. A test opens that path expecting it to be absent and was reading the working directory, so the file it is named for existed. It uses its own temp directory now.67 tests to 68. Notary is 0.10.10.