From 3cf8750716cbd4c9b0c06577d921b6a79a64f311 Mon Sep 17 00:00:00 2001 From: Commanderx-code Date: Fri, 25 Sep 2026 12:13:23 -0400 Subject: [PATCH] Prepare v0.7.1 security release Co-Authored-By: Claude Opus 5.5 --- CHANGELOG.md | 10 ++++++++++ README.md | 10 +++++----- docs/installation.md | 6 +++--- docs/release-notes.md | 32 +++++++++++++++++--------------- docs/releases.md | 8 ++++---- docs/user-guide.md | 2 +- package-lock.json | 4 ++-- package.json | 2 +- packaging/aur/.SRCINFO | 4 ++-- packaging/aur/PKGBUILD | 2 +- src-tauri/Cargo.lock | 2 +- src-tauri/Cargo.toml | 2 +- src-tauri/tauri.conf.json | 2 +- 13 files changed, 49 insertions(+), 37 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 04d3e49..2acf29d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,16 @@ Release downloads and full notes are available on [GitHub Releases](https://github.com/Commanderx-code/command-center/releases). +## [0.7.1](https://github.com/Commanderx-code/command-center/releases/tag/v0.7.1) — 2026-09-25 + +Security release. All 0.7.0 users should upgrade. + +- Per-file diffs in Repository Details no longer inspect nested submodule working files, so a submodule's own Git filters cannot run when you view its diff. The file list and full diff already worked this way. +- **Read recovery notes** refuses devices, FIFOs and other non-regular files and reads at most 256 KB, so a setting such as `/dev/zero` can no longer exhaust memory. +- `settings.json` and its `.bak` backup are written readable only by you (0600), like the app's other private data. Existing files are tightened the next time settings are saved. +- Restic `rest:` repository addresses with an embedded password are refused, as other URLs with passwords already were, instead of passing the password on restic's command line. +- Job output from a hostile Git server can no longer freeze the app. Escape-sequence cleaning is now linear; displayed output is unchanged. + ## [0.7.0](https://github.com/Commanderx-code/command-center/releases/tag/v0.7.0) — 2026-09-24 - Added **Backup file history**: search every Restic snapshot for a file name, path or pattern, see each saved copy with its snapshot time, size and modification time, spot the versions that changed or a file that was deleted, and restore a chosen version into a new folder. diff --git a/README.md b/README.md index 2add59c..b488564 100644 --- a/README.md +++ b/README.md @@ -86,13 +86,13 @@ Read [Workflows, profiles, and recovery verification](docs/operations.md) for se **[Get the latest release →](https://github.com/Commanderx-code/command-center/releases/latest)** -| Package | Download v0.7.0 | Install the downloaded file | +| Package | Download v0.7.1 | Install the downloaded file | | --------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------ | -| Debian / Ubuntu | [`.deb` · amd64](https://github.com/Commanderx-code/command-center/releases/download/v0.7.0/command-center_0.7.0_amd64.deb) | `sudo apt install ./command-center_0.7.0_amd64.deb` | -| Fedora / RPM | [`.rpm` · x86_64](https://github.com/Commanderx-code/command-center/releases/download/v0.7.0/command-center-0.7.0-1.x86_64.rpm) | `sudo dnf install ./command-center-0.7.0-1.x86_64.rpm` | -| Arch / Garuda | [`.pkg.tar.zst` · x86_64](https://github.com/Commanderx-code/command-center/releases/download/v0.7.0/command-center-0.7.0-1-x86_64.pkg.tar.zst) | `sudo pacman -U ./command-center-0.7.0-1-x86_64.pkg.tar.zst` | +| Debian / Ubuntu | [`.deb` · amd64](https://github.com/Commanderx-code/command-center/releases/download/v0.7.1/command-center_0.7.1_amd64.deb) | `sudo apt install ./command-center_0.7.1_amd64.deb` | +| Fedora / RPM | [`.rpm` · x86_64](https://github.com/Commanderx-code/command-center/releases/download/v0.7.1/command-center-0.7.1-1.x86_64.rpm) | `sudo dnf install ./command-center-0.7.1-1.x86_64.rpm` | +| Arch / Garuda | [`.pkg.tar.zst` · x86_64](https://github.com/Commanderx-code/command-center/releases/download/v0.7.1/command-center-0.7.1-1-x86_64.pkg.tar.zst) | `sudo pacman -U ./command-center-0.7.1-1-x86_64.pkg.tar.zst` | -Version 0.7.0 packages require **Linux x86_64, glibc 2.35+, GTK 3, and WebKitGTK 4.1**. They are install-tested on Ubuntu 22.04 and 24.04, Debian 12, and Fedora 43, and the Arch package on current Arch; the release notes link the workflow run. Release assets include `SHA256SUMS` for verification. +Version 0.7.1 packages require **Linux x86_64, glibc 2.35+, GTK 3, and WebKitGTK 4.1**. They are install-tested on Ubuntu 22.04 and 24.04, Debian 12, and Fedora 43, and the Arch package on current Arch; the release notes link the workflow run. Release assets include `SHA256SUMS` for verification. Arch/Garuda users can also build the same package with `makepkg -si` from `packaging/aur/`, or develop from source using the [installation guide](docs/installation.md#from-source-on-archgaruda). diff --git a/docs/installation.md b/docs/installation.md index 3798761..62313b1 100644 --- a/docs/installation.md +++ b/docs/installation.md @@ -19,19 +19,19 @@ Each downloaded package must report `OK`. The `--ignore-missing` option lets you On a compatible Debian/Ubuntu system: ```bash -sudo apt install ./command-center_0.7.0_amd64.deb +sudo apt install ./command-center_0.7.1_amd64.deb ``` On a compatible Fedora/RPM system: ```bash -sudo dnf install ./command-center-0.7.0-1.x86_64.rpm +sudo dnf install ./command-center-0.7.1-1.x86_64.rpm ``` On Arch or an Arch-based system such as Garuda (0.6.0 and later): ```bash -sudo pacman -U ./command-center-0.7.0-1-x86_64.pkg.tar.zst +sudo pacman -U ./command-center-0.7.1-1-x86_64.pkg.tar.zst ``` The Arch package is built from the release tag with `packaging/aur/PKGBUILD` in a clean Arch container and tracks current Arch libraries; update your system before installing it. To build it yourself instead, run `makepkg -si` from a copy of `packaging/aur/`. diff --git a/docs/release-notes.md b/docs/release-notes.md index 99c877c..c3260cf 100644 --- a/docs/release-notes.md +++ b/docs/release-notes.md @@ -1,19 +1,21 @@ -Command Center 0.7.0 adds backup file history: find every saved version of a file across your backups and restore the one you want. +Command Center 0.7.1 is a security release. **All 0.7.0 users should upgrade.** -### What's new +### Security fixes -- **Backup file history:** in **Backup & Restore → File history**, search all Restic snapshots for a file name (for example `notes.md`, matched in any folder), an exact path (`~/Documents/report.odt`), or a pattern (`*.kdbx`), with optional **Ignore case**. -- **See how a file changed over time:** results are grouped by path, newest first. Each saved copy shows when it was backed up, the snapshot and host, and the file's modification time and size, marked **First saved**, **Changed** or **Same as previous**. **Show only versions that changed** hides identical copies. -- **Find deleted files:** if newer snapshots of the same machine and backup path no longer contain a file, the result says it may have been deleted or moved, and when it was last saved. -- **Restore a chosen version:** **Restore this version** fills the restore form with that snapshot and the file's exact path. Pick a new destination folder and review. Restores still never overwrite existing files and are verified as they're written. -- **Wiki user guide:** a step-by-step guide to every page and feature, now linked from the README: https://github.com/Commanderx-code/command-center/wiki +- **Viewing a submodule's diff no longer runs that submodule's Git filters.** In 0.7.0, opening the **Unstaged** diff of a staged submodule in Repository Details could make Git inspect the submodule's working files with the submodule's own configuration. A copied or extracted repository with a crafted submodule could therefore run a command when you viewed that diff. Per-file diffs now skip nested submodule working files, as the file list and full diff already did. +- **Recovery notes are read with a size limit.** The recovery notes path comes from Settings or an imported setup bundle. A path such as `/dev/zero` made **Read recovery notes** read until memory ran out. Only regular files are read now, and at most 256 KB. +- **Settings are private to your user.** `settings.json` and `settings.json.bak` were created with default permissions, usually readable by other local users. They can hold your Restic repository address, password-file and KWallet entry names, and custom commands. Both are now written with 0600 permissions, like the app's other private data. +- **REST-server passwords stay off the command line.** Command Center already refused repository URLs with an embedded password, but it missed Restic's `rest:https://user:password@host/` form. That password was passed to restic as an argument, where other local users could read it from the process list, and was saved in Activity. These addresses are now refused too. +- **Hostile Git output can no longer freeze the app.** A Git server could send output that made job-output cleaning take minutes, freezing the window on every launch while the job stayed in Activity. Cleaning is now linear, and displayed output is unchanged. -### Behavior to know +### Behavior changes -- Searching is a reviewed, read-only job. It lists snapshots, then searches all of them, so it can take a while on large repositories and may ask KWallet to unlock. Nothing is restored until you review a restore. -- "Changed" compares size and modification time between copies. It doesn't compare file contents. -- A search matching a huge number of files can't be displayed. Search a more specific path instead. -- Restic treats `*`, `?` and `[` in paths as pattern characters. For file names containing them, check the include path before restoring. +- If your Restic repository is a `rest:` address with a password in it, Restic jobs now stop with an error. Remove the password from the address and set `RESTIC_REST_USERNAME` and `RESTIC_REST_PASSWORD` in the environment Command Center runs in. +- A per-file Unstaged diff of a submodule with local edits no longer shows a `-dirty` marker. Open the submodule directly to inspect its files. +- **Read recovery notes** reports "Recovery notes must be a regular file" for a device, FIFO or folder. +- Existing settings files become private the next time you save settings. + +No other features changed. See the [0.7.0 notes](https://github.com/Commanderx-code/command-center/releases/tag/v0.7.0) for backup file history. ### Linux downloads @@ -21,13 +23,13 @@ The `.deb` and `.rpm` assets target **x86_64** and require **glibc 2.35+, GTK 3, ```sh # Debian / Ubuntu -sudo apt install ./command-center_0.7.0_amd64.deb +sudo apt install ./command-center_0.7.1_amd64.deb # Fedora / RPM -sudo dnf install ./command-center-0.7.0-1.x86_64.rpm +sudo dnf install ./command-center-0.7.1-1.x86_64.rpm # Arch / Garuda (built against current Arch libraries) -sudo pacman -U ./command-center-0.7.0-1-x86_64.pkg.tar.zst +sudo pacman -U ./command-center-0.7.1-1-x86_64.pkg.tar.zst ``` Download `SHA256SUMS` beside the package and run: diff --git a/docs/releases.md b/docs/releases.md index 66212fe..f7f622a 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -5,7 +5,7 @@ Open Settings → About & updates. Check for releases, read the notes, then export the source updater. Close Command Center and run the displayed command, for example: ```sh -bash ~/Downloads/update-desktop.sh v0.7.0 +bash ~/Downloads/update-desktop.sh v0.7.1 ``` The helper requires Linux build dependencies, Git, Node/npm, and Rust/Cargo. Run as your normal user, without sudo. It asks you to type the tag, downloads that tag into a temporary checkout, checks its package version, installs dependencies, runs JavaScript and Rust tests, then builds and installs the desktop app. A failed check stops installation. It does not modify your project checkout or app settings. The GitHub tag must already exist; the release checker only advertises published stable releases. Offline/API errors are shown without claiming that the installed version is current. GitHub is contacted only when you request a release check or open its release page. @@ -25,9 +25,9 @@ This rolls back the binary only, not settings or user data. It applies to the no Keep package.json, package-lock.json, Cargo.toml, Cargo.lock, and tauri.conf.json versions aligned. Update docs/release-notes.md and CHANGELOG.md. Commit and push the reviewed source, then create and push an annotated tag matching the version: ```sh -git tag -a v0.7.0 -m 'Command Center v0.7.0' -git push origin v0.7.0 -npm run release:draft -- v0.7.0 +git tag -a v0.7.1 -m 'Command Center v0.7.1' +git push origin v0.7.1 +npm run release:draft -- v0.7.1 ``` The draft command requires an authenticated GitHub CLI (`gh`). It checks for a clean working tree and a matching local/remote tag and runs the checks and tests. It then finds the successful **Linux packages** run for the tagged commit, downloads that run's `packages` and `arch-package` artifacts, verifies their checksums, writes one `SHA256SUMS` covering the `.deb`, `.rpm`, and Arch package, and creates an **unpublished** GitHub release. The release notes are docs/release-notes.md plus a build-and-validation section linking the workflow run. If CI has not passed for the tag, no draft is created. The command never builds release packages locally: a build on a newer distribution such as Garuda would require a newer glibc than the packages declare. It does not push tags or publish the draft. Download and verify the hosted assets and test the app on your machine before publishing. diff --git a/docs/user-guide.md b/docs/user-guide.md index 02c8ce7..e3a198b 100644 --- a/docs/user-guide.md +++ b/docs/user-guide.md @@ -24,7 +24,7 @@ On the first desktop launch without a configured dotfiles integration, Command C - **Dotfiles repository** points to the checkout. The Home Manager flake may be in its `home-manager/` directory or repository root. **Home Manager profile** is the flake output name, such as `commander`. - **Backup helpers** are executable paths to your existing `backup-personal`, `backup-everything`, and `backup-health` helpers. The health helper must return the dotfiles backup-health JSON format. These scripts continue using their own machine configuration. -- **Restic repository and credentials** control snapshot browsing, checks, and restores. Use an existing KWallet entry, password file, or inherited Restic credential environment. Password contents are never stored in preferences. A locked wallet can prompt through KWallet. +- **Restic repository and credentials** control snapshot browsing, checks, and restores. Use an existing KWallet entry, password file, or inherited Restic credential environment. Password contents are never stored in preferences, and repository addresses with an embedded password, including `rest:` addresses, are refused; use `RESTIC_REST_USERNAME` and `RESTIC_REST_PASSWORD` for a REST server. A locked wallet can prompt through KWallet. - **Configuration sources** must be editable files inside your home. Files resolving into `/nix/store` are never modified. For the existing dotfiles layout, a Home Manager-managed Fastfetch config maps to `configs/fastfetch/config.jsonc`. Other layouts can be set manually. Save the source, then build/apply Home Manager to activate it. - **Recovery instructions** can point to a dedicated recovery document. Detection falls back to the dotfiles README if no recovery-specific file is found; review that choice. diff --git a/package-lock.json b/package-lock.json index c602494..46dad16 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "command-center", - "version": "0.7.0", + "version": "0.7.1", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "command-center", - "version": "0.7.0", + "version": "0.7.1", "license": "MIT", "dependencies": { "@xterm/addon-fit": "^0.11.0", diff --git a/package.json b/package.json index c592a0f..2cd320f 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "command-center", - "version": "0.7.0", + "version": "0.7.1", "private": true, "type": "module", "description": "A Linux control deck for repositories, configuration, backup, and recovery.", diff --git a/packaging/aur/.SRCINFO b/packaging/aur/.SRCINFO index 3df757b..e67819b 100644 --- a/packaging/aur/.SRCINFO +++ b/packaging/aur/.SRCINFO @@ -1,6 +1,6 @@ pkgbase = command-center pkgdesc = Local Linux workstation dashboard for repositories, backups, configuration and Toolbox - pkgver = 0.7.0 + pkgver = 0.7.1 pkgrel = 1 url = https://github.com/Commanderx-code/command-center arch = x86_64 @@ -25,7 +25,7 @@ pkgbase = command-center optdepends = restic: backup recovery optdepends = fish: Fish custom actions options = !lto - source = git+https://github.com/Commanderx-code/command-center.git#tag=v0.7.0 + source = git+https://github.com/Commanderx-code/command-center.git#tag=v0.7.1 sha256sums = SKIP pkgname = command-center diff --git a/packaging/aur/PKGBUILD b/packaging/aur/PKGBUILD index de3c74c..13ee4ef 100644 --- a/packaging/aur/PKGBUILD +++ b/packaging/aur/PKGBUILD @@ -2,7 +2,7 @@ # namcap, installs it, and launches it. Not yet submitted to AUR. # libappindicator-gtk3 is loaded at runtime for the tray, so namcap cannot see it. pkgname=command-center -pkgver=0.7.0 +pkgver=0.7.1 pkgrel=1 pkgdesc='Local Linux workstation dashboard for repositories, backups, configuration and Toolbox' arch=('x86_64') diff --git a/src-tauri/Cargo.lock b/src-tauri/Cargo.lock index e5a505b..51e028c 100644 --- a/src-tauri/Cargo.lock +++ b/src-tauri/Cargo.lock @@ -345,7 +345,7 @@ dependencies = [ [[package]] name = "command-center" -version = "0.7.0" +version = "0.7.1" dependencies = [ "libc", "linutil_core", diff --git a/src-tauri/Cargo.toml b/src-tauri/Cargo.toml index 65e5064..2d76eb3 100644 --- a/src-tauri/Cargo.toml +++ b/src-tauri/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "command-center" -version = "0.7.0" +version = "0.7.1" description = "A Linux control deck for repositories, configuration, backup, and recovery" authors = ["Commander"] license = "MIT" diff --git a/src-tauri/tauri.conf.json b/src-tauri/tauri.conf.json index c42e37a..58df86e 100644 --- a/src-tauri/tauri.conf.json +++ b/src-tauri/tauri.conf.json @@ -1,7 +1,7 @@ { "$schema": "https://schema.tauri.app/config/2", "productName": "Command Center", - "version": "0.7.0", + "version": "0.7.1", "identifier": "io.helixstack.commandcenter", "build": { "beforeDevCommand": "npm run dev",