[FEATURE/SECURITY/BUG] Add hash key validation to check the files downloaded from external projects
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Domain
- build-system, security
Research direction
No source file or test is named. Locate the external-project download and unpack rules, starting with the LVGL variables and targets shown in the report, then inventory the other download rules; done means modified external files are detected rather than accepted during the build.
Written by the indexing model from the issue text.
Description
Description / Steps to reproduce the issue
Currently all external projects are downloaded/compiled without checking if their MD5/SHA are valid, so if their content get modified we will not know, ie:
LVGL_UNPACKNAME = lvgl
UNPACK ?= unzip -o $(if $(V),,-q)
CURL ?= curl -L -O $(if $(V),,-Ss)
LVGL_UNPACKDIR = $(WD)/$(LVGL_UNPACKNAME)
$(LVGL_TARBALL):
$(ECHO_BEGIN)"Downloading: $(LVGL_TARBALL)"
$(Q) $(CURL) $(CONFIG_GRAPH_LVGL_URL)/$(LVGL_TARBALL)
$(ECHO_END)
$(LVGL_UNPACKNAME): $(LVGL_TARBALL)
$(ECHO_BEGIN)"Unpacking: $(LVGL_TARBALL) -> $(LVGL_UNPACKNAME)"
$(Q) $(UNPACK) $(LVGL_TARBALL)
$(Q) mv lvgl-$(LVGL_VERSION) $(LVGL_UNPACKNAME)
$(Q) touch $(LVGL_UNPACKNAME)
$(ECHO_END)
On which OS does this issue occur?
[OS: Linux]
What is the version of your OS?
Ubuntu 24.04
NuttX Version
mainline
Issue Architecture
[Arch: all]
Issue Area
[Area: Examples]
Host information
No response
Verification
- I have verified before submitting the report.
- Dominant language
- C
- Stars
- 466
- Forks
- 783
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 30
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/nuttx-apps
-
[FEATURE] Shrink getprime runs for OSTestPossibly taken A pull request linked to this issue is open or already merged. OpenType: Enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
apache/nuttx-apps#3620 · 5 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
Type: Enhancement
Difficulty 3/5 1-2 days Newbie friendliness 68/100
apache/nuttx-apps#3796 · 1 comment ·
Maintainers usually reply within 1 day
-
[BUG] testing/sched/timerjitter: unexpected results under normal usagePossibly taken @RogerNext claimed this 69 days ago. OpenType: Bug
Difficulty 4/5 3-5 days Newbie friendliness 52/100
apache/nuttx-apps#3634 · 1 comment ·
Maintainers usually reply within 1 day
-
[TODO] move graphics/input -> input.May be free again @cederom claimed this 194 days ago, and no pull request is open. Open
apache/nuttx-apps#3436 · 1 assignee ·
Maintainers usually reply within 1 day
-
Type: Bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
apache/nuttx-apps#3407 · 14 comments ·
Maintainers usually reply within 1 day
All issues in apache/nuttx-apps
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
dkfans/keeperfx#5415 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
ARM-software/sysarch-acs#600 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
EchoTools/nevr-runtime#117 · 2 comments ·
Maintainers usually reply within 1 day