Skip to content

tools/check-hash: enhance hash validation and integrate with Make.defs, LVGL, and zlib - #3833

Open
Swatantra-66 wants to merge 1 commit into
apache:masterfrom
Swatantra-66:feature/check-hash
Open

Swatantra-66 wants to merge 1 commit into
apache:masterfrom
Swatantra-66:feature/check-hash

Conversation

@Swatantra-66

Copy link
Copy Markdown
Contributor

Summary

This PR addresses #3418 by enhancing the centralized tools/check-hash.sh script and integrating SHA256 checksum verification into graphics/lvgl and system/zlib as pilot implementations.

  1. tools/check-hash.sh Enhancements:

    • Replaced legacy which checks with POSIX command -v.
    • Maintained a 100% shell-based implementation using standard utilities (command -v, awk, tr) without Python dependencies.
    • Added support for md5 alongside sha1|sha224|sha256|sha384|sha512 for legacy packages, while using SHA256+ for new and updated packages.
    • Normalized hashes to lowercase using tr '[:upper:]' '[:lower:]' for case-insensitive comparison.
    • Added graceful bypass support when the expected hash is explicitly set to skip, none, or empty.
    • Automatically removes corrupted/tampered files (rm -f) upon mismatch so subsequent build attempts re-download cleanly.
  2. Make.defs Centralization:

    • Defined CHECKHASH ?= $(APPDIR)$(DELIM)tools$(DELIM)check-hash.sh under # Tools to standardize invocation across all apps Makefiles.
  3. graphics/lvgl & system/zlib Integration:

    • Added LVGL_TARBALL_SHA256 and ZLIB_TARBALL_SHA256 with ?= to allow user overrides.
    • Validates checksums both upon download and immediately before unpacking (ensuring pre-existing or cached archives cannot bypass verification).
    • Added matching URL_HASH SHA256=... to CMake FetchContent_Declare.

Fixes #3418

Impact

  • Security / Integrity: Prevents corrupted, incomplete, or tampered external archives from being unpacked and built into NuttX binaries.
  • Build Process: Seamless. Fresh downloads and cached archives are verified before extraction.
  • Compatibility: 100% backward-compatible. Users can override hashes via <PKG>_TARBALL_SHA256 or bypass validation if using bleeding-edge unversioned sources.

Testing

  • Host: Windows 11 x86_64 (Git Bash / POSIX sh)
  • Script Validation:
    • Exact SHA256 match -> Passes (exit code 0).
    • Uppercase SHA256 match -> Passes (exit code 0).
    • Explicit bypass (skip / none) -> Emits warning and passes (exit code 0).
    • Mismatch / corrupted file -> Reports error, removes corrupted archive, and fails (exit code 1).
    • Cached archive verification prior to unpack -> Verified.
  • Code Style:
    • tools/checkpatch.sh -p HEAD -> 0 errors, 0 warnings.

Enhance tools/check-hash.sh and integrate automated hash checking for external downloads:
1. tools/check-hash.sh:
   - Replace which with POSIX command -v.
   - Support md5 alongside sha1/sha224/sha256/sha384/sha512.
   - Keep 100% shell-based (command -v, awk) without Python dependencies.
   - Normalize hashes to lowercase for case-insensitive comparison.
   - Support optional bypass when expected hash is empty, "none", or "skip".
   - Remove corrupted downloads on hash mismatch.
2. Make.defs:
   - Centralize CHECKHASH (?= $(APPDIR)$(DELIM)tools$(DELIM)check-hash.sh).
3. graphics/lvgl & system/zlib:
   - Add SHA256 validation both on download and prior to unpacking.
   - Add matching URL_HASH in CMakeLists.txt (FetchContent_Declare).

Fixes apache#3418.

Signed-off-by: Swatantra Yadav <maverickswatantra@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FEATURE/SECURITY/BUG] Add hash key validation to check the files downloaded from external projects

1 participant