Skip to content

chore: prepare rc.7 with update-path hardening - #14

Merged
exploitintel merged 1 commit into
mainfrom
chore/prepare-rc7
Sep 15, 2026
Merged

exploitintel merged 1 commit into
mainfrom
chore/prepare-rc7

Conversation

@exploitintel

Copy link
Copy Markdown
Owner

Release vehicle for the merged update-path verification (PR 13): the Forge pin is unchanged at 9fc72e340be66a6dae5323ad91de6ae97972d923, and this bump advances the module to version 0.1.0-rc.7 with versionCode 9. The rc.7 installer is the first release whose update path proves installed module bytes (bundled-busybox verification, marker-safe prune with a count invariant, engine identity single-sourced from the in-bundle pin).

Comment thread module/module.prop
Comment on lines +3 to +4
version=0.1.0-rc.7
versionCode=9

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed against the focus areas (boot safety, device/build pin, kernel config, KernelSU module lifecycle, ext4 loop mounting, Docker startup, Wi-Fi routing, packaging, accidental firmware/credential/artifact inclusion). This PR's only effective change relative to main is this version bump — no other tracked file differs.

Checked this specific change for correctness:

  • versionCode 8→9 is a valid monotonic increase, matching ^[1-9][0-9]*$ as required by module/uninstall.sh's strict read_module_version awk parser (module.prop line 4) and tools/assemble-module.py's installer_positive_integer check.
  • version=0.1.0-rc.7 matches ^[A-Za-z0-9][A-Za-z0-9._+-]*$ (uninstall.sh line 3 check and assemble-module.py's SAFE_NAME_PATTERN), and the file is still exactly 6 lines, satisfying the parser's NR != 6 end check.
  • No other tracked file hardcodes the old string 0.1.0-rc.6 or versionCode=8 that needed updating (tests/simple-installer.test.mjs uses an unrelated self-contained fixture with its own 0.1.0-rc.5/8, not read from this file).
  • git ls-files shows no firmware images, boot images, keys, or generated build artifacts committed; .gitignore already excludes artifacts/, kernel/out/, deployment/payload/, *.apk, *.jks, *.keystore.
  • DEVICE.json / kernel/builds.json still consistently pin akita / CP2A.260805.005, unaffected by this change.

No actionable correctness or regression issue found in this diff.

@exploitintel
exploitintel merged commit bc15837 into main Sep 15, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant