mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 03:00:18 +02:00
Harden the APK reader and build downloads after review
- frame_apk: android: attributes win over same-named attributes in other namespaces; string attributes that keep only a typed value (no raw string) still resolve; a failed icon read leaves the icon out instead of failing the install. - The clipboard IPC origin check can't throw on odd frame URLs. - fetch-deps.js: 60 s download timeout, at most 5 redirects, a SystemRoot fallback for tar.exe, and prunes pydoc_data, venv and the static libpython. - Docs keep the clipboard-tool note for running the UI in a browser. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
770f26c703
commit
d145537d9a
5 files changed
+65
-25
No files matched your search
+23
-5
@@ -27,10 +27,14 @@ def pool(strings, utf8=False):
|
||||
return struct.pack('<HHIIIIII', 1, 28, 28 + len(body), len(strings), 0, 0x100 if utf8 else 0, start, 0) + body
|
||||
|
||||
|
||||
def manifest(package, label_ref, version_ref, min_sdk):
|
||||
"""<manifest package versionName><uses-sdk minSdkVersion/><application label icon/></manifest>."""
|
||||
def manifest(package, label_ref, version_ref, min_sdk, package_raw=True, foreign_label=False):
|
||||
"""<manifest package versionName><uses-sdk minSdkVersion/><application label icon/></manifest>.
|
||||
|
||||
package_raw=False drops the package's raw string (as some repackers do);
|
||||
foreign_label adds a non-android `label` attribute after android:label.
|
||||
"""
|
||||
strings = ['label', 'icon', 'versionName', 'minSdkVersion', 'package', 'manifest', 'uses-sdk',
|
||||
'application', package]
|
||||
'application', package, 'junk', 'label'] # the second 'label' has no android id
|
||||
resmap = struct.pack('<4I', 0x01010001, 0x01010002, 0x0101021c, 0x0101020c)
|
||||
resmap = struct.pack('<HHI', 0x0180, 8, 8 + len(resmap)) + resmap
|
||||
|
||||
@@ -42,9 +46,11 @@ def manifest(package, label_ref, version_ref, min_sdk):
|
||||
|
||||
none = 0xffffffff
|
||||
chunks = (pool(strings) + resmap
|
||||
+ element(5, [(4, 8, frame_apk.T_STRING, 8), (2, none, frame_apk.T_REF, version_ref)])
|
||||
+ element(5, [(4, 8 if package_raw else none, frame_apk.T_STRING, 8),
|
||||
(2, none, frame_apk.T_REF, version_ref)])
|
||||
+ element(6, [(3, none, frame_apk.T_INT_DEC, min_sdk)])
|
||||
+ element(7, [(0, none, frame_apk.T_REF, label_ref), (1, none, frame_apk.T_REF, 0x7f020000)]))
|
||||
+ element(7, [(0, none, frame_apk.T_REF, label_ref), (1, none, frame_apk.T_REF, 0x7f020000)]
|
||||
+ ([(10, 9, frame_apk.T_STRING, 9)] if foreign_label else [])))
|
||||
return struct.pack('<HHI', 3, 8, 8 + len(chunks)) + chunks
|
||||
|
||||
|
||||
@@ -111,6 +117,18 @@ class ApkInfo(unittest.TestCase):
|
||||
self.assertEqual(info['version'], '')
|
||||
self.assertEqual(info['abis'], [])
|
||||
|
||||
def test_repacked_manifest(self):
|
||||
# Package kept only as a typed value; a foreign `label` mustn't beat android:label.
|
||||
arsc = resources({(1, '', 0): {0: 1, 1: 2}})
|
||||
info = self.read(apk({
|
||||
'AndroidManifest.xml': manifest('com.example.repacked', 0x7f010000, 0x7f010001, 24,
|
||||
package_raw=False, foreign_label=True),
|
||||
'resources.arsc': arsc,
|
||||
}))
|
||||
self.assertEqual(info['package'], 'com.example.repacked')
|
||||
self.assertEqual(info['label'], 'App label')
|
||||
self.assertIsNone(info['icon_png'])
|
||||
|
||||
def test_rejects_non_apks(self):
|
||||
for data in (b'not a zip', apk({'classes.dex': b''}), apk({'AndroidManifest.xml': b'<manifest/>'})):
|
||||
with self.assertRaises(frame_apk.ApkError):
|
||||
|
||||
Reference in new issue
Block a user