Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CONTROL/control
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
Package: enigma2-plugin-extensions-linuxsat-panel
Version: 3.0.5
Version: 3.0.6
Description: addons panel
Section: extra
Priority: optional
Expand Down
13 changes: 11 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

<p align="center">
<a href="https://github.com/Belfagor2005/LinuxsatPanel">
<img src="https://img.shields.io/badge/Version-3.0.5-blue.svg" alt="Version">
<img src="https://img.shields.io/badge/Version-3.0.6-blue.svg" alt="Version">
</a>

<a href="https://creativecommons.org/licenses/by-nc-sa/4.0/">
Expand Down Expand Up @@ -54,7 +54,16 @@

## 🗓️ Version History

### v3.0.5 (Current)
### v3.0.6 (Current)
- Security: removed --no-check-certificate from every wget install/update call
- Hardened lsConsole and checkskin temp files against local symlink attacks
- Fixed LCN scan (Order LCN Bouquet) always logging a false error even on success
- Fixed possible crash/misfile reading lcndb entries with an unexpected mode
- Fixed commits cache never actually loading (str repr vs JSON mismatch)
- Fixed crash risk in RTL/Arabic font loading (add_skin_fonts)
- Removed unused translate_utils.py and duplicate code

### v3.0.5
- Added Commit History viewer (INFO button -> Commit History)
- LSinfo now supports 3 modes: info/about/commits
- Commit list shows date, author, message and hash
Expand Down
6 changes: 3 additions & 3 deletions installer.sh
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
#!/bin/bash

version='3.0.5'
changelog="\n--Added Commit History viewer (INFO button -> Commit History)\n--LSinfo now supports 3 modes: info/about/commits\n--Commit list shows date, author, message and hash\n--Added cache system for commits (saves to commits_cache.json)\n--Auto-refresh cache every 24 hours\n--Rate limit handling with fallback to cached data\n--Updated info.txt with clean formatting (no special chars)\n--Fixed AsyncMixin inheritance for LSinfo\n--Fixed console output for script execution (removed redirections)\n--Updated README.md to v3.0.5"
version='3.0.6'
changelog="\n--Security: removed --no-check-certificate from every wget install/update call\n--Hardened lsConsole and checkskin temp files against local symlink attacks\n--Fixed LCN scan (Order LCN Bouquet) always logging a false error\n--Fixed possible crash reading lcndb/service data with an unexpected mode\n--Fixed commits cache never actually loading (str repr vs JSON mismatch)\n--Fixed crash risk in RTL/Arabic font loading (add_skin_fonts)\n--Removed unused translate_utils.py and duplicate code\n--Updated README.md to v3.0.6"

TMPPATH=/tmp/LinuxsatPanel-install
FILEPATH=/tmp/LinuxsatPanel-main.tar.gz
Expand Down Expand Up @@ -87,7 +87,7 @@ install_pkg() {
install_pkg "$Packagerequests"

echo "Downloading LinuxsatPanel..."
wget --no-check-certificate 'https://github.com/Belfagor2005/LinuxsatPanel/archive/refs/heads/main.tar.gz' -O "$FILEPATH"
wget 'https://github.com/Belfagor2005/LinuxsatPanel/archive/refs/heads/main.tar.gz' -O "$FILEPATH"
if [ $? -ne 0 ]; then
echo "Failed to download LinuxsatPanel package!"
cleanup
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -193,6 +193,9 @@ def readE2Services(self, serviceType):
refstr = '%s ORDER BY name' % (self.service_types_tv)
elif serviceType == "RADIO":
refstr = '%s ORDER BY name' % (self.service_types_radio)
else:
print("Unknown serviceType '%s', skipping." % serviceType)
return
ref = eServiceReference(refstr)
serviceHandler = eServiceCenter.getInstance()
servicelist = serviceHandler.list(ref)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -257,6 +257,11 @@ def matchLCNsAndServices(mode, lcndb, services, duplicate, renumbers):
elif data[self.LCNS_MEDIUM] in ("A", "T"):
lcnCache = terrestrialCache
serviceLCNs = terrestrialLCNs
else:
print(
"[LCNScanner] Warning: Unknown medium '{}' for service '{}', skipping!".format(
data[self.LCNS_MEDIUM], data[self.LCNS_SERVICEREFERENCE]))
continue

if service in services:
if lcn in lcnCache:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@
__email__ = "ekekaz@gmail.com"
__copyright__ = 'Copyright (c) 2024 Lululla'
__license__ = "GPL-v2"
__version__ = "3.0.5"
__version__ = "3.0.6"


def check_and_install_requests():
Expand Down Expand Up @@ -75,10 +75,6 @@ def check_and_install_requests():
PluginLanguagePath = 'Extensions/LinuxsatPanel/locale'
plugin_path = dirname(sys.modules[__name__].__file__)
AgentRequest = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3'
# used by translate_utils
DEBUG = False
HEADERS = {"User-Agent": AgentRequest}
SYSTEM_DIR = plugin_path
infourl = 'https://raw.githubusercontent.com/Belfagor2005/upload/main/fill/info.txt'
abouturl = 'https://raw.githubusercontent.com/Belfagor2005/upload/main/fill/about.txt'
xmlurl = 'https://raw.githubusercontent.com/Belfagor2005/upload/main/fill/addons_2024.xml'
Expand Down Expand Up @@ -506,6 +502,11 @@ def add_skin_fonts():
from enigma import addFont
FNTPath = join(plugin_path, "fonts")
font_config = {
RT_HALIGN_RIGHT: {
'regular': 'DejaVuSans.otf',
'medium': 'DejaVuSans.otf',
'bold': 'DejaVuSans.otf'
},
RT_HALIGN_LEFT: {
'regular': 'ls-regular.ttf',
'medium': 'ls-medium.ttf',
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -61,16 +61,6 @@ def newOE():
return boo


patterns_to_remove = [
r'scrollbarWidth="[^"]*"',
r'scrollbarSliderBorderWidth="[^"]*"',
r'textoffsets\s*="[^"]*"',
r'secondfont\s*="[^"]*"',
r'scrollbarBorderWidth="[^"]*"',
r'scrollbarForegroundColor="[^"]*"',
r'scrollbarBorderColor="[^"]*"'
]

# scrollbarMode="
patterns_to_remove = [
r'scrollbarWidth="[^"]*"',
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,16 +45,21 @@
user_log = tmplog + 'my_debug.log'


def _safe_open(path, mode):
"""Open a fixed, predictable /tmp path for write/append without
following a symlink another local user may have planted there."""
flags = os.O_CREAT | os.O_WRONLY | os.O_NOFOLLOW
flags |= os.O_APPEND if 'a' in mode else os.O_TRUNC
fd = os.open(path, flags, 0o600)
if PY3:
return os.fdopen(fd, mode, encoding="utf-8")
return os.fdopen(fd, mode)


# Funzione di logging compatibile con Python 2 e 3
try:
if PY3:
# Python 3: usa encoding
with open(user_log, "w", encoding="utf-8") as log_file:
log_file.write("Log Initialized\n")
else:
# Python 2: no encoding parameter
with open(user_log, "w") as log_file:
log_file.write("Log Initialized\n")
with _safe_open(user_log, "w") as log_file:
log_file.write("Log Initialized\n")
except Exception as e:
print("Error initializing log: %s" % str(e))

Expand All @@ -63,12 +68,11 @@ def checklogskin(data):
try:
print(colorstart + str(data) + colorend) # stampa sul terminale
if PY3:
# Python 3
with open(user_log, "a", encoding="utf-8") as log_file:
with _safe_open(user_log, "a") as log_file:
log_file.write("\n:> " + str(data))
else:
# Python 2
with open(user_log, "a") as log_file:
with _safe_open(user_log, "a") as log_file:
log_file.write("\n:> " + str(data).encode('utf-8'))
except Exception as e:
print("Error logging data: %s" % str(e))
Expand Down Expand Up @@ -202,11 +206,11 @@ def check_module_skin():
if user_skin:
user_skin = "<skin>\n" + user_skin + "</skin>\n"
if PY3:
with open(user_skin_file, "w", encoding="utf-8") as myFile:
with _safe_open(user_skin_file, "w") as myFile:
checklogskin("write myFile %s" % user_skin_file)
myFile.write(user_skin)
else:
with open(user_skin_file, "w") as myFile:
with _safe_open(user_skin_file, "w") as myFile:
checklogskin("write myFile %s" % user_skin_file)
myFile.write(user_skin.encode('utf-8'))

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@
import sys
import codecs
import os
import tempfile
import gettext
_ = gettext.gettext

Expand Down Expand Up @@ -106,6 +107,7 @@ def __init__(
self.container.dataAvail_conn = self.container.dataAvail.connect(
self.dataAvail)
self.onLayoutFinish.append(self.startRun)
self._scripts = []

def updateTitle(self):
self.setTitle(self.newtitle)
Expand All @@ -119,18 +121,34 @@ def execScript(self, cmd):
directly. Writing the command to a real temp script and running
that removes every one of those differences - a script file is
always interpreted by /bin/sh exactly as written.

The file is created with mkstemp (unique name, opened exclusively,
0600 by default) rather than a predictable path, to avoid a local
symlink/race attack on the shared /tmp directory.
"""
script = '/tmp/.lsconsole_%d.sh' % self.run
try:
with codecs.open(script, 'w', encoding='utf-8') as f:
f.write('#!/bin/sh\n')
f.write(cmd + '\n')
os.chmod(script, 0o755)
fd, script = tempfile.mkstemp(
prefix='.lsconsole_', suffix='.sh', dir='/tmp')
content = '#!/bin/sh\n' + cmd + '\n'
if not isinstance(content, bytes):
content = content.encode('utf-8')
with os.fdopen(fd, 'wb') as f:
f.write(content)
os.chmod(script, 0o700)
except (IOError, OSError) as e:
print('[Console] cannot write run script:', e)
return self.container.execute(cmd) # last-resort fallback
self._scripts.append(script)
return self.container.execute('/bin/sh ' + script)

def _cleanupScripts(self):
while self._scripts:
script = self._scripts.pop()
try:
os.remove(script)
except OSError:
pass

def startRun(self):
if self.showStartStopText:
self['text'].setText(_('Execution progress\n\n'))
Expand Down Expand Up @@ -204,6 +222,7 @@ def cancelCallback(self, ret=None):
self.container.appClosed_conn = None
self.container.dataAvail_conn = None
self.container.kill()
self._cleanupScripts()
self.close()

def closeConsole(self):
Expand All @@ -214,6 +233,7 @@ def closeConsole(self):
except BaseException:
self.container.appClosed_conn = None
self.container.dataAvail_conn = None
self._cleanupScripts()
self.close()
else:
self.show()
Expand Down
Loading
Loading