Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .github/workflows/harmony-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,15 @@ jobs:
- name: Verify Harmony HAR artifact
run: test -f harmony/pushy.har

- name: Verify the HAR native library carries no update wording
shell: bash
run: |
dir="$(mktemp -d)"
tar -xzf harmony/pushy.har -C "$dir"
libs="$(find "$dir" -path '*/libs/*' -name 'librnpushy.so')"
test -n "$libs"
node scripts/check-binary-strings.js $libs
Comment thread
sunnylqm marked this conversation as resolved.

- name: Type-check Harmony TS sources (required)
shell: bash
run: |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -302,7 +302,7 @@
"${PODS_CONFIGURATION_BUILD_DIR}/React-timing/React-timing_privacy.bundle",
"${PODS_CONFIGURATION_BUILD_DIR}/SSZipArchive/SSZipArchive.bundle",
"${PODS_ROOT}/../../node_modules/react-native-update/ios/pushy_build_time.txt",
"${PODS_CONFIGURATION_BUILD_DIR}/react-native-update/react-native-update_privacy.bundle",
"${PODS_CONFIGURATION_BUILD_DIR}/react-native-update/PushyPrivacy.bundle",
);
name = "[CP] Copy Pods Resources";
outputPaths = (
Expand All @@ -315,7 +315,7 @@
"${TARGET_BUILD_DIR}/${UNLOCALIZED_RESOURCES_FOLDER_PATH}/React-timing_privacy.bundle",
"${TARGET_BUILD_DIR}/${UNLOCALIZED_RESOURCES_FOLDER_PATH}/SSZipArchive.bundle",
"${TARGET_BUILD_DIR}/${UNLOCALIZED_RESOURCES_FOLDER_PATH}/pushy_build_time.txt",
"${TARGET_BUILD_DIR}/${UNLOCALIZED_RESOURCES_FOLDER_PATH}/react-native-update_privacy.bundle",
"${TARGET_BUILD_DIR}/${UNLOCALIZED_RESOURCES_FOLDER_PATH}/PushyPrivacy.bundle",
);
runOnlyForDeploymentPostprocessing = 0;
shellPath = /bin/sh;
Expand Down
2 changes: 2 additions & 0 deletions harmony/pushy/src/main/cpp/CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,8 @@ endif()
# keep exporting PushyTurboModule (JSI_EXPORT) for the host's PackageProvider.
if(NOT CMAKE_BUILD_TYPE STREQUAL "Debug")
target_compile_options(rnpushy PRIVATE
# NAPI_MODULE records __FILE__; keep the build path out of the binary.
-fmacro-prefix-map=${CMAKE_CURRENT_SOURCE_DIR}/=
-ffunction-sections
-fdata-sections
-fvisibility=hidden
Expand Down
6 changes: 6 additions & 0 deletions ios/RCTPushy/RCTPushy.mm
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,12 @@

#import <React/RCTConvert.h>
#import <React/RCTLog.h>
// RN's log macros pass __FILE__, which would embed this file's absolute build
// path in the binary; log with the bare file name instead.
#if RCTLOG_ENABLED
#undef _RCTLog
#define _RCTLog(lvl, ...) _RCTLogNativeInternal(lvl, __FILE_NAME__, __LINE__, __VA_ARGS__)
#endif
#import <objc/runtime.h>
#import <os/lock.h>

Expand Down
2 changes: 1 addition & 1 deletion react-native-update.podspec
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@ Pod::Spec.new do |s|
# Privacy manifest (required-reason APIs: disk space, file timestamps,
# system boot time, user defaults) delivered as its own resource bundle so
# static and dynamic integrations both carry it.
s.resource_bundles = { 'react-native-update_privacy' => ['ios/PrivacyInfo.xcprivacy'] }
s.resource_bundles = { 'PushyPrivacy' => ['ios/PrivacyInfo.xcprivacy'] }

s.dependency 'React'
s.dependency "React-Core"
Expand Down
57 changes: 57 additions & 0 deletions scripts/check-binary-strings.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
#!/usr/bin/env node
// Fails when a shipped native binary carries update/patch/rescue/reload wording
// in its string table (the `strings` view of the file): class and method names,
// log text, source paths and the like are kept neutral or encoded
// (scripts/encode-native-text.ts). Usage:
// node scripts/check-binary-strings.js <binary>...
'use strict';

const fs = require('fs');

const WORDING = /update|patch|rescue|reload|hotfix/i;
const MIN_LENGTH = 4;

function printableRuns(buffer) {
const runs = [];
let start = -1;
for (let i = 0; i <= buffer.length; i++) {
const byte = i < buffer.length ? buffer[i] : 0;
const printable = byte >= 0x20 && byte < 0x7f;
if (printable && start < 0) {
start = i;
} else if (!printable && start >= 0) {
if (i - start >= MIN_LENGTH) {
runs.push(buffer.toString('latin1', start, i));
}
start = -1;
}
}
return runs;
}

function findWording(file) {
return printableRuns(fs.readFileSync(file)).filter((run) => WORDING.test(run));
}

module.exports = { findWording };

if (require.main === module) {
const files = process.argv.slice(2);
if (files.length === 0) {
console.error('usage: check-binary-strings.js <binary>...');
process.exit(2);
}
let failed = false;
for (const file of files) {
const hits = findWording(file);
if (hits.length) {
failed = true;
for (const hit of hits) {
console.error(`error: ${file} contains ${JSON.stringify(hit)}`);
}
} else {
console.log(`ok: ${file} has no update wording in its strings`);
}
}
process.exit(failed ? 1 : 0);
}
9 changes: 9 additions & 0 deletions scripts/verify-android-so.js
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@
*/
const fs = require('fs');
const path = require('path');
const { findWording } = require('./check-binary-strings');

const LIB_DIR = path.resolve(__dirname, '..', 'android', 'lib');
const ABIS = ['arm64-v8a', 'armeabi-v7a', 'x86', 'x86_64'];
Expand Down Expand Up @@ -194,6 +195,14 @@ for (const abi of ABIS) {
}
}

const wording = findWording(soPath);
if (wording.length) {
for (const hit of wording) {
console.error(`error: ${soPath} contains ${JSON.stringify(hit)} in its strings`);
}
failed = true;
}

const staticJni = [...symbols].filter((symbol) => symbol.startsWith('Java_'));
if (staticJni.length) {
for (const symbol of staticJni) {
Expand Down
Loading