diff --git a/copyparty/__version__.py b/copyparty/__version__.py index c53f5bf9c..60143e4c9 100644 --- a/copyparty/__version__.py +++ b/copyparty/__version__.py @@ -1,8 +1,8 @@ # coding: utf-8 -VERSION = (1, 20, 17) +VERSION = (1, 20, 18) CODENAME = "sftp is fine too" -BUILD_DT = (2026, 7, 6) +BUILD_DT = (2026, 7, 9) S_VERSION = ".".join(map(str, VERSION)) S_BUILD_DT = "{0:04d}-{1:02d}-{2:02d}".format(*BUILD_DT) diff --git a/docs/changelog.md b/docs/changelog.md index 9ec6cbf22..70a9b1c42 100644 --- a/docs/changelog.md +++ b/docs/changelog.md @@ -1,3 +1,59 @@ +▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ +# 2026-0706-1937 `v1.20.17` SECURITY: fix dirkeys + +## ⚠️ ATTN: this release fixes a dirkey vulnerability + +in volumes with **both** [dirkeys](https://github.com/9001/copyparty/#dirkeys) and [filekeys](https://github.com/9001/copyparty/#filekeys) enabled (default-disabled), a valid filekey could be converted into a dirkey, granting read-access to the containing folder + +## recent important news + +* [v1.20.17 (2026-07-06)](https://github.com/9001/copyparty/releases/tag/v1.20.17) fixed a vuln when a volume has both filekeys and dirkeys enabled +* [v1.20.17 (2026-07-06)](https://github.com/9001/copyparty/releases/tag/v1.20.17) introduced csp nonces, possibly breaking some javascript-based plugins + +## 🧪 new features + +* enforce csp nonces on javascript (additional xss defense) d3b95994 + * this could *possibly* break some aftermarket javascript-based plugins ([--js-browser](https://copyparty.eu/cli/#g-js-browser) / [--html-head](https://copyparty.eu/cli/#g-html-head)) + * now probably safe to disable the markdown/logue sandboxes ([--no-sb-md](https://copyparty.eu/cli/#g-no-sb-md) / `--no-sb-lg`) in most deployments, avoiding #230 +* sandbox ffmpeg/ffprobe in bwrap to defend against future FFmpeg vulns efa43f89 85be3b8d + * doesn't work in docker / podman, so `initcfg` in the images have [use-bwrap: n](https://copyparty.eu/cli/#g-use-bwrap) to disable it db68353e + * doesn't work in [prisonparty](https://github.com/9001/copyparty/blob/hovudstraum/bin/prisonparty.sh) either... pain peko +* #1535 cbz-reader: go-to-page (thx @romfir!) 12d877b0 +* volflags `plainreadme` and `plainlogues` to show readmes/logues as plaintext 9fa950bc +* volflags for `no_readme` and `no_logues` (previously global-only) 379c0aa6 +* u2c: new mode to calculate wark from data on stdin 90639de9 +* #1504 `--ftp-banner` 8242e693 + +## 🩹 bugfixes + +* GHSA-x5pq-m9p8-f4vx (dir/filekey confusion) (thx @poolcritter!) e4075533 +* fix resuming xbu-relocated partial uploads 5beecd66 +* fix resuming partial uploads after server restart 22c3a3dd +* openbsd: fix signal masking for custom signals a00bc93f +* #1119 #1528 fix directory sort-order edgecases (thx @NecRaul!) d33d1132 +* #1526 fix [--rotf-tz](https://copyparty.eu/cli/#g-rotf-tz); was effectively volflag-only (thx @NecRaul!) e017b1bc + +## 🔧 other changes + +* ffmpeg: remove lots of obscure codecs and formats for improved security 4c820301 +* textfile-editor: some tweaks to the autobackup feature; + * option [--md-nhist](https://copyparty.eu/cli/#g-md-nhist) to limit the number of old versions to keep 34c856e8 + * browsing old versions is now default-disabled; [--show-hist](https://copyparty.eu/cli/#g-show-hist) reenables it fa1499ae +* #1512 web-ui: if mkdir fails because folder already exists, then just cd into it 5dbff4af +* #1519 sftp: reduce excessive spam from portscanners 8c4e9313 +* make database corruption more obvious on startup (usually due to broken server filesystem/hardware) be31a744 +* docker: + * #1532 add LABELs for version and creationtime 32d074ff + * updated the [image compatibility matrix](https://github.com/9001/copyparty/tree/hovudstraum/scripts/docker#editions) c3eb9ece + * the `iv` image is no longer available for arm32 / armv6 6e75faa6 + +## 🌠 fun facts + +* contains patches powered by [seventhrun - the ill shit](https://www.youtube.com/watch?v=_QW8mY663Ho&list=PLBO2h-GzDvIYRmupTCAasjzDjNxvjG639&index=12) + the rest of basschasers2 on [the Oslo-Bergen line](https://a.ocv.me/pub/g/2026/07/PXL_20260702_190436425b.jpg?cache), 1110 masl +* to those who celebrate, happy 6/7 + + + ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ # 2026-0526-1845 `v1.20.16` s6-ready diff --git a/scripts/make-sfx.sh b/scripts/make-sfx.sh index 7aa04cc80..89669bf7d 100755 --- a/scripts/make-sfx.sh +++ b/scripts/make-sfx.sh @@ -604,8 +604,8 @@ done cd copyparty/web [ -e w.hash.js.gz ] || [ -e w.hash.js ] && { echo modding sha512.hw.js - [ -e deps/sha512.hw.js.gz ] && gzip -d deps/sha512.hw.js.gz - [ -e w.hash.js.gz ] && gzip -d w.hash.js + [ -e deps/sha512.hw.js.gz ] && gzip -df deps/sha512.hw.js.gz + [ -e w.hash.js.gz ] && gzip -df w.hash.js iawk '/copyparty/{exit}/./' deps/sha512.hw.js printf '\n\n\n\n\n' >> deps/sha512.hw.js cat w.hash.js >> deps/sha512.hw.js diff --git a/scripts/pyinstaller/deps.sha512 b/scripts/pyinstaller/deps.sha512 index d8722d7a1..d4db55014 100644 --- a/scripts/pyinstaller/deps.sha512 +++ b/scripts/pyinstaller/deps.sha512 @@ -31,5 +31,5 @@ a726fb46cce24f781fc8b55a3e6dea0a884ebc3b2b400ea74aa02333699f4955a5dc1e2ec5927ac7 efcb9da8e6f50cb5ea8e1d41e631e89b6f852b68a2568619a6ec151267e7fac94aba1e36317341c4fc5df822215b7ab9dd6b33cfb738e1b8423d4f0f6cff9525 pillow-12.3.0-cp313-cp313-win_amd64.whl b9b98714dfca6fa80b0b3f222965724d63be9c54d19435d1fe768e07016913d6db8d6e043fcb185b55a9bd6fe370a80cf961814fc096046a5f4640d99ed575ef pyinstaller-6.15.0-py3-none-win_amd64.whl cad0f7cf39de691813b1d4abc7d33f8bda99a87d9c5886039b814752e8690364150da26fb61b3e28d5698ff57a90e6dcd619ed2b64b04f72b5aadb75e201bdb0 pyinstaller_hooks_contrib-2025.8-py3-none-any.whl -368ea2da3e3bfe765a37c62227e84774853aaabce6954475fa45c873e5547cb5346ca03a0f6a0789af369285bb3464881fed0275a19066913d9d396d5d9b9947 python-3.13.13-amd64.exe +d0d23fd4ae8900764df664803844155994b253ed449b9ed54ea020fbfa7aaea8800ca1928e4a7f26b9278613f8bce27ef9a424cfcc4ca15551c7e4e1b78f3991 python-3.13.14-amd64.exe 2a0420f7faaa33d2132b82895a8282688030e939db0225ad8abb95a47bdb87b45318f10985fc3cee271a9121441c1526caa363d7f2e4a4b18b1a674068766e87 setuptools-80.9.0-py3-none-any.whl diff --git a/scripts/pyinstaller/notes.txt b/scripts/pyinstaller/notes.txt index 0cee86aa8..e8dc011cf 100644 --- a/scripts/pyinstaller/notes.txt +++ b/scripts/pyinstaller/notes.txt @@ -42,7 +42,7 @@ fns=( pillow-12.3.0-cp313-cp313-win_amd64.whl pyinstaller-6.15.0-py3-none-win_amd64.whl pyinstaller_hooks_contrib-2025.8-py3-none-any.whl - python-3.13.13-amd64.exe + python-3.13.14-amd64.exe setuptools-80.9.0-py3-none-any.whl ) [ $w7 ] && fns+=(