From cf34812381f0b8cae023307c29b37ded00bd4ad5 Mon Sep 17 00:00:00 2001 From: XhmikosR Date: Sun, 5 Jul 2026 17:06:36 +0300 Subject: [PATCH 1/3] Update GitHub Actions workflows - CodeQL: scan Actions workflows too, switch to build-mode none matrix, drop autobuild - container: attach build provenance and SBOM to the image - add timeout-minutes to all jobs --- .github/workflows/ci.yml | 1 + .github/workflows/codeql-analysis.yml | 20 +++++++++++++------ .github/workflows/container.yml | 3 +++ .../{depsreview.yaml => deps-review.yaml} | 5 ++++- 4 files changed, 22 insertions(+), 7 deletions(-) rename .github/workflows/{depsreview.yaml => deps-review.yaml} (90%) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4ff4ec9aa..2574d8546 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,6 +15,7 @@ jobs: test: name: Python ${{ matrix.python }} on ${{ matrix.os }} runs-on: ${{ matrix.os }} + timeout-minutes: 15 strategy: fail-fast: false diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index f7b75d69f..35e390b96 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -15,13 +15,23 @@ on: jobs: analyze: - name: Analyze + name: Analyze (${{ matrix.language }}) runs-on: ubuntu-latest + timeout-minutes: 30 permissions: actions: read contents: read security-events: write + strategy: + fail-fast: false + matrix: + include: + - language: actions + build-mode: none + - language: python + build-mode: none + steps: - name: Clone repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 @@ -31,13 +41,11 @@ jobs: - name: Initialize CodeQL uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: - languages: "python" + languages: ${{ matrix.language }} + build-mode: ${{ matrix.build-mode }} queries: +security-and-quality - - name: Autobuild - uses: github/codeql-action/autobuild@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 - - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: - category: "/language:python" + category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/container.yml b/.github/workflows/container.yml index 1990f50c2..6e2aee37c 100644 --- a/.github/workflows/container.yml +++ b/.github/workflows/container.yml @@ -15,6 +15,7 @@ jobs: build-and-push-image: name: Build and push container image runs-on: ubuntu-latest + timeout-minutes: 20 permissions: contents: read packages: write @@ -47,3 +48,5 @@ jobs: push: ${{ github.event_name != 'pull_request' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} + provenance: true + sbom: true diff --git a/.github/workflows/depsreview.yaml b/.github/workflows/deps-review.yaml similarity index 90% rename from .github/workflows/depsreview.yaml rename to .github/workflows/deps-review.yaml index e60722fff..771167c12 100644 --- a/.github/workflows/depsreview.yaml +++ b/.github/workflows/deps-review.yaml @@ -1,5 +1,7 @@ name: 'Dependency Review' -on: [pull_request] + +on: + pull_request: permissions: contents: read @@ -7,6 +9,7 @@ permissions: jobs: dependency-review: runs-on: ubuntu-latest + timeout-minutes: 10 steps: - name: Clone repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 From c912e408e69107d2a138af43f80bd2c5aec2ce13 Mon Sep 17 00:00:00 2001 From: XhmikosR Date: Sun, 5 Jul 2026 17:20:53 +0300 Subject: [PATCH 2/3] Reject domains with invalid characters in normalize_rule --- testUpdateHostsFile.py | 10 ++++++-- updateHostsFile.py | 53 ++++++++++++++++++++++++++---------------- 2 files changed, 41 insertions(+), 22 deletions(-) diff --git a/testUpdateHostsFile.py b/testUpdateHostsFile.py index 9de043aff..3f0ac45d1 100644 --- a/testUpdateHostsFile.py +++ b/testUpdateHostsFile.py @@ -837,7 +837,7 @@ class TestNormalizeRule(BaseStdout): def test_no_match(self): kwargs = dict(targetip="0.0.0.0", keep_domain_comments=False) - # Note: "Bare"- Domains are accepted. IP are excluded. + # Note: "Bare"- Domains are accepted. IPs are excluded. for rule in [ "128.0.0.1", "::1", @@ -847,6 +847,11 @@ class TestNormalizeRule(BaseStdout): "0.0.0.0 https", "0.0.0.0 https..", "0.0.0.0 foo.", + "0.0.0.0 cm076410.tw1.ru]", + "0.0.0.0 example.com[", + "0.0.0.0 exa mple.com", + "0.0.0.0 -example.com", + "0.0.0.0 example-.com", ]: self.assertEqual(normalize_rule(rule, **kwargs), (None, None)) @@ -934,7 +939,8 @@ class TestNormalizeRule(BaseStdout): "foo.bar.edu", "www.example-foo.bar.edu", "www.example-3045.foobar.com", - "www.example.xn--p1ai" + "www.example.xn--p1ai", + "philadelphia_cbslocal.us.intellitxt.com", ): expected = (rule, "0.0.0.0 " + rule + "\n") diff --git a/updateHostsFile.py b/updateHostsFile.py index 2a79fcef5..a29b2a21b 100755 --- a/updateHostsFile.py +++ b/updateHostsFile.py @@ -1022,6 +1022,33 @@ def remove_dups_and_excl(mergefile, exclusionregexes, outputfile=None): return finalfile +# Dot-separated labels of [a-z0-9_-], hyphens not at label ends, at least two +# labels. Expects a lowercased hostname. +VALID_DOMAIN_REGEX = re.compile( + r"(?:[a-z0-9_]|[a-z0-9_][a-z0-9_-]*[a-z0-9_])" + r"(?:\.(?:[a-z0-9_]|[a-z0-9_][a-z0-9_-]*[a-z0-9_]))+" +) + + +def is_valid_domain(hostname): + """ + Check whether a lowercased hostname looks like a valid domain name. + + Parameters + ---------- + hostname : str + The hostname to validate. + + Returns + ------- + valid : bool + Whether the hostname only contains characters allowed in a domain + name and has a valid label structure. + """ + + return bool(VALID_DOMAIN_REGEX.fullmatch(hostname)) + + def normalize_rule(rule, targetip, keep_domain_comments): """ Standardize and format the rule string provided. @@ -1144,33 +1171,19 @@ def normalize_rule(rule, targetip, keep_domain_comments): if ( is_ip(hostname) or re.search(static_ip_regex, hostname) - or "." not in hostname - or ".." in hostname - or "." in hostname[-1] - or "/" in hostname - or ":" in hostname + or not is_valid_domain(hostname) ): # Example: 0.0.0.0 127.0.0.1 - # If the hostname is: - # - an IP - or looks like it, - # - doesn't contain dots, or - # - contains repeated dots, - # - ends in a dot, or - # - contains a slash, or - # - contains a colon, - # - contains an underscore, - # we don't want to normalize it. + # If the hostname is an IP (or looks like one), or isn't a valid + # domain (bad characters, no dot, repeated/trailing dots, slash, + # colon, ...), we don't want to normalize it. return belch_unwanted(rule) return normalize_response(hostname, suffix) - if ( - not re.search(static_ip_regex, split_rule[0]) - and ":" not in split_rule[0] - and ".." not in split_rule[0] - and "/" not in split_rule[0] - and "." in split_rule[0] + if not re.search(static_ip_regex, split_rule[0]) and is_valid_domain( + split_rule[0].lower() ): # Deny anything that looks like an IP; doesn't container dots or INVALID. From 1c78d479204ddd09c4fa167a76a0037dce459afb Mon Sep 17 00:00:00 2001 From: Steven Black Date: Sun, 5 Jul 2026 11:12:27 -0400 Subject: [PATCH 3/3] =?UTF-8?q?Issue=20#3185:=20fix=20=E2=80=94=20add=20se?= =?UTF-8?q?veral=20domains=20related=20to=20athwartwhoafat.com.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- data/StevenBlack/hosts | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/data/StevenBlack/hosts b/data/StevenBlack/hosts index 73544eba7..b9102dc16 100644 --- a/data/StevenBlack/hosts +++ b/data/StevenBlack/hosts @@ -3195,3 +3195,16 @@ # Added June 30, 2026 0.0.0.0 block-apple.com + +# Added July 5, 2026 +0.0.0.0 0.athwartwhoafat.com +0.0.0.0 1.athwartwhoafat.com +0.0.0.0 2.athwartwhoafat.com +0.0.0.0 3.athwartwhoafat.com +0.0.0.0 4.athwartwhoafat.com +0.0.0.0 5.athwartwhoafat.com +0.0.0.0 6.athwartwhoafat.com +0.0.0.0 7.athwartwhoafat.com +0.0.0.0 8.athwartwhoafat.com +0.0.0.0 9.athwartwhoafat.com +0.0.0.0 athwartwhoafat.com