From bde4b0d4504781e3596d3c7193eda6ae3373f193 Mon Sep 17 00:00:00 2001 From: Josh Schmelzle Date: Tue, 22 Sep 2026 23:21:59 -0400 Subject: [PATCH] fix: validate Debian versions with dpkg and honor the changelog input The validity check used a PCRE-style regex with grep -E: GNU grep warned on every run (stray \ before d, ? at start of expression) and it accepted invalid versions such as 2.3.7-. Use dpkg --validate-version instead. Both workflows declared debian_changelog_file_path but read debian/changelog regardless; read the input (via env). check-py-deb-pkg-versions-match also strips a Debian epoch before comparing with __version__, so 1:2.3.7-1 matches 2.3.7. Results are unchanged for every current caller (wlanpi-core, wlanpi-mcp, wlanpi-profiler, wlanpi-webui, wlanpi-fpms); none passes a custom changelog path. --- .../workflows/check-py-deb-pkg-versions-match.yml | 13 +++++++------ .github/workflows/get-formatted-version-string.yml | 9 +++++---- 2 files changed, 12 insertions(+), 10 deletions(-) diff --git a/.github/workflows/check-py-deb-pkg-versions-match.yml b/.github/workflows/check-py-deb-pkg-versions-match.yml index 5250801..731cbd0 100644 --- a/.github/workflows/check-py-deb-pkg-versions-match.yml +++ b/.github/workflows/check-py-deb-pkg-versions-match.yml @@ -32,14 +32,16 @@ jobs: - name: Extract Version from Debian changelog id: extract-version + env: + CHANGELOG: ${{ inputs.debian_changelog_file_path }} run: | - DEB_VERSION=$(head -n 1 debian/changelog | sed -E 's/.*\(([^)]+)\).*/\1/') + DEB_VERSION=$(head -n 1 "$CHANGELOG" | sed -E 's/.*\(([^)]+)\).*/\1/') if [ -z "$DEB_VERSION" ]; then - echo "Error: failed to parse or find version on the first line of debian/changelog" + echo "Error: failed to parse or find version on the first line of $CHANGELOG" exit 1 fi - # Strip the debian revision (e.g., -1) for Python package version - PY_COMPAT_DEB_VERSION=$(echo "$DEB_VERSION" | sed -E 's/-.*//') + # Strip the epoch (e.g., 1:) and debian revision (e.g., -1) for Python package version + PY_COMPAT_DEB_VERSION=$(echo "$DEB_VERSION" | sed -E 's/^[0-9]+://; s/-.*//') if [ -z "$PY_COMPAT_DEB_VERSION" ]; then echo "Error: failed to set PY_COMPAT_DEB_VERSION from DEB_VERSION" exit 1 @@ -51,8 +53,7 @@ jobs: - name: Check if Debian version is valid run: | - debian_version_regex='^(\d+!)?[0-9][A-Za-z0-9.\+~:-]*(?:-[A-Za-z0-9.\+~]+)?$' - if ! echo "$DEB_VERSION" | grep -Eq "$debian_version_regex"; then + if ! dpkg --validate-version "$DEB_VERSION"; then echo "Error: Invalid Debian version format detected: $DEB_VERSION" exit 1 else diff --git a/.github/workflows/get-formatted-version-string.yml b/.github/workflows/get-formatted-version-string.yml index a5e8032..7238f3c 100644 --- a/.github/workflows/get-formatted-version-string.yml +++ b/.github/workflows/get-formatted-version-string.yml @@ -26,10 +26,12 @@ jobs: - name: Extract Version from Debian Changelog id: extract-version + env: + CHANGELOG: ${{ inputs.debian_changelog_file_path }} run: | - DEB_VERSION=$(head -n 1 debian/changelog | sed -E 's/.*\(([^)]+)\).*/\1/') + DEB_VERSION=$(head -n 1 "$CHANGELOG" | sed -E 's/.*\(([^)]+)\).*/\1/') if [ -z "$DEB_VERSION" ]; then - echo "Error: failed to parse or find version on the first line of debian/changelog" + echo "Error: failed to parse or find version on the first line of $CHANGELOG" exit 1 fi echo "DEB_VERSION=$DEB_VERSION" >> "$GITHUB_ENV" @@ -37,8 +39,7 @@ jobs: - name: Check if Debian version is valid run: | - debian_version_regex='^(\d+!)?[0-9][A-Za-z0-9.\+~:-]*(?:-[A-Za-z0-9.\+~]+)?$' - if ! echo "$DEB_VERSION" | grep -Eq "$debian_version_regex"; then + if ! dpkg --validate-version "$DEB_VERSION"; then echo "Error: Invalid Debian version format detected: $DEB_VERSION" exit 1 else