{"record":{"id":"57ce5b028760a6a5","repo":"Hmbown/CodeWhale","slug":"the-update-download-redirected-to-an-unexpected-host","errorCode":null,"errorMessage":"The update download redirected to an unexpected host.","messagePattern":"The update download redirected to an unexpected host\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"crates/tui/plugins/computer-use/app/updates.mjs","lineNumber":93,"sourceCode":"    try { expanded=method===0?payload.length:inflateRawSync(payload,{maxOutputLength:Math.max(size,1)}).length; }\n    catch { throw new Error(\"Invalid or oversized compressed update entry.\"); }\n    if(expanded!==size) throw new Error(\"The update entry size did not match its contents.\");\n    position+=46+length+extra+comment;\n  }\n  if(position!==end) throw new Error(\"Invalid update archive length.\");\n  return count;\n}\n\nexport async function prepareUpdate(update) {\n  if(!update?.available) throw new Error(\"Check for an available update first.\");\n  if(!newerVersion(update.version,APP_VERSION)||update.url!==`${repository}/releases/download/v${update.version}/Codewhale-Computer-Use-${update.version}-macos-universal.zip`||!Number.isSafeInteger(update.size)||update.size<=0||update.size>limit) throw new Error(\"The update identity is invalid.\");\n  // Only GitHub's fixed release URL and its asset CDN can serve the bytes.\n  let url=update.url, response;\n  for(let redirects=0;redirects<4;redirects++) {\n    response=await fetch(url,{redirect:\"manual\",signal:AbortSignal.timeout(60_000)});\n    if(![301,302,303,307,308].includes(response.status)) break;\n    const next=new URL(response.headers.get(\"location\"),url);\n    if(next.protocol!==\"https:\"||![\"github.com\",\"release-assets.githubusercontent.com\",\"objects.githubusercontent.com\"].includes(next.hostname)) throw new Error(\"The update download redirected to an unexpected host.\");\n    url=next.href;\n  }\n  if(!response?.ok) throw new Error(\"The update could not be downloaded. Your current app is unchanged.\");\n  const bytes=await responseBytes(response,update.size);\n  if(bytes.length!==update.size||crypto.createHash(\"sha256\").update(bytes).digest(\"hex\")!==update.sha256) throw new Error(\"The update checksum did not match. Your current app is unchanged.\");\n  validateReleaseZip(bytes);\n  const stage=fs.mkdtempSync(path.join(os.tmpdir(),\"codewhale-cu-release-\"));\n  try {\n    const archive=path.join(stage,\"release.zip\"); fs.writeFileSync(archive,bytes,{mode:0o600});\n    const result=spawnSync(\"ditto\",[\"-x\",\"-k\",archive,stage],{encoding:\"utf8\"});\n    if(result.status!==0) throw new Error(\"The update could not be unpacked.\");\n    const bundle=path.join(stage,`${APP_NAME}.app`); verifyReleaseBundle(bundle);\n    const version=spawnSync(\"/usr/libexec/PlistBuddy\",[\"-c\",\"Print :CFBundleShortVersionString\",path.join(bundle,\"Contents\",\"Info.plist\")],{encoding:\"utf8\"});\n    if(version.status!==0||version.stdout.trim()!==update.version) throw new Error(\"The downloaded app has a different version.\");\n    return {stage,bundle};\n  } catch(error) { fs.rmSync(stage,{recursive:true,force:true}); throw error; }\n}\n","sourceCodeStart":75,"sourceCodeEnd":111,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/plugins/computer-use/app/updates.mjs#L75-L111","documentation":"During download, prepareUpdate() follows up to 4 HTTP redirects manually. Each redirect target must be https and on one of the allowed hosts: github.com, release-assets.githubusercontent.com, or objects.githubusercontent.com. A redirect to any other protocol or hostname is rejected to prevent the update binary from being served by an attacker-controlled server.","triggerScenarios":"The GitHub release URL or asset CDN responds with a 301/302/303/307/308 whose Location header points to a non-https URL or a hostname outside the allowlist (e.g. a corporate proxy, a mirror domain, or a malicious redirect injected between the client and GitHub).","commonSituations":"Corporate HTTPS proxies or DNS filtering appliances rewriting GitHub redirects; HTTPS interception middleboxes that re-host release assets; DNS hijacking or hosts-file overrides pointing github.com elsewhere; testing with a local mirror server that redirects to an unlisted host.","solutions":["Remove any proxy, TLS-interception, or DNS override that rewrites github.com / *.githubusercontent.com redirects to a different host.","Test the redirect chain (curl -sIL <release url>) and confirm every Location lands on github.com, release-assets.githubusercontent.com, or objects.githubusercontent.com over https.","If you operate a mirror, host the asset at the exact expected release URL instead of redirecting to a third-party domain.","Retry the update from an unrestricted network if a security appliance is intercepting traffic."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try { await prepareUpdate(update); } catch (e) { if (/unexpected host/.test(e.message)) { /* disable proxy/TLS interception or bypass the mirror, then retry */ } else throw e; }","preventionTips":["Avoid proxies or TLS-intercepting appliances on hosts that re-route github.com redirects.","Test redirect chains with curl -sIL before rolling out updates on a controlled network.","Do not front the release URL with a redirect to a third-party mirror domain."],"tags":["security","redirect","network","update"],"backgroundTag":"invalid-url","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}