Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ var Funcs = map[string][]func(*maintained_apps.FMAManifestApp) (*maintained_apps
"logitune/darwin": {LogiTunePKGInstaller},
"anka-virtualization/darwin": {AnkaVersionShortener},
"pd/darwin": {PdVersionTransformer},
"smallstepagent/darwin": {SmallstepAgentVersionTransformer},
"sonos/darwin": {SonosVersionTransformer},
"visual-studio-code/darwin": {VSCodeUniversalInstaller},
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -102,3 +102,19 @@ func PdVersionTransformer(app *maintained_apps.FMAManifestApp) (*maintained_apps
app.Version = strings.ReplaceAll(app.Version, "-", ".")
return app, nil
}

// SmallstepAgentVersionTransformer prepends "v" to match what macOS reports as
// bundle_short_version for Smallstep Agent (e.g. "0.68.0" → "v0.68.0"; the app's
// CFBundleShortVersionString carries the "v" prefix). Without this, osquery's
// version_compare treats the "v" prefix as making the host version always
// greater, breaking patch policy detection.
func SmallstepAgentVersionTransformer(app *maintained_apps.FMAManifestApp) (*maintained_apps.FMAManifestApp, error) {
if app.Version == "" {
return app, errors.New("empty version for Smallstep Agent")
}
if strings.HasPrefix(app.Version, "v") {
return app, nil
}
app.Version = "v" + app.Version
return app, nil
}
Original file line number Diff line number Diff line change
Expand Up @@ -88,6 +88,32 @@ func TestSublimeVersionTransformer(t *testing.T) {
}
}

func TestSmallstepAgentVersionTransformer(t *testing.T) {
tcs := []struct {
name string
version string
expected string
wantErr bool
}{
{name: "empty version", version: "", wantErr: true},
{name: "numeric version", version: "0.68.0", expected: "v0.68.0"},
{name: "already prefixed", version: "v0.68.0", expected: "v0.68.0"},
}

for _, tc := range tcs {
t.Run(tc.name, func(t *testing.T) {
app := &maintained_apps.FMAManifestApp{Version: tc.version, Slug: "smallstepagent"}
result, err := SmallstepAgentVersionTransformer(app)
if tc.wantErr {
require.Error(t, err)
return
}
require.NoError(t, err)
assert.Equal(t, tc.expected, result.Version)
})
}
}

func TestMySQLWorkbenchVersionTransformer(t *testing.T) {
tcs := []struct {
name string
Expand Down
8 changes: 8 additions & 0 deletions ee/maintained-apps/inputs/homebrew/smallstepagent.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
{
"name": "Smallstep Agent",
"unique_identifier": "com.smallstep.Agent",
"token": "smallstepagent",
Comment thread
allenhouchins marked this conversation as resolved.
"installer_format": "pkg",
"slug": "smallstepagent/darwin",
"default_categories": ["Security"]
}
7 changes: 7 additions & 0 deletions ee/maintained-apps/outputs/apps.json
Original file line number Diff line number Diff line change
Expand Up @@ -7519,6 +7519,13 @@
"unique_identifier": "org.sveinbjorn.Sloth",
"description": "Sloth is a displays all open files and sockets in use by all running processes."
},
{
"name": "Smallstep Agent",
"slug": "smallstepagent/darwin",
"platform": "darwin",
"unique_identifier": "com.smallstep.Agent",
"description": "Smallstep Agent is a device identity agent that manages certificates for secure access to Wi-Fi, VPNs, and other resources."
},
{
"name": "Smartsheet",
"slug": "smartsheet/darwin",
Expand Down
22 changes: 22 additions & 0 deletions ee/maintained-apps/outputs/smallstepagent/darwin.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"versions": [
{
"version": "v0.68.0",
"queries": {
"exists": "SELECT 1 FROM apps WHERE bundle_identifier = 'com.smallstep.Agent';",
"patched": "SELECT 1 WHERE NOT EXISTS (SELECT 1 FROM apps WHERE bundle_identifier = 'com.smallstep.Agent' AND version_compare(bundle_short_version, 'v0.68.0') < 0);"
},
"installer_url": "https://packages.smallstep.com/stable/step-agent/darwin/0.68.0/step-agent_0.68.0.pkg",
"install_script_ref": "b1e5b672",
"uninstall_script_ref": "f1a66f75",
"sha256": "e1f200513070880fd8072c2e8491c41552bf533290a69d1d0e7edf5628993fb2",
"default_categories": [
"Security"
]
}
],
"refs": {
"b1e5b672": "#!/bin/bash\n\n# variables\nAPPDIR=\"/Applications/\"\nTMPDIR=$(dirname \"$(realpath \"$INSTALLER_PATH\")\")\n# functions\n\nquit_and_track_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local timeout_duration=10\n\n # check if the application is running\n local app_running\n app_running=$(osascript -e \"application id \\\"$bundle_id\\\" is running\" 2>/dev/null)\n if [[ \"$app_running\" != \"true\" ]]; then\n eval \"export $var_name=0\"\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping quitting application ID '$bundle_id'.\"\n eval \"export $var_name=0\"\n return\n fi\n\n # App was running, mark it for relaunch\n eval \"export $var_name=1\"\n echo \"Application '$bundle_id' was running; will relaunch after installation.\"\n\n echo \"Quitting application '$bundle_id'...\"\n\n # try to quit the application within the timeout period\n local quit_success=false\n SECONDS=0\n while (( SECONDS < timeout_duration )); do\n if osascript -e \"tell application id \\\"$bundle_id\\\" to quit\" >/dev/null 2>&1; then\n if ! pgrep -f \"$bundle_id\" >/dev/null 2>&1; then\n echo \"Application '$bundle_id' quit successfully.\"\n quit_success=true\n break\n fi\n fi\n sleep 1\n done\n\n if [[ \"$quit_success\" = false ]]; then\n echo \"Application '$bundle_id' did not quit.\"\n fi\n}\n\n\nrelaunch_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local was_running\n\n # Check if the app was running before installation\n eval \"was_running=\\$$var_name\"\n if [[ \"$was_running\" != \"1\" ]]; then\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping relaunching application ID '$bundle_id'.\"\n return\n fi\n\n echo \"Relaunching application '$bundle_id'...\"\n\n # Launch the app in the logged-in user's GUI session. Apps launched by root\n # won't register with the user's Dock/GUI, so run 'open' as the console user.\n # Use 'launchctl asuser' to bootstrap into the console user's Mach namespace\n # and GUI session — 'sudo -u' alone doesn't do this, which can cause\n # LSOpenURLsWithRole() failures even when 'open' exits 0.\n local open_status=0\n if [[ $EUID -eq 0 ]]; then\n local console_uid\n console_uid=$(id -u \"$console_user\")\n /bin/launchctl asuser \"$console_uid\" sudo -u \"$console_user\" open -b \"$bundle_id\" >/dev/null 2>&1 || open_status=$?\n else\n open -b \"$bundle_id\" >/dev/null 2>&1 || open_status=$?\n fi\n\n if [[ $open_status -eq 0 ]]; then\n echo \"Application '$bundle_id' relaunched successfully.\"\n else\n echo \"Failed to relaunch application '$bundle_id'.\"\n fi\n}\n\n\n# install pkg files\nquit_and_track_application 'com.smallstep.Agent'\nsudo installer -pkg \"$TMPDIR/step-agent_0.68.0.pkg\" -target /\nrelaunch_application 'com.smallstep.Agent'\n",
"f1a66f75": "#!/bin/bash\n\n# variables\nLOGGED_IN_USER=$(scutil <<< \"show State:/Users/ConsoleUser\" | awk '/Name :/ { print $3 }')\n# functions\n\nexpand_pkgid_and_map() {\n local PKGID=\"$1\"\n local FUNC=\"$2\"\n if [[ \"$PKGID\" == *\"*\" ]]; then\n local prefix=\"${PKGID%\\*}\"\n echo \"Expanding wildcard for PKGID: $PKGID\"\n for receipt in $(pkgutil --pkgs | grep \"^${prefix}\"); do\n echo \"Processing $receipt\"\n \"$FUNC\" \"$receipt\"\n done\n else\n \"$FUNC\" \"$PKGID\"\n fi\n}\n\nforget_pkg() {\n local PKGID=\"$1\"\n expand_pkgid_and_map \"$PKGID\" forget_receipt\n}\n\nforget_receipt() {\n local PKGID=\"$1\"\n sudo pkgutil --forget \"$PKGID\"\n}\n\nremove_launchctl_service() {\n local service=\"$1\"\n local booleans=(\"true\" \"false\")\n local plist_status\n local paths\n local should_sudo\n\n echo \"Removing launchctl service ${service}\"\n\n # A wildcard label can't be used with launchctl or as a plist name, so expand\n # it to the labels of currently loaded services that match the pattern.\n local services=(\"$service\")\n if [[ \"$service\" == *\"*\"* ]]; then\n local regex\n # Escape regex metacharacters, turn '*' into '.*', and anchor the pattern so\n # it matches a full label rather than a substring.\n regex=$(printf '%s' \"$service\" | sed -e 's/[][(){}.^$+?|\\\\]/\\\\&/g' -e 's/\\*/.*/g')\n regex=\"^${regex}$\"\n services=()\n local id\n # Match every loaded job by label regardless of PID; launchctl list reports\n # loaded-but-not-running jobs with a \"-\" in the PID column.\n while read -r _ _ id; do\n [[ \"$id\" =~ $regex ]] && services+=(\"$id\")\n done < <(launchctl list 2>/dev/null | tail -n +2)\n if [[ ${#services[@]} -eq 0 ]]; then\n echo \"No loaded launchctl service matches ${service}\"\n return\n fi\n fi\n\n local service_label\n for service_label in \"${services[@]}\"; do\n for should_sudo in \"${booleans[@]}\"; do\n plist_status=$(launchctl list \"${service_label}\" 2>/dev/null)\n\n if [[ $plist_status == \\{* ]]; then\n if [[ $should_sudo == \"true\" ]]; then\n sudo launchctl remove \"${service_label}\"\n else\n launchctl remove \"${service_label}\"\n fi\n sleep 1\n fi\n\n paths=(\n \"/Library/LaunchAgents/${service_label}.plist\"\n \"/Library/LaunchDaemons/${service_label}.plist\"\n )\n\n # if not using sudo, prepend the home directory to the paths\n if [[ $should_sudo == \"false\" ]]; then\n for i in \"${!paths[@]}\"; do\n paths[i]=\"${HOME}${paths[i]}\"\n done\n fi\n\n for path in \"${paths[@]}\"; do\n if [[ -e \"$path\" ]]; then\n if [[ $should_sudo == \"true\" ]]; then\n sudo rm -f -- \"$path\"\n else\n rm -f -- \"$path\"\n fi\n fi\n done\n done\n done\n}\n\nremove_pkg_files() {\n local PKGID=\"$1\"\n expand_pkgid_and_map \"$PKGID\" remove_receipt_files\n}\n\nremove_receipt_files() {\n local PKGID=\"$1\"\n local PKGINFO VOLUME INSTALL_LOCATION FULL_INSTALL_LOCATION\n\n echo \"pkgutil --pkg-info-plist \\\"$PKGID\\\"\"\n PKGINFO=$(pkgutil --pkg-info-plist \"$PKGID\")\n VOLUME=$(echo \"$PKGINFO\" | awk '/<key>volume<\\/key>/ {getline; gsub(/.*<string>|<\\/string>.*/, \"\"); print}')\n INSTALL_LOCATION=$(echo \"$PKGINFO\" | awk '/<key>install-location<\\/key>/ {getline; gsub(/.*<string>|<\\/string>.*/, \"\"); print}')\n\n if [ -z \"$INSTALL_LOCATION\" ] || [ \"$INSTALL_LOCATION\" = \"/\" ]; then\n FULL_INSTALL_LOCATION=\"$VOLUME\"\n else\n FULL_INSTALL_LOCATION=\"$VOLUME/$INSTALL_LOCATION\"\n FULL_INSTALL_LOCATION=$(echo \"$FULL_INSTALL_LOCATION\" | sed 's|//|/|g')\n fi\n\n echo \"sudo pkgutil --only-files --files \\\"$PKGID\\\" | sed \\\"s|^|${FULL_INSTALL_LOCATION}/|\\\" | tr '\\\\\\\\n' '\\\\\\\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\"\n sudo pkgutil --only-files --files \"$PKGID\" | sed \"s|^|/${INSTALL_LOCATION}/|\" | tr '\\n' '\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\n\n echo \"sudo pkgutil --only-dirs --files \\\"$PKGID\\\" | sed \\\"s|^|${FULL_INSTALL_LOCATION}/|\\\" | grep '\\\\.app$' | tr '\\\\\\\\n' '\\\\\\\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\"\n sudo pkgutil --only-dirs --files \"$PKGID\" | sed \"s|^|${FULL_INSTALL_LOCATION}/|\" | grep '\\.app$' | tr '\\n' '\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\n\n root_app_dir=$(\n sudo pkgutil --only-dirs --files \"$PKGID\" \\\n | sed \"s|^|${FULL_INSTALL_LOCATION}/|\" \\\n | grep 'Applications' \\\n | awk '{ print length, $0 }' \\\n | sort -n \\\n | head -n1 \\\n | cut -d' ' -f2-\n )\n if [ -n \"$root_app_dir\" ]; then\n echo \"sudo rmdir -p \\\"$root_app_dir\\\" 2>/dev/null || :\"\n sudo rmdir -p \"$root_app_dir\" 2>/dev/null || :\n fi\n}\n\ntrash() {\n local logged_in_user=\"$1\"\n local target_file=\"$2\"\n local timestamp=\"$(date +%Y-%m-%d-%s)\"\n local rand=\"$(jot -r 1 0 99999)\"\n\n # replace ~ with /Users/$logged_in_user\n if [[ \"$target_file\" == ~* ]]; then\n target_file=\"/Users/$logged_in_user${target_file:1}\"\n fi\n\n local trash=\"/Users/$logged_in_user/.Trash\"\n\n # If the target contains glob characters, expand it and move each match.\n if [[ \"$target_file\" == *[*?[]* ]]; then\n local file file_name\n local matched=false\n local i=0\n # compgen -G expands the (quoted) pattern itself, so paths containing\n # spaces glob correctly; reading line by line keeps each match intact.\n while IFS= read -r file; do\n [[ -n \"$file\" ]] || continue\n [[ -e \"$file\" || -L \"$file\" ]] || continue\n matched=true\n i=$((i + 1))\n file_name=\"$(basename \"$file\")\"\n echo \"removing $file.\"\n # The per-match counter keeps matches that share a basename from\n # overwriting each other in the trash.\n mv -f \"$file\" \"$trash/${file_name}_${timestamp}_${rand}_${i}\"\n done < <(compgen -G \"$target_file\" 2>/dev/null)\n if [[ \"$matched\" == false ]]; then\n echo \"$target_file doesn't exist.\"\n fi\n return\n fi\n\n local file_name=\"$(basename \"${target_file}\")\"\n\n if [[ -e \"$target_file\" ]]; then\n echo \"removing $target_file.\"\n mv -f \"$target_file\" \"$trash/${file_name}_${timestamp}_${rand}\"\n else\n echo \"$target_file doesn't exist.\"\n fi\n}\n\nremove_launchctl_service 'com.smallstep.Agent.UserAgent'\nremove_launchctl_service 'com.smallstep.launchd.Agent'\nremove_pkg_files 'com.smallstep.Agent'\nforget_pkg 'com.smallstep.Agent'\nsudo rm -rf '/Library/LaunchAgents/com.smallstep.Agent.UserAgent.plist'\ntrash $LOGGED_IN_USER '~/Library/Application Scripts/com.smallstep.Agent.Token'\ntrash $LOGGED_IN_USER '~/Library/Containers/com.smallstep.Agent.Token'\n"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Description: Search for the templates generating the uninstall scripts.

# Look for the buggy pkgutil command and unquoted trash variable in Go templates
rg 'sudo pkgutil --only-files' --type=go
rg 'trash \$LOGGED_IN_USER' --type=go

Repository: fleetdm/fleet

Length of output: 4726


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect the generated file and look for its source templates in the repo.
git ls-files 'ee/maintained-apps/outputs/smallstepagent/darwin.json' \
  'ee/**/templates/**' \
  'ee/**/template/**' \
  'ee/**/generator/**' \
  'ee/**/install*' \
  'ee/**/uninstall*' \
  'ee/**/*.go' \
  'ee/**/*.sh' | sed -n '1,200p'

echo '--- file context ---'
cat -n ee/maintained-apps/outputs/smallstepagent/darwin.json | sed -n '1,220p'

echo '--- search for suspicious uninstall patterns ---'
rg -n 'sudo pkgutil --only-files|trash \$LOGGED_IN_USER|FULL_INSTALL_LOCATION|INSTALL_LOCATION' ee -S

Repository: fleetdm/fleet

Length of output: 2093


Use FULL_INSTALL_LOCATION in the file-removal pipeline.

sudo pkgutil --only-files --files "$PKGID" still prefixes paths with /${INSTALL_LOCATION}/, so installs on a non-boot volume can be removed from the wrong location. Switch that pipeline to ${FULL_INSTALL_LOCATION}/ to match the path calculation used elsewhere.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ee/maintained-apps/outputs/smallstepagent/darwin.json` at line 20, Update the
file-removal pipeline in remove_receipt_files to prefix pkgutil file paths with
FULL_INSTALL_LOCATION rather than INSTALL_LOCATION, matching the calculated
volume-aware base path used by the directory-removal pipeline. Leave the
surrounding pkgutil, sed, and xargs behavior unchanged.

}
}
Loading
Loading