Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 17 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,16 +50,26 @@ jobs:
}

- name: Restore
run: dotnet restore .\Hakamiq.CsoKit.slnx -r win-x64 -p:NuGetAudit=false
run: dotnet restore .\CsoKit.slnx -r win-x64 -p:NuGetAudit=false

- name: Build native backend
run: .\scripts\Build-Native.ps1 -Configuration Release -Platform x64

- name: Build Debug
run: dotnet build .\Hakamiq.CsoKit.slnx -c Debug --no-restore -p:NuGetAudit=false
run: dotnet build .\CsoKit.slnx -c Debug --no-restore -p:NuGetAudit=false

- name: Test Debug
run: dotnet test .\Hakamiq.CsoKit.slnx -c Debug --no-build
- name: Stage native backend for tests
run: |
$source = ".\artifacts\native-build\win-x64\Release\CsoKit.Native.dll"
$destination = ".\tests\CsoKit.Tests\bin\Debug\net10.0\CsoKit.Native.dll"
if (-not (Test-Path -LiteralPath $source -PathType Leaf)) {
throw "Native test DLL was not found: $source"
}
New-Item -ItemType Directory -Force (Split-Path -Parent $destination) | Out-Null
Copy-Item -LiteralPath $source -Destination $destination -Force

- name: Build native backend
run: .\scripts\Build-Native.ps1 -Configuration Release -Platform x64
- name: Test Debug with native integration
run: dotnet test .\CsoKit.slnx -c Debug --no-build

- name: Publish release package
run: .\scripts\Publish-Release.ps1 -Runtime win-x64
Expand All @@ -70,6 +80,6 @@ jobs:
- name: Upload release ZIP artifact
uses: actions/upload-artifact@v7
with:
name: hakamiq-csokit-win-x64
name: csokit-win-x64
path: artifacts/release/*.zip
if-no-files-found: error
8 changes: 4 additions & 4 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ jobs:
- name: Attest release ZIP
uses: actions/attest@v4
with:
subject-path: artifacts/release/hakamiq-csokit-${{ env.RELEASE_VERSION }}-win-x64.zip
subject-path: artifacts/release/csokit-${{ env.RELEASE_VERSION }}-win-x64.zip

- name: Attest SHA256 manifest
uses: actions/attest@v4
Expand All @@ -92,7 +92,7 @@ jobs:
- name: Upload workflow artifact
uses: actions/upload-artifact@v7
with:
name: hakamiq-csokit-${{ env.RELEASE_VERSION }}-win-x64
name: csokit-${{ env.RELEASE_VERSION }}-win-x64
path: |
artifacts/release/*.zip
artifacts/publish/win-x64/SHA256SUMS.txt
Expand All @@ -102,7 +102,7 @@ jobs:
env:
GH_TOKEN: ${{ github.token }}
run: |
$zipPath = "artifacts\release\hakamiq-csokit-$env:RELEASE_VERSION-win-x64.zip"
$zipPath = "artifacts\release\csokit-$env:RELEASE_VERSION-win-x64.zip"
$shaPath = "artifacts\publish\win-x64\SHA256SUMS.txt"

if (-not (Test-Path $zipPath)) {
Expand All @@ -120,7 +120,7 @@ jobs:
$zipPath,
$shaPath,
"--title",
"Hakamiq CsoKit $env:RELEASE_VERSION",
"CsoKit $env:RELEASE_VERSION",
"--notes-file",
"RELEASE_NOTES.md"
)
Expand Down
4 changes: 2 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ $RECYCLE.BIN/
.localhistory/
.vshistory/

# Hakamiq local corpus and disc/container images
# CsoKit local corpus and disc/container images
*.iso
*.cso
*.zso
Expand All @@ -137,7 +137,7 @@ $RECYCLE.BIN/
*.bin
*.pbp

# Hakamiq local reports
# CsoKit local reports
*.repair-report.txt
*.verify-report.txt
*.compress-report.txt
Expand Down
56 changes: 54 additions & 2 deletions CHANGES.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,22 @@
# Changes

## 2026-08-02 — v7 published smoke gate repair

- Update the published CLI help smoke to the current verify contract: `csokit verify <input.cso|input.zso|input.dax>`.
- Build and stage `CsoKit.Native.dll` inside the standalone published EXE smoke directory before `native-info` and codec checks.
- Add the published EXE smoke to `Verify-Hardening.ps1` so the main merge gate covers it automatically.
- Add source guards preventing regression of the help contract, native staging, or main-gate integration.

## Release gate filename-policy alignment

- Move release and round-trip artifacts into isolated working directories.
- Use short fixed output names (`smoke.cso`, `out.cso`, and `back.iso`) that comply with the 2–10 Unicode text-element policy.
- Add a shared PowerShell output-name guard and enforce its presence from `Verify-Hardening.ps1`.
- Scan literal `.cso` and `.iso` names in release scripts so future policy regressions fail before build and publish.

## 0.6.0

Hakamiq CsoKit 0.6.0 adds the Windows desktop app, improves the CLI release path, and hardens ISO/CSO verification. This release is mainly about making the tool easier to use without weakening the repair and verification rules.
CsoKit 0.6.0 adds the Windows desktop app, improves the CLI release path, and hardens ISO/CSO verification. This release is mainly about making the tool easier to use without weakening the repair and verification rules.

### Added

Expand Down Expand Up @@ -41,4 +55,42 @@ Before publishing 0.6.0, the release gate must pass:
- SHA256 manifest generation.
- Optional real ISO smoke when a local game image is available.

That is enough for the public release. Deeper benchmark and forensic notes live under docs/archive.
That is enough for the public release. Deeper benchmark and forensic notes live under docs/archive.
## Security and architecture hardening

- Restrict production native-library loading to the application directory; gate repository artifact probing behind `CSOKIT_NATIVE_DEV_SEARCH` and support an optional SHA-256 constraint.
- Require native ABI 2 before every native codec path.
- Propagate cancellation through deep verification, repair, CLI `Ctrl+C`, WPF Stop, and final output promotion.
- Add a centralized, bounded compression-worker policy and checked queue sizing.
- Add `CsoKit.Application`, typed operation metrics/detail lines, and a central container-reader factory.
- Split WPF operation execution and report generation out of the main ViewModel file and add WPF-facing tests.
- Build Native before tests in CI and require real native compression/decompression round trips.
- Centralize managed/native/release versioning in the root `VERSION` file.

### Hardening review follow-up

- Fix CLI thread-option definite assignment so Debug builds do not fail with CS0165.
- Qualify the WPF base class as `System.Windows.Application` to avoid the Application namespace collision.
- Remove the CLI project reference to Core and route compression, decompression, repair, and verification use cases through Application results and DTOs.
- Make typed operation detail records the source of rendered text and remove the legacy free-text detail parser.
- Add architecture source guards to the hardening verification gate.

## 2026-08-02 hardening v3 correction

- Fix WPF compilation after ViewModel/report extraction by adding explicit namespace imports and safe worker-count parsing.
- Use compressible native round-trip fixtures and separately verify fail-closed handling of native `OUTPUT_TOO_SMALL` candidates.
## 2026-08-02 output file-name length policy

- Require user-visible output base names to contain 2 to 10 characters, excluding the extension.
- Truncate long automatically suggested names and pad one-character names without changing the extension.
- Keep collision suffixes inside the same ten-character limit, for example `Game-2.cso`.
- Apply the same validation to CLI and WPF through the Application boundary.
- Add Arabic and English validation messages and boundary tests, including Unicode text elements.

## 2026-08-02 output-name CLI failure handling

- Handle output-name validation failures before requiring operation DTOs in `compress`, `decompress`, and `repair`.
- Preserve structured text errors and stable `CannotWriteOutput` exit codes for one-character and eleven-character output names.
- Emit JSON failure envelopes even when early validation returns no operation data; metrics are `null` in that case.
- Keep typed DTOs mandatory for successful operations, where missing data remains an internal contract failure.
- Add dedicated text and JSON tests for the lower and upper file-name boundaries across all three commands.
10 changes: 9 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,4 +78,12 @@ If you have a real PSP ISO available, add the optional corpus smoke:

For a future release, replace `0.6.0` with the version you are publishing.

If NuGet vulnerability metadata times out with `NU1900`, retry later. If you must validate while the audit feed is unavailable, use `-SkipNuGetAudit` and mention that in the release notes or gate summary.
If NuGet vulnerability metadata times out with `NU1900`, retry later. If you must validate while the audit feed is unavailable, use `-SkipNuGetAudit` and mention that in the release notes or gate summary.
## Native development search

Normal releases load `CsoKit.Native.dll` only beside the application executable. Local
repository artifact probing is disabled by default. Developers may opt in with
`CSOKIT_NATIVE_DEV_SEARCH=1`; set `CSOKIT_NATIVE_SHA256` when testing a specific build.

The release version comes from the root `VERSION` file. Update that file once; managed
project metadata, CMake native constants, and release scripts consume it.
8 changes: 8 additions & 0 deletions CsoKit.slnx
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
<Solution>
<Project Path="src\CsoKit.Core\CsoKit.Core.csproj" />
<Project Path="src\CsoKit.Application\CsoKit.Application.csproj" />
<Project Path="src\CsoKit.Cli\CsoKit.Cli.csproj" />
<Project Path="src\CsoKit.App\CsoKit.App.csproj" />
<Project Path="tests\CsoKit.Tests\CsoKit.Tests.csproj" />
<Project Path="tests\CsoKit.App.Tests\CsoKit.App.Tests.csproj" />
</Solution>
8 changes: 8 additions & 0 deletions Directory.Build.props
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
<Project>
<PropertyGroup>
<CsoKitVersion>$([System.IO.File]::ReadAllText('$(MSBuildThisFileDirectory)VERSION').Trim())</CsoKitVersion>
<Version>$(CsoKitVersion)</Version>
<PackageVersion>$(CsoKitVersion)</PackageVersion>
<InformationalVersion>$(CsoKitVersion)</InformationalVersion>
</PropertyGroup>
</Project>
6 changes: 0 additions & 6 deletions Hakamiq.CsoKit.slnx

This file was deleted.

4 changes: 2 additions & 2 deletions LICENSE.txt
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
Hakamiq CsoKit Proprietary License
CsoKit Proprietary License

Copyright (c) 2026 HAKAMIQ.
All rights reserved.

Hakamiq CsoKit is proprietary software owned by HAKAMIQ.
CsoKit is proprietary software owned by HAKAMIQ.

You may download and use the official compiled release binaries for personal, non-commercial use.

Expand Down
46 changes: 27 additions & 19 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,69 +1,71 @@
# Hakamiq CsoKit
# CsoKit

Hakamiq CsoKit is a Windows x64 toolkit for PSP ISO and CSO files. Use the desktop app for normal work, or the CLI when you want scripting and exact control.
CsoKit is a Windows x64 toolkit for PSP ISO and CSO files. Use the desktop app for normal work, or the CLI when you want scripting and exact control.

## Download

Grab the latest Windows x64 package from the [Releases page](https://github.com/HAKAMIQ/Hakamiq.CsoKit/releases/latest):
Grab the latest Windows x64 package from the [Releases page](https://github.com/HAKAMIQ/CsoKit/releases/latest):

hakamiq-csokit-*-win-x64.zip
csokit-*-win-x64.zip

Extract it anywhere. Keep `Hakamiq.Cso.Native.dll` next to the executables.
Extract it anywhere. Keep `CsoKit.Native.dll` next to the executables.

## Quick start

Desktop app:

.\Hakamiq.Cso.App.exe
.\CsoKit.App.exe

CLI help:

.\hakamiq-cso.exe --help
.\csokit.exe --help

Version:

.\hakamiq-cso.exe --version
.\csokit.exe --version

## Common commands

Show CSO information:

.\hakamiq-cso.exe info ".\game.cso"
.\csokit.exe info ".\game.cso"

Verify a CSO file:

.\hakamiq-cso.exe verify ".\game.cso"
.\csokit.exe verify ".\game.cso"

Deep-verify and calculate SHA256:

.\hakamiq-cso.exe verify ".\game.cso" --deep --sha256
.\csokit.exe verify ".\game.cso" --deep --sha256

Detect an input format:

.\hakamiq-cso.exe detect ".\game.iso"
.\csokit.exe detect ".\game.iso"

Analyze a PSP ISO:

.\hakamiq-cso.exe analyze ".\game.iso" --psp
.\csokit.exe analyze ".\game.iso" --psp

Compress ISO to CSO:

.\hakamiq-cso.exe compress ".\game.iso"
.\csokit.exe compress ".\game.iso"

Use the fast profile:

.\hakamiq-cso.exe compress ".\game.iso" --profile fast
.\csokit.exe compress ".\game.iso" --profile fast

Decompress CSO to ISO:

.\hakamiq-cso.exe decompress ".\game.cso"
.\csokit.exe decompress ".\game.cso"

Repair or normalize readable input into CSO1:

.\hakamiq-cso.exe repair ".\game.cso" -o ".\fixed.cso" --profile game-safe --deep-verify
.\csokit.exe repair ".\game.cso" -o ".\fixed.cso" --profile game-safe --deep-verify

Profiles: `game-safe` default, `compat`, `fast`, `smallest`, `archive-smallest`.

Output base names must be 2 to 10 characters; `.cso` and `.iso` extensions are not counted. Automatically suggested names follow this limit.

Full CLI reference: [docs/CLI.md](docs/CLI.md).

## Exit codes
Expand All @@ -86,11 +88,17 @@ Full CLI reference: [docs/CLI.md](docs/CLI.md).

## Limitations

Hakamiq CsoKit focuses on PSP ISO/CSO workflows.
CsoKit focuses on PSP ISO/CSO workflows.
ZSO, DAX, and CSO2 are readable input containers; CSO1 is the default output format.
Verification checks file structure, not emulator or device compatibility.

## More documentation

- [CLI reference](docs/CLI.md)
- [Contributor scripts and release gates](CONTRIBUTING.md)
- [Contributor scripts and release gates](CONTRIBUTING.md)
## Architecture and safety

The repository is split into `CsoKit.Core`, `CsoKit.Application`, CLI, and WPF adapters.
Production native loading is limited to the application directory and requires ABI 2.
Compression workers are bounded, and cancellation is propagated through verification,
repair, and final output promotion. See `docs/SECURITY_HARDENING.md`.
4 changes: 2 additions & 2 deletions RELEASE_NOTES.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Hakamiq CsoKit 0.6.0
# CsoKit 0.6.0

Windows x64 release focused on PSP ISO/CSO workflows, WPF usability, and release-grade verification.

Expand Down Expand Up @@ -40,7 +40,7 @@ If NuGet vulnerability metadata times out with `NU1900`, retry later. If you mus

The official GitHub release provides:

hakamiq-csokit-0.6.0-win-x64.zip
csokit-0.6.0-win-x64.zip
SHA256SUMS.txt

Download from the GitHub Releases page.
Loading