diff --git a/.github/workflows/release-canary.yml b/.github/workflows/release-canary.yml index 239f49eced..c25381909a 100644 --- a/.github/workflows/release-canary.yml +++ b/.github/workflows/release-canary.yml @@ -193,6 +193,8 @@ jobs: ubuntu-snap-system-docker: name: Ubuntu Snap with system Docker + env: + OPENSHELL_INSTALL_SNAP: "1" if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }} runs-on: ubuntu-latest timeout-minutes: 20 @@ -260,6 +262,8 @@ jobs: ubuntu-snap-docker-preflight: name: Ubuntu Snap Docker preflight + env: + OPENSHELL_INSTALL_SNAP: "1" if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }} runs-on: ubuntu-latest timeout-minutes: 20 diff --git a/install.sh b/install.sh index 60bfd6f64c..b482054d3b 100755 --- a/install.sh +++ b/install.sh @@ -61,23 +61,25 @@ ENVIRONMENT VARIABLES: OPENSHELL_ACK_BREAKING_UPGRADE Set to 1 only after backing up and cleaning up a pre-v0.0.37 or non-snap installation. + OPENSHELL_INSTALL_SNAP + Set to 1 to install the OpenShell snap on Linux. NOTES: When OPENSHELL_VERSION is unset, this resolves the latest tagged release from ${GITHUB_URL}/releases/latest. - On Linux, the installer uses the OpenShell snap when the snap command is - available and OPENSHELL_VERSION is unset or dev. Snap installs use - latest/stable by default and latest/edge for dev. Explicit release tags - and prereleases use Debian or RPM packages. The OpenShell snap requires a - running Docker Engine installed from a system package or Docker's package - repository. The Docker snap is not currently compatible with OpenShell. - - For explicit versions or without snap, Linux installs the Debian package - on amd64/arm64 or the RPM packages on x86_64/aarch64, depending on the - host package manager. + Linux installs the Debian package on amd64/arm64 or the RPM packages on + x86_64/aarch64, depending on the host package manager. macOS installs the release Homebrew formula on Apple Silicon and starts a brew services-backed local gateway. + + The installer uses the OpenShell snap only when OPENSHELL_INSTALL_SNAP=1 is + set or an OpenShell snap is already installed, the snap command is + available, and OPENSHELL_VERSION is unset or dev. Snap installs use + latest/stable by default and latest/edge for dev. The OpenShell snap + requires a running Docker Engine installed from a system package or + Docker's package repository. The Docker snap is not currently compatible + with OpenShell. EOF } @@ -657,10 +659,18 @@ local_gateway_endpoint() { esac } +openshell_snap_installed() { + snap list openshell >/dev/null 2>&1 +} + +# The snap gateway runs as root without client authentication, so new installs +# use it only on explicit opt-in. Existing snap installs keep refreshing rather +# than gaining a second gateway on the same port. linux_package_method() { case "${OPENSHELL_VERSION:-}" in '' | dev) - if has_cmd snap; then + if has_cmd snap \ + && { [ "${OPENSHELL_INSTALL_SNAP:-0}" = "1" ] || openshell_snap_installed; }; then echo "snap" return 0 fi @@ -1340,6 +1350,8 @@ Install Docker Engine from a system package or Docker's package repository, then info "using existing Docker installation" wait_for_docker_daemon + warn "the OpenShell snap gateway allows unauthenticated access from any local user or process" + _channel="$(openshell_snap_channel)" if snap list openshell >/dev/null 2>&1; then info "refreshing OpenShell snap from ${_channel}..." diff --git a/tasks/scripts/test-install-sh.sh b/tasks/scripts/test-install-sh.sh index 8cc6102148..5ecdb55c31 100755 --- a/tasks/scripts/test-install-sh.sh +++ b/tasks/scripts/test-install-sh.sh @@ -103,22 +103,30 @@ assert_glibc_preflight_fails \ assert_linux_package_method() { local name=$1 local requested_version=$2 - local snap_present=$3 + local snap_mode=$3 local dpkg_present=$4 local rpm_present=$5 local expected=$6 local actual + # snap_mode: 0 = no snap command, 1 = snap command only, + # optin = OPENSHELL_INSTALL_SNAP=1, existing = OpenShell snap installed. actual="$( export OPENSHELL_VERSION="$requested_version" + if [ "$snap_mode" = "optin" ]; then + export OPENSHELL_INSTALL_SNAP=1 + else + unset OPENSHELL_INSTALL_SNAP + fi has_cmd() { case "$1" in - snap) [ "$snap_present" = "1" ] ;; + snap) [ "$snap_mode" != "0" ] ;; dpkg) [ "$dpkg_present" = "1" ] ;; rpm) [ "$rpm_present" = "1" ] ;; *) return 1 ;; esac } + openshell_snap_installed() { [ "$snap_mode" = "existing" ]; } linux_package_method )" if [ "$actual" != "$expected" ]; then @@ -127,13 +135,19 @@ assert_linux_package_method() { fi } -assert_linux_package_method "snap takes precedence over deb and rpm" "" 1 1 1 snap -assert_linux_package_method "dev uses snap" dev 1 1 1 snap -assert_linux_package_method "pre uses deb despite snap" pre 1 1 1 deb -assert_linux_package_method "numbered prerelease uses deb despite snap" v0.1.0-pre.3 1 1 1 deb -assert_linux_package_method "pre uses rpm despite snap" pre 1 0 1 rpm -assert_linux_package_method "pinned stable uses deb despite snap" v1.2.3 1 1 1 deb -assert_linux_package_method "pinned stable uses rpm despite snap" v1.2.3 1 0 1 rpm +assert_linux_package_method "deb is the default despite snap" "" 1 1 1 deb +assert_linux_package_method "rpm is the default despite snap" "" 1 0 1 rpm +assert_linux_package_method "dev uses deb despite snap" dev 1 1 1 deb +assert_linux_package_method "opt-in selects snap" "" optin 1 1 snap +assert_linux_package_method "opt-in dev selects snap" dev optin 1 1 snap +assert_linux_package_method "existing snap install keeps refreshing" "" existing 1 1 snap +assert_linux_package_method "existing snap install keeps refreshing dev" dev existing 1 1 snap +assert_linux_package_method "opt-in without snap uses deb" "" 0 1 1 deb +assert_linux_package_method "pre uses deb despite snap opt-in" pre optin 1 1 deb +assert_linux_package_method "numbered prerelease uses deb despite snap opt-in" v0.1.0-pre.3 optin 1 1 deb +assert_linux_package_method "pre uses rpm despite snap opt-in" pre optin 0 1 rpm +assert_linux_package_method "pinned stable uses deb despite existing snap" v1.2.3 existing 1 1 deb +assert_linux_package_method "pinned stable uses rpm despite existing snap" v1.2.3 existing 0 1 rpm assert_linux_package_method "deb is selected without snap" "" 0 1 1 deb assert_linux_package_method "dev uses deb without snap" dev 0 1 1 deb assert_linux_package_method "rpm is selected without snap or deb" "" 0 0 1 rpm