Skip to content

Installers execute release binaries when integrity metadata is missing #401

Description

@carfeii

Affected versions: confirmed on main at commit 3f10983 (and the originally-scanned 75e2c64).

Summary

install.sh and install.ps1 continue past a missing version.json, a missing per-platform checksum entry, or (bash) no available sha256 tool, treating each the same as a successful checksum verification. Only an actual checksum mismatch is fatal.

Details

# install.sh
expected_sha=""
if [ -n "$manifest_json" ]; then
  expected_sha="$(extract_asset_sha256 "$manifest_json" "$platform_key")"
else
  log "warning: could not fetch version.json; skipping checksum verification"
fi
...
if [ -n "$expected_sha" ]; then
  # verify
else
  # nothing: proceeds to extract and install anyway
fi

install.ps1 has the identical structure.

POC

(available upon request)

Impact

An outage or compromise of the manifest/checksum delivery path, or simply a machine without sha256sum/shasum on the bash path, causes the installer to extract, install, and execute an unverified release binary, with the only indication being a warning log line a scripted/piped install (curl ... | sh) never surfaces to an interactive user.

Suggested fix: fail closed unless the checksum was actually verified to match, with an explicit opt-out for operators who understand the risk. A fix is included in the linked pull request.

Fix: #400

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions