Skip to content

fix(install): refuse to install an unverified release by default - #400

Open
carfeii wants to merge 1 commit into
Tencent:mainfrom
carfeii:fix/installer-fail-closed-checksum-v2
Open

carfeii wants to merge 1 commit into
Tencent:mainfrom
carfeii:fix/installer-fail-closed-checksum-v2

Conversation

@carfeii

@carfeii carfeii commented Oct 5, 2026

Copy link
Copy Markdown

Both install.sh and install.ps1 treated a missing version.json, a missing per-platform checksum entry, or (bash only) no available sha256 tool as reasons to silently skip verification and continue, the same as a successful checksum match. Only an actual mismatch was fatal. An outage or compromise of the manifest/checksum delivery path (or simply missing a sha256 tool) therefore installed and executed an unverified binary with no indication beyond a warning log line.

Both scripts now refuse to install unless the checksum was actually verified to match, with an explicit BSK_INSTALL_ALLOW_UNVERIFIED=1 escape hatch (env var on both platforms) for operators who understand the risk and want the previous best-effort behavior back.

Test plan

  • Validated install.sh end-to-end against stubbed curl/tar/sha256sum in an isolated $HOME: confirmed it now refuses when the manifest is unreachable or no checksum is published for the platform (both previously succeeded with exit 0), confirmed BSK_INSTALL_ALLOW_UNVERIFIED=1 still installs in that case, and confirmed the existing checksum-match/mismatch paths are unchanged.
  • install.ps1 received the identical fix (same variable-flow pattern: track a verified flag, set it only on a confirmed match, check it before extraction) but could not be executed in this environment, which has no PowerShell runtime available. Reviewed by inspection against the already-validated bash logic; happy to iterate if CI surfaces anything.

Both install.sh and install.ps1 treated a missing version.json, a
missing per-platform checksum entry, or (bash only) no available
sha256 tool as reasons to silently skip verification and continue, the
same as a successful checksum match. Only an actual mismatch was
fatal. An outage or compromise of the manifest/checksum delivery path
(or simply missing a sha256 tool) therefore installed and executed an
unverified binary with no indication beyond a warning log line.

Both scripts now refuse to install unless the checksum was actually
verified to match, with an explicit BSK_INSTALL_ALLOW_UNVERIFIED=1
escape hatch (env var on both platforms) for operators who understand
the risk and want the previous best-effort behavior back.

Validated install.sh end-to-end against stubbed curl/tar/sha256sum in
an isolated $HOME: confirmed it now refuses when the manifest is
unreachable or no checksum is published for the platform (both
previously succeeded), confirmed BSK_INSTALL_ALLOW_UNVERIFIED=1 still
installs in that case, and confirmed the existing checksum-match path
is unchanged. install.ps1 received the identical fix (same variable-
flow pattern) but could not be executed in this environment, which has
no PowerShell runtime; reviewed by inspection against the already-
validated bash logic.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant