Conversation
Both install.sh and install.ps1 treated a missing version.json, a missing per-platform checksum entry, or (bash only) no available sha256 tool as reasons to silently skip verification and continue, the same as a successful checksum match. Only an actual mismatch was fatal. An outage or compromise of the manifest/checksum delivery path (or simply missing a sha256 tool) therefore installed and executed an unverified binary with no indication beyond a warning log line. Both scripts now refuse to install unless the checksum was actually verified to match, with an explicit BSK_INSTALL_ALLOW_UNVERIFIED=1 escape hatch (env var on both platforms) for operators who understand the risk and want the previous best-effort behavior back. Validated install.sh end-to-end against stubbed curl/tar/sha256sum in an isolated $HOME: confirmed it now refuses when the manifest is unreachable or no checksum is published for the platform (both previously succeeded), confirmed BSK_INSTALL_ALLOW_UNVERIFIED=1 still installs in that case, and confirmed the existing checksum-match path is unchanged. install.ps1 received the identical fix (same variable- flow pattern) but could not be executed in this environment, which has no PowerShell runtime; reviewed by inspection against the already- validated bash logic.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Both
install.shandinstall.ps1treated a missingversion.json, a missing per-platform checksum entry, or (bash only) no available sha256 tool as reasons to silently skip verification and continue, the same as a successful checksum match. Only an actual mismatch was fatal. An outage or compromise of the manifest/checksum delivery path (or simply missing a sha256 tool) therefore installed and executed an unverified binary with no indication beyond a warning log line.Both scripts now refuse to install unless the checksum was actually verified to match, with an explicit
BSK_INSTALL_ALLOW_UNVERIFIED=1escape hatch (env var on both platforms) for operators who understand the risk and want the previous best-effort behavior back.Test plan
install.shend-to-end against stubbedcurl/tar/sha256sumin an isolated$HOME: confirmed it now refuses when the manifest is unreachable or no checksum is published for the platform (both previously succeeded with exit 0), confirmedBSK_INSTALL_ALLOW_UNVERIFIED=1still installs in that case, and confirmed the existing checksum-match/mismatch paths are unchanged.install.ps1received the identical fix (same variable-flow pattern: track a verified flag, set it only on a confirmed match, check it before extraction) but could not be executed in this environment, which has no PowerShell runtime available. Reviewed by inspection against the already-validated bash logic; happy to iterate if CI surfaces anything.