Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 13 additions & 2 deletions install.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,11 @@ Environment overrides:
$env:BSK_REPO GitHub owner/repo (default: Tencent/BrowserSkill)
$env:BSK_VERSION Pin CLI version (default: latest from version.json)
$env:BSK_INSTALL_DIR Install directory (default: $HOME\.local\bin)
$env:BSK_INSTALL_ALLOW_UNVERIFIED
Set to 1 to install even when the release's
integrity cannot be verified (version.json
unreachable, or no checksum published for this
platform). Default: refuse.
#>

#Requires -Version 5.1
Expand Down Expand Up @@ -187,12 +192,13 @@ function Main {
$archiveName = "bsk-v${version}-$($platform.TargetTriple).zip"
$downloadUrl = "${GitHub}/releases/download/${tag}/${archiveName}"
$expectedSha = if ($asset) { $asset.sha256 } else { $null }
$checksumVerified = $false
if (-not $expectedSha) {
if (-not $manifest) {
Write-Log "warning: could not fetch version.json; skipping checksum verification"
Write-Log "warning: could not fetch version.json; cannot verify checksum"
}
else {
Write-Log "warning: no checksum published for $($platform.PlatformKey); skipping checksum verification"
Write-Log "warning: no checksum published for $($platform.PlatformKey); cannot verify checksum"
}
}

Expand All @@ -214,12 +220,17 @@ function Main {
$actualSha = (Get-FileHash -Algorithm SHA256 -LiteralPath $archivePath).Hash
if ($actualSha -ieq $expectedSha) {
Write-Log "checksum OK"
$checksumVerified = $true
}
else {
Write-Die "checksum mismatch: expected $expectedSha, got $actualSha"
}
}

if (-not $checksumVerified -and $env:BSK_INSTALL_ALLOW_UNVERIFIED -ne "1") {
Write-Die "refusing to install an unverified release (set `$env:BSK_INSTALL_ALLOW_UNVERIFIED=1 to override)"
}

Write-Log "extracting ${archiveName}"
# PowerShell 5.1's Expand-Archive treats the destination as a wildcard path.
Add-Type -AssemblyName System.IO.Compression.FileSystem
Expand Down
25 changes: 20 additions & 5 deletions install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@
# BSK_VERSION Pin CLI version (default: latest from version.json)
# BSK_INSTALL_DIR Install directory (default: $HOME/.local/bin)
# BSK_BRANCH Branch for install_sh raw URL metadata only (unused here)
# BSK_INSTALL_ALLOW_UNVERIFIED
# Set to 1 to install even when the release's integrity
# cannot be verified (version.json unreachable, no
# checksum published for this platform, or no
# sha256sum/shasum available). Default: refuse.

set -eu

Expand Down Expand Up @@ -150,16 +155,21 @@ main() {
archive="bsk-v${version}-${triple}.tar.gz"
download_url="${GITHUB}/releases/download/${tag}/${archive}"

# Best-effort checksum: a missing manifest/checksum only skips
# verification (does not block the install), but a *mismatch* is fatal.
# A missing manifest/checksum/hash-tool used to only skip verification
# (never blocked the install); a *mismatch* was always fatal. Now a
# missing-verification case is also fatal by default, since it installs
# and runs an unverified binary identically to a successful bypass of
# the mismatch check. BSK_INSTALL_ALLOW_UNVERIFIED=1 opts back into the
# old best-effort behavior for operators who understand the risk.
expected_sha=""
checksum_verified=0
if [ -n "$manifest_json" ]; then
expected_sha="$(extract_asset_sha256 "$manifest_json" "$platform_key")"
else
log "warning: could not fetch version.json; skipping checksum verification"
log "warning: could not fetch version.json; cannot verify checksum"
fi
if [ -z "$expected_sha" ] && [ -n "$manifest_json" ]; then
log "warning: no checksum published for ${platform_key}; skipping checksum verification"
log "warning: no checksum published for ${platform_key}; cannot verify checksum"
fi

tmp_dir="$(mktemp -d)"
Expand All @@ -174,14 +184,19 @@ main() {
expected_lower="$(printf '%s' "$expected_sha" | tr 'A-F' 'a-z')"
if [ "$actual_sha" = "$expected_lower" ]; then
log "checksum OK"
checksum_verified=1
else
die "checksum mismatch: expected ${expected_lower}, got ${actual_sha}"
fi
else
log "warning: no sha256 tool (sha256sum/shasum) found; skipping checksum verification"
log "warning: no sha256 tool (sha256sum/shasum) found; cannot verify checksum"
fi
fi

if [ "$checksum_verified" -ne 1 ] && [ "${BSK_INSTALL_ALLOW_UNVERIFIED:-}" != "1" ]; then
die "refusing to install an unverified release (set BSK_INSTALL_ALLOW_UNVERIFIED=1 to override)"
fi

log "extracting ${archive}"
tar -xzf "${tmp_dir}/${archive}" -C "$tmp_dir"

Expand Down