diff --git a/README.md b/README.md index f65cfc8..662924c 100644 --- a/README.md +++ b/README.md @@ -72,6 +72,8 @@ ti --version The installer writes `ti` and `ti-drive9` to `~/.ti/bin` without sudo. Add the `export PATH=...` line to your shell profile to make it persistent. +The macOS/Linux installer downloads both binaries and their checksum files from CDN-fronted sources and verifies the checksums before installation. + Windows users: ```powershell diff --git a/docs/priciples.md b/docs/priciples.md index e7ec695..838d122 100644 --- a/docs/priciples.md +++ b/docs/priciples.md @@ -215,7 +215,7 @@ GitHub Releases and GoReleaser produce release archives and checksums. Supported - Installation and update do not require sudo. - Installers do not edit shell profiles automatically; they print the command that prepends `~/.ti/bin` to `PATH`. -- Installers support ti release version pinning and checksum verification. The companion is currently downloaded and checksum-verified from Drive9's unversioned release endpoint; ti does not yet negotiate a companion version range. +- Installers support ti release version pinning and checksum verification. The shell installer downloads the companion and its checksums from Drive9's CloudFront-fronted release endpoint (`releases.drive9.ai/latest`); the PowerShell installer and updater use Drive9's origin release endpoint. These companion sources are unversioned; ti does not yet negotiate a companion version range. - `ti update --check` checks explicitly; there is no background update. - `ti update` is itself explicit consent and does not require `--yes`. - The updater stages and verifies ti and its companion before replacement. diff --git a/e2e/installer_test.go b/e2e/installer_test.go index 476677e..6333f79 100644 --- a/e2e/installer_test.go +++ b/e2e/installer_test.go @@ -172,8 +172,8 @@ done case "$url" in */ti_checksums.txt) source=%q ;; */%s) source=%q ;; - */checksums.txt) source=%q ;; - */%s) source=%q ;; + https://releases.drive9.ai/latest/SHA256SUMS) source=%q ;; + https://releases.drive9.ai/latest/%s) source=%q ;; *) printf 'unexpected URL: %%s\n' "$url" >&2; exit 1 ;; esac if [ -n "$out" ]; then diff --git a/scripts/install.sh b/scripts/install.sh index 4930dbb..40d928b 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -189,8 +189,9 @@ ARCHIVE_URL="${RELEASE_BASE}/${ARTIFACT}" CHECKSUMS_URL="${RELEASE_BASE}/ti_checksums.txt" TARGET="${INSTALL_DIR}/ti" COMPANION_ARTIFACT="drive9-${OS}-${ARCH}" -COMPANION_URL="https://drive9.ai/releases/${COMPANION_ARTIFACT}" -COMPANION_CHECKSUMS_URL="https://drive9.ai/releases/checksums.txt" +COMPANION_BASE="https://releases.drive9.ai/latest" +COMPANION_URL="${COMPANION_BASE}/${COMPANION_ARTIFACT}" +COMPANION_CHECKSUMS_URL="${COMPANION_BASE}/SHA256SUMS" COMPANION_TARGET="${INSTALL_DIR}/ti-drive9" if [ "$DRY_RUN" -eq 1 ]; then