From 39c236560c5bbe9324249e2a6b486cce673b6d49 Mon Sep 17 00:00:00 2001 From: qiffang Date: Sun, 27 Sep 2026 18:08:49 +0800 Subject: [PATCH 1/2] fix(installer): download Drive9 companion from GitHub --- README.md | 2 ++ docs/priciples.md | 2 +- e2e/installer_test.go | 4 ++-- scripts/install.sh | 5 +++-- 4 files changed, 8 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index f65cfc8..98fb367 100644 --- a/README.md +++ b/README.md @@ -72,6 +72,8 @@ ti --version The installer writes `ti` and `ti-drive9` to `~/.ti/bin` without sudo. Add the `export PATH=...` line to your shell profile to make it persistent. +The macOS/Linux installer downloads both binaries and their checksum files from GitHub and verifies the checksums before installation. + Windows users: ```powershell diff --git a/docs/priciples.md b/docs/priciples.md index e7ec695..4100606 100644 --- a/docs/priciples.md +++ b/docs/priciples.md @@ -215,7 +215,7 @@ GitHub Releases and GoReleaser produce release archives and checksums. Supported - Installation and update do not require sudo. - Installers do not edit shell profiles automatically; they print the command that prepends `~/.ti/bin` to `PATH`. -- Installers support ti release version pinning and checksum verification. The companion is currently downloaded and checksum-verified from Drive9's unversioned release endpoint; ti does not yet negotiate a companion version range. +- Installers support ti release version pinning and checksum verification. The shell installer downloads the companion and its checksums from `mem9-ai/drive9-fe` on GitHub; the PowerShell installer and updater use Drive9's release endpoint. These companion sources are unversioned; ti does not yet negotiate a companion version range. - `ti update --check` checks explicitly; there is no background update. - `ti update` is itself explicit consent and does not require `--yes`. - The updater stages and verifies ti and its companion before replacement. diff --git a/e2e/installer_test.go b/e2e/installer_test.go index 476677e..11d2f02 100644 --- a/e2e/installer_test.go +++ b/e2e/installer_test.go @@ -172,8 +172,8 @@ done case "$url" in */ti_checksums.txt) source=%q ;; */%s) source=%q ;; - */checksums.txt) source=%q ;; - */%s) source=%q ;; + https://raw.githubusercontent.com/mem9-ai/drive9-fe/main/site/releases/checksums.txt) source=%q ;; + https://raw.githubusercontent.com/mem9-ai/drive9-fe/main/site/releases/%s) source=%q ;; *) printf 'unexpected URL: %%s\n' "$url" >&2; exit 1 ;; esac if [ -n "$out" ]; then diff --git a/scripts/install.sh b/scripts/install.sh index 4930dbb..241d8da 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -189,8 +189,9 @@ ARCHIVE_URL="${RELEASE_BASE}/${ARTIFACT}" CHECKSUMS_URL="${RELEASE_BASE}/ti_checksums.txt" TARGET="${INSTALL_DIR}/ti" COMPANION_ARTIFACT="drive9-${OS}-${ARCH}" -COMPANION_URL="https://drive9.ai/releases/${COMPANION_ARTIFACT}" -COMPANION_CHECKSUMS_URL="https://drive9.ai/releases/checksums.txt" +COMPANION_BASE="https://raw.githubusercontent.com/mem9-ai/drive9-fe/main/site/releases" +COMPANION_URL="${COMPANION_BASE}/${COMPANION_ARTIFACT}" +COMPANION_CHECKSUMS_URL="${COMPANION_BASE}/checksums.txt" COMPANION_TARGET="${INSTALL_DIR}/ti-drive9" if [ "$DRY_RUN" -eq 1 ]; then From c3df86c7a9fc648acd8345ece71734ddd16a5a55 Mon Sep 17 00:00:00 2001 From: qiffang Date: Sun, 27 Sep 2026 21:27:39 +0800 Subject: [PATCH 2/2] fix(installer): fetch Drive9 companion from CloudFront release CDN MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Downloading the companion via `https://raw.githubusercontent.com/mem9-ai/drive9-fe/...` worked around the Netlify reset seen in Daytona sandboxes but hard-codes a GitHub raw URL that has its own rate limits, cache behavior, and availability profile — not intended as a distribution channel. Route the shell installer to `https://releases.drive9.ai/latest/` instead. This is the S3 + CloudFront release channel now published by the drive9 release-cli workflow (mem9-ai/drive9#1003). It: - Reproduces cleanly in Daytona sandboxes where drive9.ai (Netlify) resets and github.com raw is sometimes throttled. - Serves the same `drive9--` binaries and a SHA256SUMS file in the identical ` ` format, so the installer's existing `awk '$2 == name'` verification is unchanged. - Is CDN-fronted (global edge cache) and controlled by us, so we can invalidate/rotate as needed. Updates the installer regression fixture to expect the new host, and adjusts README/product principles to describe the new source. PowerShell installer and `ti update` continue to use Drive9's origin release endpoint (unchanged in this PR). Co-Authored-By: Claude Opus 4.7 (1M context) --- README.md | 2 +- docs/priciples.md | 2 +- e2e/installer_test.go | 4 ++-- scripts/install.sh | 4 ++-- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/README.md b/README.md index 98fb367..662924c 100644 --- a/README.md +++ b/README.md @@ -72,7 +72,7 @@ ti --version The installer writes `ti` and `ti-drive9` to `~/.ti/bin` without sudo. Add the `export PATH=...` line to your shell profile to make it persistent. -The macOS/Linux installer downloads both binaries and their checksum files from GitHub and verifies the checksums before installation. +The macOS/Linux installer downloads both binaries and their checksum files from CDN-fronted sources and verifies the checksums before installation. Windows users: diff --git a/docs/priciples.md b/docs/priciples.md index 4100606..838d122 100644 --- a/docs/priciples.md +++ b/docs/priciples.md @@ -215,7 +215,7 @@ GitHub Releases and GoReleaser produce release archives and checksums. Supported - Installation and update do not require sudo. - Installers do not edit shell profiles automatically; they print the command that prepends `~/.ti/bin` to `PATH`. -- Installers support ti release version pinning and checksum verification. The shell installer downloads the companion and its checksums from `mem9-ai/drive9-fe` on GitHub; the PowerShell installer and updater use Drive9's release endpoint. These companion sources are unversioned; ti does not yet negotiate a companion version range. +- Installers support ti release version pinning and checksum verification. The shell installer downloads the companion and its checksums from Drive9's CloudFront-fronted release endpoint (`releases.drive9.ai/latest`); the PowerShell installer and updater use Drive9's origin release endpoint. These companion sources are unversioned; ti does not yet negotiate a companion version range. - `ti update --check` checks explicitly; there is no background update. - `ti update` is itself explicit consent and does not require `--yes`. - The updater stages and verifies ti and its companion before replacement. diff --git a/e2e/installer_test.go b/e2e/installer_test.go index 11d2f02..6333f79 100644 --- a/e2e/installer_test.go +++ b/e2e/installer_test.go @@ -172,8 +172,8 @@ done case "$url" in */ti_checksums.txt) source=%q ;; */%s) source=%q ;; - https://raw.githubusercontent.com/mem9-ai/drive9-fe/main/site/releases/checksums.txt) source=%q ;; - https://raw.githubusercontent.com/mem9-ai/drive9-fe/main/site/releases/%s) source=%q ;; + https://releases.drive9.ai/latest/SHA256SUMS) source=%q ;; + https://releases.drive9.ai/latest/%s) source=%q ;; *) printf 'unexpected URL: %%s\n' "$url" >&2; exit 1 ;; esac if [ -n "$out" ]; then diff --git a/scripts/install.sh b/scripts/install.sh index 241d8da..40d928b 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -189,9 +189,9 @@ ARCHIVE_URL="${RELEASE_BASE}/${ARTIFACT}" CHECKSUMS_URL="${RELEASE_BASE}/ti_checksums.txt" TARGET="${INSTALL_DIR}/ti" COMPANION_ARTIFACT="drive9-${OS}-${ARCH}" -COMPANION_BASE="https://raw.githubusercontent.com/mem9-ai/drive9-fe/main/site/releases" +COMPANION_BASE="https://releases.drive9.ai/latest" COMPANION_URL="${COMPANION_BASE}/${COMPANION_ARTIFACT}" -COMPANION_CHECKSUMS_URL="${COMPANION_BASE}/checksums.txt" +COMPANION_CHECKSUMS_URL="${COMPANION_BASE}/SHA256SUMS" COMPANION_TARGET="${INSTALL_DIR}/ti-drive9" if [ "$DRY_RUN" -eq 1 ]; then