fix(install): restore wget installs, add FSEND_ALLOW_ROOT opt-in, calm output - #214
Merged
Merged
Conversation
added 2 commits
September 20, 2026 22:54
…m output Found while verifying v1.13.0 on macOS and in busybox/alpine/debian containers: - download(): --proto =https is curl-only — both GNU wget and busybox abort on it, so every wget-only install failed. Wget keeps its capability-gated TLS floor; the pin stays curl-only. The busybox smoke scenario now also installs through real GitHub with no test seam, so the real flag set is exercised (that was the blind spot). - selfupdate: resolve symlinks only when the binary itself is one. Always resolving rewrote /var → /private/var on macOS, handing the installer a physical prefix PATH spells differently — a duplicate PATH line and a false shadow warning on every --update. - root opt-in: single-user machines (busybox containers, appliances) have no other user, so the refusal locked them out entirely. FSEND_ALLOW_ROOT=1 opts in, with a warning; --update honors it too via its own catalog entry (E040) — riding E033 advised 'check your internet connection', nonsense for a policy refusal. - installer output: no progress meters, no dim gray, 'checksum verified' says what was verified, the opt-in command renders as a block; error command tails get the accent treatment share codes get.
The FSEND_ALLOW_ROOT scenario actually installs as root, leaving root-owned files the user-level EXIT trap cannot remove — the runner saw 'rm: cannot remove ...: Permission denied' after all 10 scenarios had passed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Found while verifying v1.13.0 on macOS and in busybox/alpine/debian containers.
Regression (release blocker): the new installer passed curl-only
--proto =httpsto the wget branch — both GNU wget and busybox abort on it, so every wget-only install failed (v1.12.0 worked). CI missed it because the busybox smoke scenario runs through theFSEND_RELEASE_BASE_URLseam, which empties the pin. Fixed by keeping the pin curl-only (wget retains its capability-gated TLS floor, as in v1.12.0), and the busybox smoke scenario now also installs through real GitHub with no seam so the real flag set can never silently regress.Root opt-in: single-user machines (busybox containers, appliances, CI) have no other user, so the root refusal locked them out entirely.
FSEND_ALLOW_ROOT=1opts in with a warning;fsend --updatehonors it too via a new catalog entry E040 — previously it rode E033, which advised "check your internet connection" for a policy refusal. The refusal now shows the opt-in command as a prominent block:macOS
--updatenoise: symlinks are now resolved only when the binary itself is one. Always resolving rewrote/var→/private/var, handing the installer a physical prefix PATH spells differently — a duplicate PATH line and a false shadow warning on every--update.Installer output: no more
###progress meters, no more dim gray (unreadable on many palettes), "verified" clarified to "checksum verified", and the outro tightened into a calm next-steps block. Mirrored in install.ps1. Error command tails (brew upgrade fsend, the opt-in) get the accent treatment share codes get.Verification
--updateas root with/without opt-in → transfer (5 MB, checksums match)--updatebefore/after contrast (unfixed binary built from main as control), file transfer (8.4 MB, checksums match)smoke-install.sh9/9 (incl. busybox root refusal + real-flags guard) ·smoke-install.ps115/15 ·go test ./...19/19 · shellcheck · gofmt