Skip to content

fix(install): restore wget installs, add FSEND_ALLOW_ROOT opt-in, calm output - #214

Merged
polius merged 2 commits into
mainfrom
fix/install-regressions
Sep 20, 2026
Merged

polius merged 2 commits into
mainfrom
fix/install-regressions

Conversation

@polius

@polius polius commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Summary

Found while verifying v1.13.0 on macOS and in busybox/alpine/debian containers.

Regression (release blocker): the new installer passed curl-only --proto =https to the wget branch — both GNU wget and busybox abort on it, so every wget-only install failed (v1.12.0 worked). CI missed it because the busybox smoke scenario runs through the FSEND_RELEASE_BASE_URL seam, which empties the pin. Fixed by keeping the pin curl-only (wget retains its capability-gated TLS floor, as in v1.12.0), and the busybox smoke scenario now also installs through real GitHub with no seam so the real flag set can never silently regress.

Root opt-in: single-user machines (busybox containers, appliances, CI) have no other user, so the root refusal locked them out entirely. FSEND_ALLOW_ROOT=1 opts in with a warning; fsend --update honors it too via a new catalog entry E040 — previously it rode E033, which advised "check your internet connection" for a policy refusal. The refusal now shows the opt-in command as a prominent block:

✗ refusing to run as root — fsend installs per-user, without sudo.
  to install anyway, run:

      FSEND_ALLOW_ROOT=1 curl -fsSL https://getfsend.alzina.dev | sh

  or download a release by hand: https://github.com/polius/fsend/releases

macOS --update noise: symlinks are now resolved only when the binary itself is one. Always resolving rewrote /var → /private/var, handing the installer a physical prefix PATH spells differently — a duplicate PATH line and a false shadow warning on every --update.

Installer output: no more ### progress meters, no more dim gray (unreadable on many palettes), "verified" clarified to "checksum verified", and the outro tightened into a calm next-steps block. Mirrored in install.ps1. Error command tails (brew upgrade fsend, the opt-in) get the accent treatment share codes get.

Verification

  • Docker busybox: real-GitHub install (the exact failing case), root refusal, root opt-in install + binary runs
  • Docker alpine: full cycle fresh → downgrade 1.12.0 → installer re-run upgrade → --update as root with/without opt-in → transfer (5 MB, checksums match)
  • Docker debian (GNU wget 1.25): real install ✓
  • macOS: fresh install, reinstall awareness, --update before/after contrast (unfixed binary built from main as control), file transfer (8.4 MB, checksums match)
  • smoke-install.sh 9/9 (incl. busybox root refusal + real-flags guard) · smoke-install.ps1 15/15 · go test ./... 19/19 · shellcheck · gofmt

Pol Alzina added 2 commits September 20, 2026 22:54
…m output

Found while verifying v1.13.0 on macOS and in busybox/alpine/debian
containers:

- download(): --proto =https is curl-only — both GNU wget and busybox
  abort on it, so every wget-only install failed. Wget keeps its
  capability-gated TLS floor; the pin stays curl-only. The busybox smoke
  scenario now also installs through real GitHub with no test seam, so
  the real flag set is exercised (that was the blind spot).
- selfupdate: resolve symlinks only when the binary itself is one.
  Always resolving rewrote /var → /private/var on macOS, handing the
  installer a physical prefix PATH spells differently — a duplicate
  PATH line and a false shadow warning on every --update.
- root opt-in: single-user machines (busybox containers, appliances)
  have no other user, so the refusal locked them out entirely.
  FSEND_ALLOW_ROOT=1 opts in, with a warning; --update honors it too
  via its own catalog entry (E040) — riding E033 advised 'check your
  internet connection', nonsense for a policy refusal.
- installer output: no progress meters, no dim gray, 'checksum
  verified' says what was verified, the opt-in command renders as a
  block; error command tails get the accent treatment share codes get.
The FSEND_ALLOW_ROOT scenario actually installs as root, leaving
root-owned files the user-level EXIT trap cannot remove — the runner
saw 'rm: cannot remove ...: Permission denied' after all 10 scenarios
had passed.
@polius
polius merged commit fbe29c9 into main Sep 20, 2026
22 checks passed
@polius
polius deleted the fix/install-regressions branch September 20, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant