Skip to content

Replace Go installer with pure-script installation - #120

Merged
itsfuad merged 7 commits into
mainfrom
fix/release-gh-repo
Aug 30, 2026
Merged

itsfuad merged 7 commits into
mainfrom
fix/release-gh-repo

Conversation

@itsfuad

@itsfuad itsfuad commented Aug 30, 2026

Copy link
Copy Markdown
Member

Summary

  • install.sh / install.ps1 are now the only installers: manifest download + SHA256SUMS verification, pack URL/digest extraction from the manifest, pack download + SHA-256 verification, staging extraction, atomic activation, idempotent PATH persistence.
  • Deleted cmd/peeper-installer and internal/installer; host jobs no longer build or upload installer binaries. Release assets drop from 17 to 11.
  • Manifest Ed25519 signature still generated and published for out-of-band audit; consumer-side verification is now the SHA-256 chain (accepted tradeoff).
  • README and docs/distribution.md updated.

Validation

  • go test ./... all packages pass; gofmt clean; git diff --check clean
  • bash -n scripts/install.sh; YAML parse of release.yml, release-host.yml, ci.yml
  • grep: no stale peeper-installer / internal/installer references

Bundle native runtime into compiler pack and require exactly one compiler
and one toolchain per host in release manifest schema 2. Replace 24-job
component release with six host-local pipelines that each fetch their
immutable toolchain once, build compiler and runtime, package one host
pack, and verify fresh installation before upload. Collapse sign,
checksum, and draft publication into one protected finalization job and
remove SBOM and provenance attestation. Add POSIX and PowerShell
bootstrap installers that detect the platform, verify the native
installer against SHA256SUMS, run it, and persist user PATH
idempotently. Remove completed lock-path migration from the toolchain
planner without changing fingerprints.
Component downloads now run concurrently so total install time tracks the
largest pack instead of the sum, with one aggregate throttled progress line
on stderr. Progress counts bytes on the write side of the copy so streamed
data is reported accurately. README drops compiler pipeline and repository
layout sections and the stale no-binary-release note.
The installer binary download is large enough to need feedback; curl now
uses a stderr progress bar and PowerShell keeps its default progress for
that step only. The tiny SHA256SUMS fetch stays silent.
Bootstrap scripts now perform the full installation: download the release
manifest, verify it against SHA256SUMS, read pack URLs and SHA-256 digests
for the detected host, download compiler and toolchain packs, verify every
digest, extract into staging on the destination filesystem, and activate
atomically. Removes cmd/peeper-installer and internal/installer, dropping
six installer builds and assets per release; release assets drop to 11.
Manifest signing stays for out-of-band audit.
@itsfuad
itsfuad merged commit 4141717 into main Aug 30, 2026
14 checks passed
@github-project-automation github-project-automation Bot moved this from Todo to Done in Peeper Roadmap Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant