Repository navigation
fix: support macOS checksum verification in installer - #154
Conversation
Prefer sha256sum and fall back to shasum -a 256, with an explicit error when neither tool is available. Keep temporary files in scope for cleanup and cover installer checksum paths in Unix CI. Fixes #153 Co-authored-by: Copilot App <[email protected]> Copilot-Session: 8fa9fdb3-d372-4d62-ac90-9eddde36904e
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused portability fix is correct and comprehensively covered by isolated regression scenarios.
Review tier: Balanced
Findings: None
What changed in this PR
Adds portable SHA-256 verification for macOS while preserving secure failure and cleanup behavior.
Changes:
- Falls back from
sha256sumtoshasum -a 256. - Adds fixture-based installer regression tests.
- Runs installer tests on Linux and macOS CI.
| File | Description |
|---|---|
scripts/install.sh |
Adds portable checksum selection and scoped cleanup. |
scripts/test-install.sh |
Tests verification, failures, selection, and cleanup. |
.github/workflows/ci.yml |
Runs installer tests on Unix CI platforms. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Use portable -c and redirect verification stdout instead of --quiet, which the macOS runner's sha256sum rejects. Update installer regressions to enforce portable arguments. Co-authored-by: Copilot App <[email protected]> Copilot-Session: 8fa9fdb3-d372-4d62-ac90-9eddde36904e
Pass an explicit stdin operand required by macOS sha256sum and enable strict validation so malformed checksum entries cannot succeed. Exercise those arguments in the installer regression harness. Co-authored-by: Copilot App <[email protected]> Copilot-Session: 8fa9fdb3-d372-4d62-ac90-9eddde36904e
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The GNU-only --strict flag breaks verification when sha256sum is provided by BusyBox.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Balanced (auto)
Findings: 1
Note
Copilot is running an experiment and ran this review at Balanced.
New issues introduced by this change (1)
| Severity | Finding |
|---|---|
scripts/install.sh — Avoid the GNU-only --strict flag for sha256sum View comment |
Validate a single exact archive entry and its 64-digit hexadecimal checksum before invoking the verifier with -c -. Reject missing, malformed, and duplicate entries without relying on --strict. Add BusyBox-compatible regressions, using the native applet when available. Co-authored-by: Copilot App <[email protected]> Copilot-Session: 8fa9fdb3-d372-4d62-ac90-9eddde36904e
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation addresses macOS compatibility with comprehensive validation and CI coverage.
Review tier: Balanced
Findings: None
Issues resolved since last review (1)
| Severity | Finding |
|---|---|
scripts/install.sh — Avoid the GNU-only --strict flag for sha256sum View resolved comment |

Summary
sha256sumwhen available, falling back to macOS'sshasum -a 256.-c -verification compatible with GNU, BSD, and BusyBox tools.Validation
sha256sum/Perlshasumbackends.Fixes #153