Skip to content

feat(update): examine release downloads with checksums.txt - #36

Merged
nabil1440 merged 2 commits into
agent/30-updatefrom
agent/9-checksums
Sep 28, 2026
Merged

nabil1440 merged 2 commits into
agent/30-updatefrom
agent/9-checksums

Conversation

@nabil1440

@nabil1440 nabil1440 commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Layer 6 of 7 of the monitoring agent (#31 → #37).

Summary

  • fly update and install.sh now examine each download with the checksums.txt of the release. If the checksum is not correct, they stop, and the old binary continues.
  • The agent and fly update use the same check code.

Change

  • internal/release: fly update reads checksums.txt, then uses Download and Install, with a limit of 10 minutes.
  • install.sh: it downloads checksums.txt and runs sha256sum -c.
  • README: releases before v0.2.0 have no checksums.txt, so push the release tag right after the merge into main.

Adversarial review

Not refuted. These smaller items are fixed in this PR:

  • Two different sums for one file make checksums.txt not valid, in fly update and in install.sh.
  • Ctrl-C during fly update stops the download and removes the partial file.

Tests

  • A release with a correct, a wrong and no checksum file; CRLF line ends, upper-case hex, repeated, similar and empty lines; no file left after an update.
  • install.sh in Ubuntu 24.04: a correct checksum installs, a wrong or a missing checksum stops.

Closes #9

@nabil1440
nabil1440 added this pull request to stack #38 September 22, 2026 10:40
@nabil1440 nabil1440 self-assigned this Sep 22, 2026
@nabil1440 nabil1440 changed the title agent/9 checksums feat(update): examine release downloads with checksums.txt Sep 22, 2026
- fly update downloads checksums.txt of the release and compares the
  sha256 of the archive before it extracts the binary. A release without
  checksums.txt, or without a line for the archive, is not installed.
- fly update now uses the same download and check code as agent.update,
  with a limit of 10 minutes.
- install.sh downloads checksums.txt and runs sha256sum -c. It stops when
  the file is missing or the checksum does not agree.

Refs #9
…trl-C

Fixes from the adversarial review of this layer.

- checksums.txt with two different sums for the same file is not valid.
  Before, fly update used the first line and install.sh refused.
- Ctrl-C or SIGTERM during fly update stops the download and removes the
  partial file.
- README: releases before v0.2.0 have no checksums.txt, so push the tag
  right after the merge into main.
- Tests for CRLF line ends, upper case hex, repeated and similar lines, an
  empty checksum file, and no files left after a successful update.

Refs #9
@nabil1440
nabil1440 merged commit 5f219bf into develop Sep 28, 2026
1 check passed
@nabil1440
nabil1440 deleted the agent/9-checksums branch September 28, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

enhancement: Examine release downloads with checksums

1 participant