Skip to content

fix(install): make install.sh reliable, and never let root write in the agent folder - #37

Merged
nabil1440 merged 2 commits into
agent/9-checksumsfrom
agent/10-install-sh
Sep 28, 2026
Merged

nabil1440 merged 2 commits into
agent/9-checksumsfrom
agent/10-install-sh

Conversation

@nabil1440

@nabil1440 nabil1440 commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Layer 7 of 7 of the monitoring agent (#31 → #37).

Summary

  • install.sh stops at the first error, with a correct message, and removes its temporary files.
  • On a server with the agent, the CLI and the agent use one binary, and root never writes in the folder of the agent user.
  • The release archives hold the binary as root:root.

Change

  • install.sh: set -euo pipefail, curl -fsSL with timeouts and retries, a trap, and no grep -P.
  • Without the agent, a root file is installed in /usr/local/bin with a temporary name and a rename. A link there is replaced, not followed.
  • With the agent, the user and the binary come from fly-agent.service (User=, ExecStart=). The agent user writes the new binary; root only gives it the file. Then /usr/local/bin/fly becomes the link, and the agent restarts (try-restart).
  • make release: archives with the owner root:root (GNU tar and bsdtar). Before, install.sh left /usr/local/bin/fly with the owner of the CI user (uid 1001).

Adversarial review

The first version was refuted. These items are fixed in this PR:

  • Root followed /usr/local/bin/fly into the folder of the agent user. That user could point the binary at /etc/passwd and make root overwrite it. Now root does not write there.
  • A server that the old installer split (a separate /usr/local/bin/fly) gets one binary again.
  • A broken link or a leftover fly.new no longer stops the script without a correct message.
  • The checksum lines follow the same rules as fly update.

Tests

In Ubuntu 24.04, with the published dev pre-release: a new server, a split server, a link to /etc/passwd (it stays unchanged), a unit with an unknown binary (stop), a wrong checksum, a dangling link, a leftover fly.new, and CRLF line ends. shellcheck has no warnings.

Closes #10

… link

- Use set -euo pipefail, curl -fsSL and a trap that removes the temporary
  files. Report the HTTP status of the GitHub API, with a rate-limit message
  for 403 and 429. Parse tag_name with sed; remove the grep -P step.
- Extract only fly-<os>-<arch>, without the owner from the archive, and
  install it as root:root. Before, the binary in /usr/local/bin belonged to
  uid 1001 (the CI user), so a local user with that uid could replace a
  binary that root runs.
- On a server with the monitoring agent, /usr/local/bin/fly is a link to
  ~fly/.fly/bin/fly: install through the link, keep the owner of the
  target, and restart fly-agent. The CLI and the agent keep one binary.
- Install with a rename, so a running fly never sees a partial binary.
- make release: the archives hold the binary as root:root (GNU tar and
  bsdtar).

Refs #10
Fixes from the adversarial review of this layer.

- On a server with the monitoring agent, the agent user writes the new
  binary (runuser), and root only gives it the file on stdin. Before, root
  followed /usr/local/bin/fly into ~fly/.fly/bin: the fly user could point
  the binary at /etc/passwd and make root overwrite it, or swap in a link
  during the copy and make root give it /etc/shadow.
- Take the user and the binary from fly-agent.service (User=, ExecStart=)
  and require <home>/.fly/bin/fly. A server that the old installer split
  (a separate /usr/local/bin/fly) gets one binary again, with the link.
- Without the agent, install a root file with a temporary name and a
  rename. A link at /usr/local/bin/fly is replaced, never followed, and a
  leftover fly.new cannot break the install.
- Restart the agent with try-restart, so a stopped agent stays stopped.
- Read checksums.txt with the same rules as fly update ("*" mark, CRLF).
- Take the first tag_name of the one-line API reply. Add timeouts and
  retries to each download. The install command uses curl -fsSL.

Refs #10
@nabil1440
nabil1440 merged commit 39c15a7 into develop Sep 28, 2026
2 checks passed
@nabil1440
nabil1440 deleted the agent/10-install-sh branch September 28, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

enhancement: Make install.sh more reliable

1 participant