Repository navigation
fix: realign hyperi-update with how tools install - #111
Merged
Merged
Conversation
The Linux updater now refreshes every release binary the roles put in /usr/local/bin and nothing at the OS level carries. One refetch helper replaces the three per-format ones. It takes the asset's own arch spelling, a forge other than GitHub (tea from Gitea, macbash from downloads.hyperi.io), tar, nested tar and zip assets, a published checksum, and a minimum release age that matches the role's 7-day cooldown for aws-vault and Fedora's kubectx and kubens. It only touches a binary that lives under /usr/local, and only on the distro whose role installs it there. A stamp in /var/lib/hyperi-update records the source and digest of each install, so a release that has not moved is not downloaded again. A GITHUB_TOKEN or GH_TOKEN in the environment is sent to api.github.com from a 0600 file. Newly covered: lazygit, actionlint, osv-scanner, aws-vault, git-scrub, sccache, fnm, tea and macbash on both distros, hadolint, gitleaks and act on Ubuntu, and sd, kubectx and kubens on Fedora. Both updaters now refresh pnpm globals with `pnpm update -g --latest`, which `npm update -g` never reached, and uv-managed Pythons with `uv python upgrade`, which installs no python or python3 shim. Go tools are refreshed only when their binary is in ~/go/bin and the module has a newer release, which adds gosec and flarectl on Linux without doubling a dnf copy. The macOS updater drops `claude update`, since the claude-code cask rides `brew upgrade --cask --greedy`, and finds brew's keg-only rustup. developer-go appends ~/go/bin to the login PATH, where gopls, govulncheck, gosec and flarectl were installed but unreachable. Comments that claimed hyperi-update refreshed git-scrub on macOS and Apple container now say what does, and the install matrix lists the binaries the updater covers.
Every release binary the Linux updater installs is now checked against the sha256 GitHub publishes for the asset, read from the release document the updater already fetches. Where a release has no digest (dive v0.13.1) it falls back to the release's checksum file, and tea and macbash keep their .sha256 files. A mismatch fails the tool and leaves the installed binary alone. In a release list, the digest is read from the chosen release only, because an asset name without a version repeats in every release. A new binary is installed beside the old one and renamed over it, so it is never missing or half-written. A symlink member in an archive is rejected. On Ubuntu, uv and uvx in the user's ~/.local/bin are refreshed from the same release as the user, since `uv self update` refuses a copy it did not install. When sccache is replaced, the hyperi-sccache user unit is restarted if it is running, otherwise a server still running the old binary is stopped. Release lookups send the last ETag, and the response is cached per user. With a token, an unchanged release costs no rate limit. Anonymous 304s still count, and when the API refuses, the cached document stands in so a current tool is not reported as failed. Every curl call is bounded by connect and total timeouts. The EXIT trap no longer acts on SUDO_KEEPALIVE_PID or GH_AUTH_HEADER inherited from the caller. The GitHub token is read once and stops being exported to child processes. The go tools section runs after the Go toolchain section and rebuilds a tool when the toolchain moved. On macOS, nounset and pipefail are set after `emulate`, which had reset them, so a failed softwareupdate is reported. The comments on the timer unit, the astral role, removals and hyperi-go.sh now match what runs. The install matrix covers pnpm and uv Python refreshes in Tier 2, the verification, ETag and uv behaviour in Tier 3, gron as the one release binary left out, and the lazygit row.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
hyperi-update now refreshes only what nothing at the OS level refreshes, and it checks every download before it touches /usr/local/bin.
refetchhelper replaces the three old ones. It handles per-arch asset names, Gitea and plain HTTPS hosts (tea, macbash), tar, nested tar and zip.--latest, because the role installs them unpinned);claude update, which does nothing for the cask thatbrew upgrade --cask --greedyalready covers.set -uand pipefail work again, sinceemulate -L zshwas resetting both.Tested on ubuntu:24.04, ubuntu:26.04 and fedora:44 against real release assets:
test-hyperi-update.shpassed 18 of 18.Not run: arm64, a real GitHub token, the systemd user unit restart, and macOS beyond
zsh -nand--help.Done when a weekly run on any supported box refreshes each tool exactly once, from a verified download, without adding a second copy.