From 61c97c847c30601ff981b380050ca7235eb6356b Mon Sep 17 00:00:00 2001 From: Jon Chery Date: Mon, 10 Aug 2026 21:18:24 +0000 Subject: [PATCH] fix(P1): recompute TARBALL after fallback version walk (REQ-132) The fallback walk (REQ-098) reassigns VERSION from the requested release to the nearest older release carrying a binary asset, but never recomputed TARBALL (set once at line 106 from the requested version). The stale tarball name then flowed into: - grep -F "$TARBALL" SHA256SUMS -> matched nothing (the fallback release's SHA256SUMS only lists the fallback tarball) - sha256sum -c - -> empty stdin -> "no properly formatted checksum lines found" -> REQ-132 refusal - tar -xzf "${TMPDIR}/${TARBALL}" -> would look for the wrong filename (download saved under the stale name too) User-visible symptom (v0.14.2 latest had no asset, fell back to v0.12.18): install: verifying checksum... sha256sum: 'standard input': no properly formatted checksum lines found install: error: checksum verification failed (REQ-132); refusing to install Fix: recompute TARBALL immediately after VERSION is reassigned in the fallback branch, so download/grep/sha256sum/tar all reference the fallback version's tarball. ASSET_URL and SHA256SUMS_URL were already correct (derived from the API/ASSET_URL); TARBALL was the only stale variable. Reproduced the exact error before the fix; confirmed end-to-end install succeeds after (orca-v0.12.18-linux-amd64.tar.gz: OK -> extracting -> installed). Added a bats regression test pinning --version v0.14.2 and asserting the dry-run "would install" line references the fallback version (not the stale pinned one). ---ci--- project: orca phase: 1 milestone: v0.15 status: execute decisions: - id: D-001 decision: Recompute TARBALL in the fallback branch immediately after VERSION is reassigned, so grep/sha256sum/tar use the fallback version's filename instead of the stale requested version's. rationale: Reproduced the exact user error ("no properly formatted checksum lines found") by running grep -F "$TARBALL" SHA256SUMS | sha256sum -c with a stale v0.14.2 tarball name against v0.12.18 SHA256SUMS. TARBALL is the only stale variable: ASSET_URL and VERSION are correctly updated from API output, and SHA256SUMS_URL derives from ASSET_URL. Single-line fix, minimal blast radius, preserves the working non-fallback path. confidence: 0.96 alternatives: - lazy TARBALL via a function (over-engineering for one stale assignment) - move TARBALL= assignment past the fallback block (breaks find_asset_url which needs the requested version's name pre-walk) lessons: - When a fallback/walk mutates one variable (VERSION), audit every variable derived from it (TARBALL) for the same mutation. The user-facing info line at 167 constructed the name inline and looked correct, masking that the variable itself was stale. ---/ci--- --- scripts/install.sh | 1 + scripts/tests/install_test.bash | 23 +++++++++++++++++++++++ 2 files changed, 24 insertions(+) diff --git a/scripts/install.sh b/scripts/install.sh index fbd4737..375ba81 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -164,6 +164,7 @@ if [ -z "$ASSET_URL" ]; then ASSET_URL="$(echo "$FALLBACK_OUT" | head -1)" if [ -n "$ASSET_URL" ]; then VERSION="$(echo "$FALLBACK_OUT" | tail -1)" + TARBALL="orca-${VERSION}-${OS}-${ARCH}.tar.gz" info "WARNING: falling back to ${VERSION} which has orca-${VERSION}-${OS}-${ARCH}.tar.gz." else err "could not find any release with a ${OS}-${ARCH} tarball in the last 50 releases. Check that a release exists with a linux-${ARCH} binary." diff --git a/scripts/tests/install_test.bash b/scripts/tests/install_test.bash index a7cb722..8869903 100644 --- a/scripts/tests/install_test.bash +++ b/scripts/tests/install_test.bash @@ -39,6 +39,29 @@ load test_helper assert_contains "$output" "dry-run (--check)" } +@test "install.sh fallback walk syncs TARBALL to fallback version (REQ-132 regression)" { + # Regression guard: when the fallback walk reassigns VERSION, the + # TARBALL variable must be recomputed too. v0.14.2 is a release with + # no binary asset; the installer must walk back to an earlier release. + # The dry-run "would install" line must reference the SAME fallback + # version as the "falling back to" line — not the stale pinned one. + # Before the fix, TARBALL stayed at the pinned v0.14.2 name while + # VERSION became the fallback, causing grep|sha256sum to see no + # matching checksum line and REQ-132 to refuse install. + skip_if_no_network + run timeout 60 "$SCRIPTS_DIR/install.sh" --check --version v0.14.2 + assert_status 0 "$status" + assert_contains "$output" "falling back" + # Capture the fallback version from the "falling back to vX.Y.Z" line. + fb_version="$(printf '%s\n' "$output" | sed -n 's/.*falling back to \(v[0-9][0-9.]*\).*/\1/p' | head -1)" + [ -n "$fb_version" ] || { echo "could not parse fallback version from output: $output" >&2; return 1; } + # The dry-run "would install" line must use the fallback version, + # proving VERSION and TARBALL are in sync (not the stale pinned v0.14.2). + assert_contains "$output" "would install: orca ${fb_version}" + # And it must NOT reference the stale pinned version in the install line. + assert_not_contains "$output" "would install: orca v0.14.2" +} + @test "install.sh rejects unknown arguments" { run "$SCRIPTS_DIR/install.sh" --bogus-flag [ "$status" -ne 0 ]