Problem. After #572, install.sh fails closed on missing checksums, matches filenames exactly, and rejects symlink/hardlink tar entries. Remaining gaps:
- Every
curl call (version probe at ~L53/L61, archive at ~L107, checksums at ~L118) has no --connect-timeout / --max-time, and no size cap (--max-filesize), so a stalled or hostile server can hang or flood the installer. The Rust upgrade path already has timeouts and caps (256 MiB archive, 1 MiB checksums/JSON).
- Checksums come from the same release as the archive, so they protect against corruption/partial tampering but not against a compromised release. Signature verification (cosign or minisign) would close this; it needs key infrastructure and a release-pipeline change, so it is a separate, larger follow-up.
Direction. (1) is a small PR: --connect-timeout, --max-time, --max-filesize mirroring the Rust limits, plus a shellcheck-clean change. (2) Decide on cosign vs minisign and key management; track as its own issue once (1) lands.
Follow-up noted in #572.
Problem. After #572,
install.shfails closed on missing checksums, matches filenames exactly, and rejects symlink/hardlink tar entries. Remaining gaps:curlcall (version probe at ~L53/L61, archive at ~L107, checksums at ~L118) has no--connect-timeout/--max-time, and no size cap (--max-filesize), so a stalled or hostile server can hang or flood the installer. The Rust upgrade path already has timeouts and caps (256 MiB archive, 1 MiB checksums/JSON).Direction. (1) is a small PR:
--connect-timeout,--max-time,--max-filesizemirroring the Rust limits, plus a shellcheck-clean change. (2) Decide on cosign vs minisign and key management; track as its own issue once (1) lands.Follow-up noted in #572.