Skip to content

security(install): add curl timeouts and size caps to install.sh; consider signature verification #580

Description

@ajianaz

Problem. After #572, install.sh fails closed on missing checksums, matches filenames exactly, and rejects symlink/hardlink tar entries. Remaining gaps:

  1. Every curl call (version probe at ~L53/L61, archive at ~L107, checksums at ~L118) has no --connect-timeout / --max-time, and no size cap (--max-filesize), so a stalled or hostile server can hang or flood the installer. The Rust upgrade path already has timeouts and caps (256 MiB archive, 1 MiB checksums/JSON).
  2. Checksums come from the same release as the archive, so they protect against corruption/partial tampering but not against a compromised release. Signature verification (cosign or minisign) would close this; it needs key infrastructure and a release-pipeline change, so it is a separate, larger follow-up.

Direction. (1) is a small PR: --connect-timeout, --max-time, --max-filesize mirroring the Rust limits, plus a shellcheck-clean change. (2) Decide on cosign vs minisign and key management; track as its own issue once (1) lands.

Follow-up noted in #572.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions