Skip to content

fix(install): resolve releases from the apex domain - #1140

Merged
elucid merged 2 commits into
mainfrom
fix/release-endpoint-apex-domain
Oct 2, 2026
Merged

elucid merged 2 commits into
mainfrom
fix/release-endpoint-apex-domain

Conversation

@elucid

@elucid elucid commented Oct 2, 2026

Copy link
Copy Markdown
Member

Problem

A user reported that pasting curl -fsSL https://hunk.dev/install.sh | sh into Terminal.app shows "Malware Detected, Paste Blocked" with no override. Reproduced on macOS 26.5.1 (XProtect 5363) by copying the command from hunk.dev in a browser and pressing ⌘V.

Root cause

macOS 26.4+ does more than pattern-match pasted text. From the unified log (xprotectd, syspolicyd, networkserviceproxy):

  1. Terminal hands a browser-sourced paste to xprotectd.
  2. xprotectd executes the command in a sandboxed container (a real curl process appears) and its rules engine watches what it does.
  3. Each host the command contacts is checked against Apple's website-reputation service (websitereview.corp.apple.com, via Safari.SafeBrowsing.Service over Oblivious HTTP).
  4. The installer's first network call is https://updates.hunk.dev/v1/curl/latest. That host returns a bad verdict → Killing container due to rules engine deny → the dialog.

Isolation tests, all pasted from a browser with the same curl … | sh shape:

Command Result
curl -fsSL https://hunk.dev/install.sh | sh Blocked (type 19, "blocked scripted malware execution")
curl -fsSL https://hunk.dev/robots.txt | sh Passed
curl -fsSL https://hunk.dev/install.sh | sh -s -- --help (exits before networking) Passed
curl -fsSL https://updates.hunk.dev/v1/curl/latest | sh Blocked (type 20, "blocked paste event")

So the command shape is fine (it is identical to Deno/Ollama/Tailscale); the problem is the hostname updates.hunk.dev, which install.sh started contacting in #969 (0.22.0). Google Safe Browsing reports the host clean; this is Apple's list only.

Fix

  • vercel.json: rewrite /api/release/latest → https://updates.hunk.dev/v1/curl/latest. Vercel proxies server-side and forwards headers and method, so the Worker's allowlisted X-Hunk-* logging and Cache-Control: no-store are unchanged.
  • install.sh and latestRelease.ts (startup check, hunk update) resolve from https://hunk.dev/api/release/latest. Clients now only contact hunk.dev/www.hunk.dev, api.github.com, and github.com — the same profile as every other installer.
  • Tests, VM fixtures, Worker README, and the deployment doc updated. Changeset: patch.

Non-goals: the Worker and its updates.hunk.dev custom domain stay deployed, since 0.22–0.23 binaries still call it for update checks and fall back to GitHub on failure. Retire it in a later release. A delisting request for the host is being filed at websitereview.apple.com separately.

Verification

  • bun run typecheck, bun run lint — clean
  • bun test scripts/packaging/install-sh.test.ts packages/hunk/src/core/install/latestRelease.test.ts packages/hunk/src/core/process/updateNotice.test.ts packages/hunk/src/core/install/selfUpdate.test.ts test/cli/install-vm/prepare-fixtures.test.ts — 102 pass
  • Not run: test/cli/install-vm (requires the VM harness); Worker tests (Worker code unchanged).

To verify on the Vercel preview before merge:

curl -fsS -D - -H 'X-Hunk-Request-Source: install' https://<preview>.vercel.app/api/release/latest
# expect HTTP 200, application/json, {"version":"0.23.0"}, cache-control: no-store

After merge: copy the install command from hunk.dev in a browser and ⌘V into Terminal.app on macOS 26.4+ / 27; it should paste cleanly.

macOS 26.4+ runs browser-pasted Terminal commands in an XProtect sandbox and
blocks the paste with "Malware Detected, Paste Blocked" when the command
contacts a host Apple's website reputation service distrusts. The install
script's first network call was to updates.hunk.dev, which that service flags,
so `curl -fsSL https://hunk.dev/install.sh | sh` was blocked.

Serve release discovery as https://hunk.dev/api/release/latest through a
Vercel rewrite to the release-proxy Worker, and point the installer and
`hunk update` at it, so clients only contact the apex domain.
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hunk-web Ready Ready Preview Oct 2, 2026 6:09pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Medium risk] Changes release discovery URL for the installer.

The release lookup has a fallback, but the deployment verification requirement should be satisfied before merging.

Findings

  1. P2 Rewrite lacks an automated check ▶
  2. P2 Deployment check accepts wrong responses ▶
Fix with agent prompt
### Issue 1
vercel.json:10
The updated tests check the client URL and the Worker separately, but none checks that this Vercel route reaches the Worker's expected path. A later routing change could break release discovery while those tests still pass. Add an automated route check or a preview-deployment smoke test.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

### Issue 2
website/src/content/docs/docs/help/deployment.md:59
This command succeeds for any successful HTTP response, including an HTML page returned by a misrouted endpoint. The repository requires verification to fail visibly when the intended behavior has not been verified. Before merging, make this check validate a release version and the expected cache policy, not just the status.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR routes curl-release discovery through an apex-domain Vercel rewrite while retaining the existing Worker and GitHub fallback.

  • Updates installer and in-app release URLs, associated tests, VM fixtures, and deployment documentation.
  • The rewrite lacks an automated route check, and the new deployment command does not validate its response.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Installer / hunk update] --> B[hunk.dev/api/release/latest]
  B --> C[Vercel rewrite]
  C --> D[updates.hunk.dev/v1/curl/latest]
  D --> E[Release metadata]
  A -->|lookup fails| F[GitHub releases API]
Loading

Reviews (1) · Last reviewed commit: "fix(install): resolve releases from the ..."

Comment thread vercel.json
Comment thread website/src/content/docs/docs/help/deployment.md Outdated
@elucid
elucid enabled auto-merge (squash) October 2, 2026 18:09
@elucid
elucid disabled auto-merge October 2, 2026 18:14
@elucid
elucid merged commit f4beb16 into main Oct 2, 2026
18 checks passed

This branch was successfully deployed

1 active deployment
Preview — ad80ed0a Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant