fix: harden the install / update / uninstall scripts
Nightly Build / build (push) Successful in 7m50s
Nightly Build / build (push) Successful in 7m50s
Four things found while re-reading the family of scripts around the logout fix. Both installers piped curl straight into tar, so a truncated download half-extracted — and the installer explicitly supports reinstalling over an existing install, which turned an interrupted download into a tree mixing old and new files with no error saying so. They now download to a temp file and verify the archive in a staging dir before writing anything to the install directory: the ordering update.sh has had since it was written, for the same reason. update.sh never removed files deleted upstream. Extracting over the install dir only adds and overwrites, so a renamed page under docs/ kept being mounted read-only into every container for the assistant to read, and a removed command kept being discovered. It now prunes, from the directories the tarball owns end to end (web, commands, skills, docs), whatever the already-verified staging copy does not have. Pruning after the extraction rather than replacing the directory keeps every intermediate state a complete install. agents/ is deliberately excluded: dropping in an agent is a documented extension point, so that directory is not ours alone and pruning it would delete somebody's work. uninstall.sh fed `docker ps -aq --filter 'name=skald-'` to `docker rm -f`. Docker's name filter is a regex matched anywhere in the name, not a prefix, so any unrelated container merely containing "skald-" was force-removed. Anchored to ^skald-. uninstall.sh also matched uname's raw Linux/Darwin while its three siblings normalize to lowercase. It was correct on its own, but being the odd one out of four copy-paste relatives is precisely how update.sh acquired its no-op case arms, so it now normalizes like the others. Finally, the uninstaller reports that lingering is still enabled and how to turn it off, rather than disabling it: it is a persistent per-user setting other user services may rely on by now, so taking it back silently would stop those too.
This commit is contained in:
@@ -296,6 +296,31 @@ main() {
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# ── Drop files the new build no longer ships ───────────────────────────────
|
||||
# Extracting over the install dir only ever adds and overwrites, so anything
|
||||
# deleted upstream survives forever: a renamed doc page keeps being mounted
|
||||
# read-only into every container for the assistant to read, a removed command
|
||||
# keeps being discovered. For the directories the tarball owns end to end we
|
||||
# therefore prune whatever the (already verified) staging copy does not have.
|
||||
#
|
||||
# Pruned AFTER extracting rather than by replacing the directory, so every
|
||||
# intermediate state is a complete install and the only files removed are
|
||||
# ones the new build has verifiably dropped.
|
||||
#
|
||||
# agents/ is deliberately not in this list: adding an agent is a documented
|
||||
# extension point (agents/<id>/meta.json + AGENT.md), so the directory is not
|
||||
# ours alone and pruning it would delete somebody's work — at the price of an
|
||||
# upstream-deleted agent lingering. bin/ is out too: two files, both
|
||||
# overwritten every time, nothing to reclaim.
|
||||
for owned in web commands skills docs; do
|
||||
[ -d "$STAGING/$owned" ] && [ -d "${INSTALL_DIR}/$owned" ] || continue
|
||||
( cd "${INSTALL_DIR}/$owned" && find . -type f ) | while IFS= read -r rel; do
|
||||
rel="${rel#./}"
|
||||
[ -e "${STAGING}/${owned}/${rel}" ] || rm -f "${INSTALL_DIR}/${owned}/${rel}"
|
||||
done
|
||||
find "${INSTALL_DIR}/$owned" -mindepth 1 -type d -empty -delete 2>/dev/null || true
|
||||
done
|
||||
|
||||
# Update version file for release channel
|
||||
if [ "$CHANNEL" = "release" ]; then
|
||||
echo "$VERSION" > "$INSTALL_DIR/.release-version"
|
||||
|
||||
Reference in New Issue
Block a user