From a82c1bea17d145fe3869a53ba8e58bd6b005cd4a Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 11:22:33 +0100 Subject: [PATCH 1/4] fix(setup): install just from a checksum-verified release, not curl|bash Both just.systems/install.sh | bash fallbacks are replaced with install_just_verified: a pinned just 1.58.0 release binary per platform, fetched over TLS1.2+ into mktemp and sha256-checked before install (ported from hyperpolymath/standards setup.sh 3079bc12; macOS shasum fallback added). Unknown platforms fail rather than guess a target. Verified locally: real download installs just 1.58.0; a tampered digest is rejected; sh -n + shellcheck clean; hypatia scan reports no shell_download_then_run in setup.sh. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65 --- setup.sh | 63 ++++++++++++++++++++++++++++++++++++++++++++++++++++---- 1 file changed, 59 insertions(+), 4 deletions(-) diff --git a/setup.sh b/setup.sh index 24c7e5e..6dc8e7a 100755 --- a/setup.sh +++ b/setup.sh @@ -128,6 +128,61 @@ detect_platform() { esac } +# ── Verified just install ── +# Replaces `curl https://just.systems/install.sh | bash`: piping a remote script +# into a shell runs whatever the server returns, with no chance to check it. +# A pinned RELEASE BINARY is fetched instead and its digest checked before use +# (ported from hyperpolymath/standards setup.sh, 3079bc12). Digests computed +# 2026-08-07; casey/just publishes none, so this is trust-on-first-use — any +# later substitution fails loudly. An unrecognised platform returns failure +# rather than fetching a plausible-looking binary for the wrong target. +JUST_VERSION="1.58.0" + +just_target() { + case "$(uname -s 2>/dev/null):$(uname -m 2>/dev/null)" in + Linux:x86_64|Linux:amd64) echo "x86_64-unknown-linux-musl" ;; + Linux:aarch64|Linux:arm64) echo "aarch64-unknown-linux-musl" ;; + Darwin:x86_64) echo "x86_64-apple-darwin" ;; + Darwin:arm64|Darwin:aarch64) echo "aarch64-apple-darwin" ;; + *) echo "" ;; + esac +} + +just_sha256() { + case "$1" in + x86_64-unknown-linux-musl) echo "4a5cc2f53e6f0f8c59092a6cc38291eb729d46a7dd95d3ae582008881b84931d" ;; + aarch64-unknown-linux-musl) echo "748237128c4c40cbdabc65e841d05ceba13cc23a91eaba395495894c1d9764df" ;; + x86_64-apple-darwin) echo "9a09cfef66aaa79da58203970103a0684307716caaabd3e9844cacc4dc0f4023" ;; + aarch64-apple-darwin) echo "50ae3e996c974a0bf32ea7d10f495070df33f1b43e0616b2769e3d4821ed8f48" ;; + *) echo "" ;; + esac +} + +# sha256sum is GNU; macOS ships shasum instead. +sha256_of() { + if command -v sha256sum >/dev/null 2>&1; then sha256sum "$1" | cut -d" " -f1 + else shasum -a 256 "$1" | cut -d" " -f1 + fi +} + +install_just_verified() { + jv_target="$(just_target)" + [ -z "$jv_target" ] && { fail "just: no verified build for $(uname -s)/$(uname -m); use your package manager"; return 1; } + jv_want="$(just_sha256 "$jv_target")" + jv_tmp="$(mktemp -d)" + jv_url="https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-${jv_target}.tar.gz" + curl -fsSL --proto '=https' --tlsv1.2 -o "$jv_tmp/just.tar.gz" "$jv_url" || { rm -rf "$jv_tmp"; return 1; } + jv_got="$(sha256_of "$jv_tmp/just.tar.gz")" + if [ "$jv_got" != "$jv_want" ]; then + fail "just: CHECKSUM MISMATCH for $jv_url (expected $jv_want, got $jv_got)" + rm -rf "$jv_tmp" + return 1 + fi + tar -xzf "$jv_tmp/just.tar.gz" -C "$jv_tmp" just + sudo install -m 0755 "$jv_tmp/just" /usr/local/bin/just + rm -rf "$jv_tmp" +} + # ── Install just ── install_just() { if command -v just >/dev/null 2>&1; then @@ -140,8 +195,8 @@ install_just() { case "$PKG_MGR" in dnf) sudo dnf install -y just ;; apt) sudo apt-get install -y just 2>/dev/null || { - # just not in older apt repos — use installer - curl -fsSL https://just.systems/install.sh | bash -s -- --to /usr/local/bin + # just not in older apt repos — use the verified release binary + install_just_verified } ;; pacman) sudo pacman -S --noconfirm just ;; apk) sudo apk add just ;; @@ -152,8 +207,8 @@ install_just() { guix) guix install just ;; nix) nix-env -iA nixpkgs.just ;; *) - info "Using just installer script..." - curl -fsSL https://just.systems/install.sh | bash -s -- --to /usr/local/bin + info "Installing verified just release..." + install_just_verified ;; esac From 124518b6a14ff55b460c44f566d9f699d3ff407e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 11:23:24 +0100 Subject: [PATCH 2/4] docs(setup): stop advertising curl|sh in the usage comment The advertised rsr-template-repo URL no longer exists (setup.sh was removed there in 162b02a), and the pattern is the one this script now refuses to use for just. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65 --- setup.sh | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/setup.sh b/setup.sh index 6dc8e7a..bf83d34 100755 --- a/setup.sh +++ b/setup.sh @@ -6,9 +6,7 @@ # Then hands off to `just setup` for project-specific configuration. # # Usage: -# curl -fsSL https://raw.githubusercontent.com/hyperpolymath/rsr-template-repo/main/setup.sh | sh -# # or after cloning: -# ./setup.sh +# ./setup.sh # after cloning — read it first; never pipe a fetched script into a shell # # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) From ba8acca9453db1821f48ea6429f2be8ffe293d5e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 11:27:18 +0100 Subject: [PATCH 3/4] Update setup.sh Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- setup.sh | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/setup.sh b/setup.sh index bf83d34..b6efde3 100755 --- a/setup.sh +++ b/setup.sh @@ -176,9 +176,11 @@ install_just_verified() { rm -rf "$jv_tmp" return 1 fi - tar -xzf "$jv_tmp/just.tar.gz" -C "$jv_tmp" just - sudo install -m 0755 "$jv_tmp/just" /usr/local/bin/just + tar -xzf "$jv_tmp/just.tar.gz" -C "$jv_tmp" just \ + && sudo install -m 0755 "$jv_tmp/just" /usr/local/bin/just + jv_rc=$? rm -rf "$jv_tmp" + return "$jv_rc" } # ── Install just ── From 3b42ef41703151c36abbe46f4e1db9e7923d710a Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 10:33:36 +0000 Subject: [PATCH 4/4] docs(setup): document just release lookup and verified installation helpers --- setup.sh | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/setup.sh b/setup.sh index b6efde3..f69d2a9 100755 --- a/setup.sh +++ b/setup.sh @@ -136,6 +136,8 @@ detect_platform() { # rather than fetching a plausible-looking binary for the wrong target. JUST_VERSION="1.58.0" +# Print the just release target for the current OS and architecture. +# Takes no arguments; prints an empty line for unsupported platforms. just_target() { case "$(uname -s 2>/dev/null):$(uname -m 2>/dev/null)" in Linux:x86_64|Linux:amd64) echo "x86_64-unknown-linux-musl" ;; @@ -146,6 +148,8 @@ just_target() { esac } +# Print the pinned archive SHA-256 for the release target passed as $1. +# Prints an empty line if the target has no known digest for JUST_VERSION. just_sha256() { case "$1" in x86_64-unknown-linux-musl) echo "4a5cc2f53e6f0f8c59092a6cc38291eb729d46a7dd95d3ae582008881b84931d" ;; @@ -163,6 +167,10 @@ sha256_of() { fi } +# Download JUST_VERSION for the current platform and verify its pinned digest +# before installing to /usr/local/bin/just with sudo. Takes no arguments. +# Returns nonzero for an unsupported platform, download or checksum failure, +# or failed extraction or installation; removes the temporary download directory. install_just_verified() { jv_target="$(just_target)" [ -z "$jv_target" ] && { fail "just: no verified build for $(uname -s)/$(uname -m); use your package manager"; return 1; }