4 ms·
I do not even dislike curl|sh for security reasons. Package managers go to great lengths to provide a reproducible runtime within them. When was the last time y
by mioelnir 10y ago
I do not even dislike curl|sh for security reasons. Package managers go to great lengths to provide a reproducible runtime within them. When was the last time you saw 'curl | env -i sh -C' as instruction?
If the script fails halfway? Good look trying to undo whatever it did if you do not have access to `zfs rollback` or similar.
It is also less-than-fun to go through `zfs diff` and the downloaded script to make a package out of it that can be distributed and automated.
- __david__ 10y agoAgreed, I think this is the biggest issue. Also you have to trust some random installer to put the binary...somewhere? Is it going to overwrite junk in /usr/local? Does it assume ~/.something is available? Does it require root and then try to stuff code into /etc? Does it work if the install directory has a space in it? What if there's a symlink somewhere in the path? There's a million things that the script can do stupidly, and practically every single one has at least one assumption that is bad. One trick I've learned is to edit the script before running it and prefix anything that looks dangerous with "echo" (because of course none of them ever support --dry-run). Then I can at least see what they are doing, what they are downloading, etc. curl|sh is the bane of my existence. Shame on you if that's your only means of installing.
- jjnoakes 10y agoNone of this is an inherent problem with curl and piping however; any installer you could download and run has the same list of issues, and many of those aren't even auditable. You should redirect your anger away from curl and pipe and toward using install scripts vs package managers in general, because that's where your beef really is.
- __david__ 10y agoI don't know about you but I don't end up running binary installers too much. Certainly not on linux. Even so, windows style binary installers are at least frameworks designed for installing stuff (many with years of bug fixes under their belt), while the curl|sh style installers are just ad-hoc one-offs written in a language that's known for being pretty hostile to defensive programming. So yes, any installer could make those errors, but in my experience only random shell installers seem to do that. Saying they are the same is a false equivalency in my eyes.
- jjnoakes 10y agoWho said anything about only binary installers? I specifically mentioned install scripts as being different from the subject of the discussion, and you seem to be conflating the two.
- __david__ 10y agoYou said, "many of those aren't even auditable." The only installers I can think of that aren't auditable are binary installers. If you meant something else, I'm not understanding.