8 ms·
> To install Zed on most Linux distributions, run the shell script below. > curl https://zed.dev/install.sh https://zed.dev/install.sh | sh Please stop tellin
by dinozarw 2y ago
> To install Zed on most Linux distributions, run the shell script below.
> curl https://zed.dev/install.sh https://zed.dev/install.sh | sh
Please stop telling people to curl pipe scripts into their shell...
- admax88qqq 2y agoWhy? I’m going to run their software anyways. And this is a really easy way to run an installer. This is basically the Linux equivalent of download and double click which is a user flow that is underrated for simplicity and usability.
- hyperbrainer 2y agoCompletely agree. Furthermore, you could always just not pipe it to sh, read it first if you care so much. Releasing and maintaining packages across a range of distros is extremely hard and time consuming, and they just released the linux version.
- flexagoon 2y ago> Releasing and maintaining packages across a range of distros is extremely hard and time consuming That's why Flatpak exists
- oneshtein 2y agoIt's time consuming only if author interested in good UX. If author wants to use their users as alpha-testers, then he can spent a minimal amount of time on packaging.
- palata 2y agoGiven that it's open source, it's not the authors' problem to package it. You can package it for your distro, or wait for someone to do it. It will be better because you presumably use it. Chances are that the authors don't use the same distro as you do, so they are not in a good position to make a package for you.
- oneshtein 2y agoOf course, nobody forces author to do anything, but insecure installation method will continue to generate loud warning about insecurity.
- admax88qqq 2y agoWhat makes it insecure?
- oneshtein 2y agoIt's other way around. Any method of installation is insecure by default. Moreover, hackers are able to penetrate even multi-layered security defence systems sometimes (for a short period of time). What makes this 0-security system secure?
- admax88qqq 2y agoI don't think I understand your point? My argument is that the install method is just piping a curl command to your shell is _no less secure_ than any other typical application install procedure, and the user experience is pretty decent. I don't think we should be generating "loud warnings" about so called "insecure install methods" nor should we fault the Zed authors for not solving software security.
- oneshtein 2y agoYes, an one 0 security installation method cannot be less secure than an other 0 security installation method. Both are insecure. However, when source code and compilation instructions are available, an independent maintainer can verify source manually, compile it in isolation, test in it in isolation, make patches, add SELinux rules, make package, then sign the package, to produce a secure package, which can be safely consumed by end users.
- palata 2y agoThe point is that when you use a distro, you trust that distro and its maintainers. If you use the package they build for you, then you rely on this trust. Now if you use a random script from the internet, then you don't give your distro maintainers a chance to actually review the package and instead you blindly trust this script. Arguably you increase your attack surface. Also a system package manager checks the packages (there is signatures and stuff), whereas piping a script to curl doesn't do that at all. So if the server is compromised, you just execute random code. It's harder to compromise the system package manager.
- prmoustache 2y agoI don't see how maintaining a 150 lines script is more convenient and less of a hassle to maintain than having a pipeline building a flatpak, an rpm, a deb and a plain tarball with binaries. In 2024, everyone looking for a code editor knows how to extract a tar.gz right?
- jakswa 2y ago> In 2024, everyone looking for a code editor knows how to extract a tar.gz right? I'll raise my hand and say I still get the `tar` terminal command options confused and have to pause and figure out the file format I'm dealing with and the options. So, no, I usually don't know, and have to look it up in the manpage/help. "Was it -xvfz for this one? Shit I just did this recently..."
- prmoustache 2y agoYou don't even need a terminal if you can't remember the options. Extracting an archive is done by any half decent file manager.
- blub 2y agomacOS for example checks the crypto signatures of downloaded apps, so it’s much better than randomly executing code from the internet. I think even Windows does this nowadays.
- bscphil 2y agoBecause you don't know how the script is going to try to install the program. A double-click installer on Windows has a standard approach that results in the program being placed in C\Program Files and the files being tracked and an uninstaller being placed in a centralized location. On Linux, any random "installer script" could spew files all over your /usr or anywhere else with no way to clean them up. This could even break your OS. The Linux equivalent to double-click installer is ... a double-click installer, Flatpak. Or for even more bonus points, make the app fully portable as an AppImage. In the rare case I can't find what I'm looking for in my distribution repos, I look for an AppImage.
- christophilus 2y ago> A double-click installer on Windows has a standard approach Maybe today. In the past, I’ve had them spit stuff all over random places— not to mention registry cruft.
- paride5745 2y agoIndeed! Just release a flatpak, even a snap. I’m not asking to support all distros. But at least one between flatpak and snap is enough to support pretty much all distros out there in a clean manner, not with curl | sh
- slim 2y agobut then I will need curl | sh to install snap :(
- paride5745 2y agolol good stuff snap is in pretty much any distro repo out there :D
- vbezhenar 2y agoThat's only for few minutes before I uninstall it.
- gsck 2y agoSnap is never the answer. Every time I use snap I always get really sad, it could've been great but instead its incredibly slow. Like unusably slow
- fortyseven 2y agoVersus what? Everything you install involves trust at some point.
- lyu07282 2y agoObviously most distributions provide package managers that should be used for unified automated update mechanisms and gpg signing. Superior to curl | sh in every way.
- pilif 2y agoOf the three distros I know to more detailed extents, Debian, Arch and RedHat, none of those make it easy to install and keep updated a third-party package through the built-in package manager. In all cases, signatures and repositories need to be configured, often requiring both root access and usage of the CLI and in all cases much harder than running an installer script (which might be doing exactly these steps). To achieve easy means of installing using distro package managers means including the application in the distro itself, but now it's beholden to the distro's software update policies and thus stuck on that specific version for years or even decades. That is not what a v0.something of an end-user centric desktop application wants for themselves.
- hnarn 2y agoIt's not uncommon that the curl | sh method actually, among other things, detect what distro you're running and add the repos before installing via the package manager, so in the end it depends on what the script actually does. Atuin does it well for example: https://docs.atuin.sh/guide/installation/ https://docs.atuin.sh/guide/installation/ -- and offers other options (as you should).
- ellieh 2y agoWe're actually not going to be doing that for much longer. Lots of users kept querying how it was installed, where, how to remove it, etc. The response of "it depends, we probably used your system package manager" was not often well received. Users who know how to use their package manager tended to just do that anyway, and not use the script.
- DuncanCoffee 2y agoI always see this comment and understand its reasoning, but people who check what they are installing are the same people who can download and check a shell script. In this case it's 150 rows with spaces and comments and the first one is # Downloads the latest tarball from https://zed.dev/releases https://zed.dev/releases and unpacks it # into ~/.local/. If you'd prefer to do this manually, instructions are at # https://zed.dev/docs/linux https://zed.dev/docs/linux. Then it's a download, extract and copy stuff around, it takes 1 minute to visually parse If an install script is obfuscated then yeah, I'd skip it too.