Skip to content

fix(setup): checksum-verified just install instead of curl|bash (CWE-494) - #122

Merged
hyperpolymath merged 4 commits into
mainfrom
fix/verified-just-install-signed
Oct 1, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
fix/verified-just-install-signed

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

This replaces #119. The tree is byte-identical (git diff origin/fix/verified-just-install HEAD is empty). The only change is that every commit is now signed.

#119 could not merge because main enforces required_signatures. CodeRabbit's docstring commit (3b42ef4) was pushed unsigned. That commit could only be removed by rewriting the branch with a force-push, so this branch instead cherry-picks it signed, keeping CodeRabbit as the author (a080f08).

The content is unchanged from #119, which CodeRabbit approved. It installs just from a pinned release binary checked against a SHA-256 digest, instead of piping curl https://just.systems/install.sh into bash (CWE-494).

The open code-scanning note on setup.sh line 130 (download_then_run_shell) points at a comment that quotes the old one-liner. It is not live code. Hypatia's comment-line fix is in hyperpolymath/hypatia#883.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

hyperpolymath and others added 4 commits September 30, 2026 11:22
Both just.systems/install.sh | bash fallbacks are replaced with
install_just_verified: a pinned just 1.58.0 release binary per platform,
fetched over TLS1.2+ into mktemp and sha256-checked before install
(ported from hyperpolymath/standards setup.sh 3079bc12; macOS shasum
fallback added). Unknown platforms fail rather than guess a target.

Verified locally: real download installs just 1.58.0; a tampered digest
is rejected; sh -n + shellcheck clean; hypatia scan reports no
shell_download_then_run in setup.sh.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
The advertised rsr-template-repo URL no longer exists (setup.sh was
removed there in 162b02a), and the pattern is the one this script now
refuses to use for just.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Repository guideline files applied to this review (2)
CLAUDE.md — auto-discovered
.github/copilot-instructions.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 41f53fcb-d159-471c-a4f8-98ac4a41f7ba

📥 Commits

Reviewing files that changed from the base of the PR and between 86cb69e and a080f08.

📒 Files selected for processing (1)
  • setup.sh

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (37)
  • GitHub Check: scan / rust-secrets
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: scan / shell-secrets
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: scan / gitleaks
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Security policy checks
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Live Actions policy (credentialed advisory)
  • GitHub Check: check
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: boundary
  • GitHub Check: panic-attack assail
  • GitHub Check: Patch Bridge CVE triage
  • GitHub Check: E2E (coordination repo — nothing to exercise)
  • GitHub Check: lint
  • GitHub Check: Hypatia neurosymbolic scan
  • GitHub Check: Runtime Policy
  • GitHub Check: docs
  • GitHub Check: Validate DEED manifests
  • GitHub Check: Empty-linter (invisible characters)
  • GitHub Check: Groove manifest check
  • GitHub Check: Validate K9 contracts
  • GitHub Check: analyze (actions, none)
  • GitHub Check: Validate eclexiaiser manifest
  • GitHub Check: check
  • GitHub Check: antipattern-check
  • GitHub Check: openssf-compliance
  • GitHub Check: semgrep-cloud-platform/scan
🧰 Additional context used
📓 Path-based instructions (2)
Source excerpt: Licence **MPL-2.0** + SPDX header on every file (never AGPL).

📄 CodeRabbit inference engine (CLAUDE.md)

Files:

  • setup.sh
Source excerpt: SPDX: `MPL-2.0` on all new files.

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

Files:

  • setup.sh
🔇 Additional comments (1)
setup.sh (1)

9-9: LGTM!

Also applies to: 129-168, 170-193, 206-207, 218-219


📝 Summary

Summary by CodeRabbit

  • Setup
    • Setup instructions now direct you to run the local setup script after cloning, rather than piping a downloaded script into the shell.
    • The setup script installs just version 1.58.0 on supported Linux and macOS systems, verifying the download before installation. Unsupported systems or installation problems now result in a clear failure instead of falling back to an unverified installer.

Walkthrough

The setup script now installs just version 1.58.0 from pinned release archives for supported Linux and macOS targets. It verifies each archive before installation and uses this installer in the apt and default package-manager fallback branches.

Changes

Verified just installation

Layer / File(s) Summary
Install and verify the just release
setup.sh
The script defines supported release targets and pinned hashes, downloads and verifies the selected archive, then installs just. The apt and default package-manager fallback branches use this installer. The usage comment directs users to run ./setup.sh after cloning.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to a080f

The fallback installer now verifies a pinned release before installation and stops setup on failure. No actionable merge-blocking risk was identified; normal installation checks remain appropriate.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a080f

The change substantially reduces exposure to substituted remote installer code. Remaining uncertainty concerns the initial digest provenance and interrupted or concurrent privileged installation, rather than a demonstrated new attack path.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The privileged sink is a host-wide executable under /usr/local/bin, so an accepted malicious artifact could affect other users or processes that later invoke that path. Installation requires sudo authority; the inspected flow does not establish cross-host or tenant reachability.

Security Findings and Attack Paths

  • inferred — A substituted remote download must match the repository-pinned digest before reaching installation, unlike the previous remote-shell path. Local same-UID mutation between verification and privileged copying remains a possible handoff weakness, but a new privilege-escalation path is not established without the applicable sudo policy and local threat model.

Trust Boundaries and Controls

  • observed — The new acceptance control combines a fixed version and target-specific digest with HTTPS download restrictions. Unsupported targets and checksum mismatches return failure before extraction or sudo installation. Existing executables remain trusted without re-verification, as they were before this PR.

Resilience and Maintainability Implications

  • inferred — The helper returns extraction or installation failure, but interruption and concurrent destination writes lack explicit recovery guarantees. Because the outer caller checks only command presence, propagation of partial-install failure depends on the resulting filesystem state. Platform-specific partial-file behavior was not verified.

Hardening Proposals

  • proposed — Make temporary-directory creation failure explicit, add interruption cleanup, and preserve the helper's failure result at its callers. If concurrent or restricted-sudo installation is supported, define a protected, serialized publication step with destination validation and recovery behavior.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the security change and branch-signing context, but it does not follow the repository template. It omits the required Changes section, checklist responses, Testing section, an… Rewrite the description using the repository template. Add a Summary, a Changes list, completed Required and Applicable checklist items, a Testing section with commands and results, and Screenshots or terminal output when applicable.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: checksum verification for the just installation instead of curl|bash.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the security change and branch-signing context, but it does not follow the repository template. It omits the required Changes section, checklist responses, Testing section, and Screenshots section.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the hash with care,
Then finds a pinned release there.
The script installs just in place,
For Linux and Mac at measured pace.
Hops away with carrots to spare.

Comment @coderabbitai help to get the list of available commands.

Comment thread setup.sh
}

# ── Verified just install ──
# Replaces `curl https://just.systems/install.sh | bash`: piping a remote script
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants