mirror of
https://github.com/affaan-m/ECC.git
synced 2026-09-28 12:35:13 +02:00
* fix(install): make install.sh robust to sh/dash invocation Two related portability fixes so `sh install.sh` behaves correctly even though the script is written for bash: - The cygpath detection used the bash-only `&>/dev/null` redirection. dash misparses `&>`, so `command -v cygpath &>/dev/null` always took the true branch and tried to run the nonexistent `cygpath` binary, failing with "cygpath: not found". Switched to the POSIX-portable `>/dev/null 2>&1` form. - Some dash builds don't support `set -o pipefail`, so `sh install.sh` can fail immediately at that line before even reaching the cygpath check (or the `[[ ... ]]` symlink-resolution logic further down). Added a guard that re-execs the script under bash when the current shell lacks bash capabilities, so the rest of the bash-only syntax always runs under a real bash regardless of the invoking shell. The guard probes for the `[[` compound command directly (via `eval '[[ 1 == 1 ]]'`) rather than trusting the $BASH_VERSION environment variable, since that variable could be inherited or spoofed under a non-bash shell and cause the guard to be skipped. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XBaBRjaZgwhrZtYoqcQfp * test(install): cover the sh install.sh re-exec path Greptile flagged that the bash re-exec guard added in install.sh has no automated coverage, since the existing test helper only invoked the wrapper via `bash`. Adds two regression tests: - "delegates to the Node installer when invoked via a POSIX sh wrapper" — runs the script via `sh` and asserts the args/cwd still reach the Node installer correctly. - "re-execs into bash under sh even when BASH_VERSION is spoofed in the environment" — exercises the eval '[[ 1 == 1 ]]' capability probe directly, guarding against a regression back to trusting the (spoofable) $BASH_VERSION variable. CodeRabbit then pointed out that the second test used generic `sh`, which could trivially pass without exercising the re-exec branch at all if `sh` ever resolves to bash on some system. Added a findPosixOnlyShell() helper that prefers `dash` (falling back to checking `sh`, and skipping with an explicit message if neither genuinely lacks bash's `[[`), so the test reliably exercises the branch it claims to cover instead of passing vacuously. CodeRabbit then flagged that the skip path itself was miscounted as a pass (the callback returned normally, so `test()` reported success and `passed` was incremented even though nothing executed). Moved the findPosixOnlyShell() check outside the test() registration, so the test is only registered — and only counted — when a genuinely POSIX-only shell is actually available; otherwise it's excluded from both the passed and failed counts with an explicit skip line. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XBaBRjaZgwhrZtYoqcQfp --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
43 lines
1.7 KiB
Bash
Executable File
43 lines
1.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# install.sh — Legacy shell entrypoint for the ECC installer.
|
|
#
|
|
# This wrapper resolves the real repo/package root when invoked through a
|
|
# symlinked npm bin, then delegates to the Node-based installer runtime.
|
|
|
|
# Re-exec under bash if invoked via a POSIX sh (e.g. `sh install.sh`), since
|
|
# the rest of this script relies on bash features (`set -o pipefail`, `[[`).
|
|
# Probe actual shell capability instead of trusting $BASH_VERSION, which is
|
|
# just an environment variable and could be inherited/spoofed under sh.
|
|
if ! (eval '[[ 1 == 1 ]]' >/dev/null 2>&1); then
|
|
exec bash "$0" "$@"
|
|
fi
|
|
|
|
set -euo pipefail
|
|
|
|
SCRIPT_PATH="$0"
|
|
while [ -L "$SCRIPT_PATH" ]; do
|
|
link_dir="$(cd "$(dirname "$SCRIPT_PATH")" && pwd)"
|
|
SCRIPT_PATH="$(readlink "$SCRIPT_PATH")"
|
|
[[ "$SCRIPT_PATH" != /* ]] && SCRIPT_PATH="$link_dir/$SCRIPT_PATH"
|
|
done
|
|
SCRIPT_DIR="$(cd "$(dirname "$SCRIPT_PATH")" && pwd)"
|
|
|
|
# Auto-install Node dependencies when running from a git clone.
|
|
# SECURITY: --ignore-scripts blocks preinstall/postinstall RCE from a
|
|
# compromised dependency. ECC deps are pure JS (no native build step).
|
|
if [ ! -d "$SCRIPT_DIR/node_modules" ]; then
|
|
echo "[ECC] Installing dependencies..."
|
|
(cd "$SCRIPT_DIR" && npm install --ignore-scripts --no-audit --no-fund --loglevel=error)
|
|
fi
|
|
|
|
# On MSYS2/Git Bash, convert the POSIX path to a Windows path so Node.js
|
|
# (a native Windows binary) receives a valid path instead of a doubled one
|
|
# like G:\g\projects\... that results from Git Bash's auto path conversion.
|
|
if command -v cygpath >/dev/null 2>&1; then
|
|
NODE_SCRIPT="$(cygpath -w "$SCRIPT_DIR/scripts/install-apply.js")"
|
|
else
|
|
NODE_SCRIPT="$SCRIPT_DIR/scripts/install-apply.js"
|
|
fi
|
|
|
|
exec node "$NODE_SCRIPT" "$@"
|