Skip to content

download: temp-file+rename for the raw path, verify on extract paths, mismatch test #187

Description

@fentas

Follow-ups from the #186 review round (the trust-pair fix). #186 made 403/401 and 0-byte downloads hard errors; these three harden the write path itself:

  1. Temp-file + rename for the raw-copy path (pkg/binary/download.go ~:575): the download opens the FINAL path with O_TRUNC, so a failed verifyWritten leaves a truncated binary in place and tells the user to retry. Write to <file>.partial and rename only after verify — the previous good binary then survives every failure mode. (Self-update already has its own .old rollback; this is for the general path.)
  2. Extract paths lack any size/emptiness verify: extractSingleFileFromTar/Zip + extractFromTarAuto/ZipAuto (~:64/:128/:319/:409) — a 0-byte tar.gz currently dies as a bare EOF from gzip. Apply the same verify + a message naming the file.
  3. Content-Length-mismatch branch untested (~:47): the written != contentLength error path has no test; add an httptest case with a lying Content-Length.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions