Follow-ups from the #186 review round (the trust-pair fix). #186 made 403/401 and 0-byte downloads hard errors; these three harden the write path itself:
- Temp-file + rename for the raw-copy path (
pkg/binary/download.go ~:575): the download opens the FINAL path with O_TRUNC, so a failed verifyWritten leaves a truncated binary in place and tells the user to retry. Write to <file>.partial and rename only after verify — the previous good binary then survives every failure mode. (Self-update already has its own .old rollback; this is for the general path.)
- Extract paths lack any size/emptiness verify:
extractSingleFileFromTar/Zip + extractFromTarAuto/ZipAuto (~:64/:128/:319/:409) — a 0-byte tar.gz currently dies as a bare EOF from gzip. Apply the same verify + a message naming the file.
- Content-Length-mismatch branch untested (~:47): the
written != contentLength error path has no test; add an httptest case with a lying Content-Length.
Follow-ups from the #186 review round (the trust-pair fix). #186 made 403/401 and 0-byte downloads hard errors; these three harden the write path itself:
pkg/binary/download.go~:575): the download opens the FINAL path withO_TRUNC, so a failedverifyWrittenleaves a truncated binary in place and tells the user to retry. Write to<file>.partialand rename only after verify — the previous good binary then survives every failure mode. (Self-update already has its own.oldrollback; this is for the general path.)extractSingleFileFromTar/Zip+extractFromTarAuto/ZipAuto(~:64/:128/:319/:409) — a 0-byte tar.gz currently dies as a bareEOFfrom gzip. Apply the same verify + a message naming the file.written != contentLengtherror path has no test; add an httptest case with a lying Content-Length.