Skip to content

install.sh: sync the Pages fallback with pilot-protocol/release#49 - #263

Merged
TeoSlayer merged 3 commits into
mainfrom
chore/install-sh-proxy-transport
Sep 24, 2026
Merged

TeoSlayer merged 3 commits into
mainfrom
chore/install-sh-proxy-transport

Conversation

@TeoSlayer

@TeoSlayer TeoSlayer commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

What

Keeps the Pages fallback public/install.sh byte-identical to the canonical installer in pilot-protocol/release#49. sync-install-sh.yml fails its last step, "Fail when the Pages fallback copy has drifted", when the two differ.

Merge order

Merge right after pilot-protocol/release#49, not before.

  • When app-store: add Slipstream splash logo #49 merges, notify-install-sh-sync dispatches release-install-sh-changed to this repo.
  • sync-install-sh then uploads the new canonical script to R2 (pilot-release-assets/install.sh, served by the pilot-release Worker at https://pilotprotocol.network/install.sh) and checks the live URL.
  • Until this PR merges, that run then fails on the drift step. The live URL is already correct at that point, because the R2 upload runs first.
  • If this PR merges first, the push-triggered sync re-uploads the old canonical script and fails the same drift check until app-store: add Slipstream splash logo #49 lands.

Content

This is the installer from release#49 at c36ad9b (sha256 4384f0cb…b671; synced here in a7f94bc, byte-identical to pilotprotocol#470's copy):

  • Root is allowed in a Linux container or VM without systemd when root runs it (Meta Muse). It is still refused on hosts with systemd or launchd, and under sudo/doas on any host.
  • --transport auto|udp|compat and PILOT_TRANSPORT.
  • proxy_cmd handles rotating proxy credentials. Only the command is stored, never the credentials.
  • No raw-IP registry is written for compat, or for auto behind a proxy.
  • Downloads are retried once after a credential rotation.
  • The onboarding text reads replies from send-message --wait.
  • With a daemon that cannot use the proxy (v1.13.9) on a proxy-only host, nothing tells the agent to run pilotctl daemon start; the output points at the pilot-sandbox recipe.
  • The transport is stated after the download, so v1.13.9 is no longer announced as auto.
  • --version <tag> and --channel beta install again: the manifest hash is compared only for the tag it describes.

No other file changes.

🤖 Generated with Claude Code

public/install.sh must stay byte-identical to pilot-protocol/release:install.sh
(sync-install-sh.yml fails its last step when it drifts). This is the
installer from release#49 (ae447bc): root allowed in a Linux container/VM
without systemd (Meta Muse), --transport auto|udp|compat, proxy_cmd for
rotating proxy credentials (never the credentials), no raw-IP registry for
compat or auto behind a proxy, downloads retried once after a credential
rotation, and onboarding text that reads replies from send-message --wait.

Merge right AFTER release#49: merging it first leaves the fallback ahead of
the canonical script until #49 lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Preview deployed to Cloudflare Pages

  • Commit deploy URL: https://185b7b77.pilotprotocol.pages.dev
  • Branch alias: https://chore/install-sh-proxy-transport.pilotprotocol.pages.dev (may take ~30s to propagate)
  • Commit: a7f94bc2774ff64efa88369cc3b6cfbb11ca5616

teovl and others added 2 commits September 24, 2026 10:17
…eview fixes)

Byte-identical to release@67e83fc: root refused under sudo, no
`pilotctl daemon start` advice on proxy-only hosts with a daemon that cannot
use the proxy, the transport stated after the download, and --version /
--channel beta installable again.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…36ad9b)

Byte-identical to release@c36ad9b (sha256 4384f0cb...): sandbox proxy_cmd
only for credentials a fresh shell sees and never over an explicit
PILOT_PROXY; restart advice stops the running daemon before the sandbox
recipe; macOS LaunchAgent start line conditioned and never sent to the
Linux-only recipe; truthful --transport auto note for pre-auto daemons.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants