Skip to main content

Module self_update

Module self_update 

Source
Expand description

isb update: replace the running isb with a release from GitHub.

The release’s SHA256SUMS must carry a signature (SHA256SUMS.sig) by a release key compiled into isb; the tarball for this build’s target is then checked against it, unpacked next to the running binary (so the final rename stays on one filesystem and is atomic), smoke-tested with --version, and renamed over it. A binary a package manager owns is left to that manager: replacing it underneath mise, cargo, npm or pip leaves their records lying about what is installed. mise installs are deprecated: mise does not check the release signature, so isb points them at INSTALL_COMMAND instead.

Enums§

Manager
A package manager that owns an installed isb.

Constants§

CURRENT
The version of this build.
INSTALL_COMMAND
The installer: it checks the release signature as isb update does and installs to ~/.local/bin, where isb update keeps isb current.
RELEASE_KEYS
Ed25519 public keys (hex) that sign each release’s SHA256SUMS. The signature is SHA256SUMS.sig, 64 raw bytes; the private key is the repo secret ISB_RELEASE_SIGNING_KEY (master copy in the maintainers’ vault). A list, so a new key can ship in a release before the old one retires.

Functions§

current_exe
The running binary’s real path (symlinks resolved, so the file replaced is the one that runs, not the link to it).
host_target
The release target this build matches, as the release assets name it.
install
Download version for target and atomically replace exe with it.
is_newer
Whether a is a newer version than b. Versions are compared by their numeric MAJOR.MINOR.PATCH; anything that does not parse is never newer.
latest_version
The latest published release’s version, without the leading v.
normalize
v1.2.3 and 1.2.3 both mean 1.2.3.
release_asset
The release asset name (without .tar.gz) for a version and target.
verify_sums
Whether sig is a release key’s signature of sums.