Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

switch to using --check #4

Merged
merged 3 commits into from
Nov 1, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 15 additions & 12 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,20 +22,23 @@ Paste the following into your command line to define the `checksum` function.

```bash
function checksum() {
local s
s=$(curl -fsSL "$1")
if ! command -v shasum >/dev/null
then
shasum() { sha1sum "$@"; }
fi
c=$(printf %s\\n "$s" | shasum | awk '{print $1}')
if [ "$c" = "$2" ]
then
printf %s\\n "$s"
local h
if command -v shasum >/dev/null ; then
h=shasum
else
echo "invalid checksum $c != $2" 1>&2;
h=sha1sum
fi
if [ ! "$2" ] ; then
printf %s\\n "$s" | "$h" | awk '{print $1}'
return 1;
fi
unset s
unset c
printf %s\\n "$s" | "$h" --check --status <(printf '%s -\n' "$2") || {
echo "checksum failed" >&2;
return 1;
}
printf %s\\n "$s"
}
```

Expand All @@ -45,7 +48,7 @@ Alternatively, you can download, review and verify the [checksum.sh script](http
```bash
curl -O https://checksum.sh/checksum.sh
cat checksum.sh
echo "26f0b74833d2b98c72c09dcb46f10eab18ac57a3 checksum.sh" | shasum -c
echo "df260dd53581e6e30c0afbe32b80db6b0bec2d07 checksum.sh" | shasum -c
```

If everything is OK, you can source the script which will define the `checksum` function.
Expand Down
25 changes: 14 additions & 11 deletions checksum.sh
Original file line number Diff line number Diff line change
@@ -1,18 +1,21 @@
#!/bin/bash

function checksum() {
local s
s=$(curl -fsSL "$1")
Copy link

@dundarious dundarious Oct 31, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note that shell truncates trailing newlines from variables, so if a script ends with several newlines, it'll only keep the last one. Example exhibiting the problem:

# In another shell, run `python -m http.server --bind localhost 8980`
$ printf %s\\n 1 2 3 "" "" "" > f  # File contents: "1\n2\n3\n\n\n\n"
$ printf %s\\n 1 2 3 > t  # File contents: "1\n2\n3\n"
$ shasum -a 256 f
09bc489de9097269db796e13a5d79c0bdb021a4ba90e1ac1e7f56aecc60b5b7c *f
$ shasum -a 256 t
14c5e74c4b96ccef41cd94db73a9ec3348038ac094feca4fd897cecffa07cdae *t
$ curl -fsSL http://localhost:8980/f | shasum -a 256
09bc489de9097269db796e13a5d79c0bdb021a4ba90e1ac1e7f56aecc60b5b7c *-
$ curl -fsSL http://localhost:8980/t | shasum -a 256
14c5e74c4b96ccef41cd94db73a9ec3348038ac094feca4fd897cecffa07cdae *-
$ t=$(curl -fsSL http://localhost:8980/t)
$ f=$(curl -fsSL http://localhost:8980/f)
$ printf %s\\n "$t" | shasum -a 256
14c5e74c4b96ccef41cd94db73a9ec3348038ac094feca4fd897cecffa07cdae *-
$ printf %s\\n "$f" | shasum -a 256
14c5e74c4b96ccef41cd94db73a9ec3348038ac094feca4fd897cecffa07cdae *-

So printf %s\\n "$f" | shasum -a 256 does not give the same as curl -fsSL http://localhost:8980/f | shasum -a 256, it gives the same result as curl -fsSL http://localhost:8980/t | shasum -a 256 and printf %s\\n "$t" | shasum -a 256.

It's quite likely there exist scripts in the wild that have trailing newlines, so the shell variable capture is probably non-viable.

(I ran this experiment in msys zsh on windows, but ran it based on knowledge of the newline chomping of POSIX sh -- I just double-checked and ran it on bash on linux and it was the same result, only difference being the weird "*" in the shasum output is now another space as expected)

Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the shell variable capture is probably non-viable.

@dundarious given that, downloading the script to a tmp file may be the best solution

Copy link
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

#6

if ! command -v shasum >/dev/null
then
shasum() { sha1sum "$@"; }
fi
c=$(printf %s\\n "$s" | shasum | awk '{print $1}')
if [ "$c" = "$2" ]
then
printf %s\\n "$s"
local h
if command -v shasum >/dev/null ; then
h=shasum
else
echo "invalid checksum $c != $2" 1>&2;
h=sha1sum
fi
if [ ! "$2" ] ; then
printf %s\\n "$s" | "$h" | awk '{print $1}'
return 1;
fi
unset s
unset c
printf %s\\n "$s" | "$h" --check --status <(printf '%s -\n' "$2") || {
echo "checksum failed" >&2;
return 1;
}
printf %s\\n "$s"
}