NixOS/guix are gonna solve this issue once and for all (famous last words)
NixOS/guix are gonna solve this issue once and for all (famous last words)
They are almost always irreversible too. Like you can't undo the steps the shell scripts have done.
Edit: I realize you're not speaking specifically about rustup, but what I said can and should apply to anything you choose to install this way.
0: https://www.rust-lang.org/tools/install#rustup
1: https://github.com/rust-lang/rustup
2: https://forge.rust-lang.org/infra/other-installation-methods...
On most languages, you must decide to do it to create a mess. Bash is almost alone on the place where you can do it by accident.
The one mess you see from other languages is creating files on the wrong place (or all over the place). But not those above.
You’re talking as if all bash scripts are hacked together carelessly and work by accident. You can actually learn bash. Thankfully the script we’re discussing is written with care and vetted by the community.
Problems like removing a large directory instead of a file
The rm command doesn’t even remove directories by default, you have to specify a flag. Not knowing a tool is not a good reason to bash it.(And no, those problems do usually not appear due to logic errors or typos in other languages. It's very, very rare.)
I'm well aware that the Rust installation script is well vetted and stable enough to be reliable. Bootstraping a development environment is also a real problem, with no good answers. It's understandable that they want to bootstrap from Bash. But as understandable as it is, it still carries the Bash issues with it.
Of course, the optimum solution would be to do it from your system's tools. That is something that will probably happen naturally given enough time.
It doesn't really matter, if you combine `/home/myuser` and some unsantized input variable, and then call `remove_dir_all` [0], it doesn't matter how safe the language is, you're going to delete your entire home directory with absolutely no warning, whether it's in bash, go, python, rust or haskell. Yes bash makes this very easy to do, but so does pretty much every language in existence.
> (And no, those problems do usually not appear due to logic errors or typos in other languages. It's very, very rare.)
They absolutely do. Here's an explosive script in golang (deliberately doesn't compile just in case) - running this in func main() will ruin your day most likely. dirToRemove := "~/" + os.Getenv("BAD_ENV_VAR") os.RemoveAll(dirToRemove
I can write one of these in bash, python, go, you name it.
rm doens't do that unless you explicitly tell it to.
> Problems like removing a large directory instead of a file, creating your files on random places instead of the directory you pass on, or creating more files than you intended?
But yes, all of these can and do exist in other languages. Using python as an example, if you read an environment variable without checking it's set (as in the infamous steam bug) [0], you'll end up with pretty much the exact same behaviour. You can misindent your loop in python and not create/remove files that you intend to, or your script can have a syntax error halfway through and the interpreter will happily proceed until it halts, and leave you in a half baked state just like bash does.
[0] https://github.com/valvesoftware/steam-for-linux/issues/3671
- the domain in the curlbashware URL could be less shady than sh.rustup.rs
- the "rustup is an official Rust project" claim on https://rustup.rs/ could be a link to a page somewhere on rust-lang.org that confirms that rustup.rs is the site to use
- the domain in the curlbashware URL could be less shady than sh.rustup.rs
The domain is only as shady as it is unfamiliar. It's not shady to me since I recognize it as the canonical domain of the recommended installer for Rust, "rustup". - the "rustup is an official Rust project" claim on https://rustup.rs/ could be a link to a page somewhere on rust-lang.org that confirms that rustup.rs is the site to use
It links to rust-lang.org, whose installation page then describes rustup as the recommended way to install [0]. I suppose it could link directly to the page, but what really does that gain?In HN and similar places, it is pretty normal to see a cc-tld used purely because the abbreviation fits. Not everyone is used to that, though. If it were e.g. https://rustup.dev/, that would mitigate this concern.
Also, a bad actor could just as well register https://rustup.dev. Rather than judging a URL in a vacuum based on the TLD, you should instead cross reference the official docs and confirm that the URL is correct.
And yes, a bad actor could just as easily register rustup.dev. Nobody ever claimed that checking the TLD is sufficient to make a site trustworthy; only that it appears a bit shady. Unless you're already familiar with Rust (or at least with a particular aspect of startup culture), there's no obvious reason to choose .rs. On the other hand, domains in somepopularsite.unrelatedtld have been a phishing staple for decades -- making the shady vibe at least a little bit reasonable.
Of course you should cross reference the authenticity of any URL you are about to execute as a shell script. No one is saying not to.
But your point seems to agree with mine: it’s only as shady as it is unfamiliar. The answer shouldn’t be to come up with a URL that lowers your guard. Instead, users should get familiar.
Relying on a familiar looking domain doesn't get you much security, especially with internationalized domain names where what a domain name appears like in one language could actually be very different in another.
People repeat this a lot but really it just seems dangerous. Can you give an example of a scenario where offering a download via `curl | bash` is more dangerous than "download this installer with the hash 01234 and then execute it"?
I don't have a strong opinion that it's good or bad practice, I just thought it was a clever thing to do about it.
Edit: I think I was thinking of https://news.ycombinator.com/item?id=17636032 / https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b.... Wow, it's been a while.
If you downloaded and peeked into the script before running it, this would be a lot less likely to happen.
There is really no downsides to downloading it, checking it out and then running it other than it not being able to be blindly copy pasted into a terminal.
People copy and paste these commands. They don't type them out. There's a big "copy to clipboard" button next to the rustup one.
Should we take bets on whether this happens first, or whether nuclear fusion becomes mainstream first?