"curl-to-shell pipe to install" - what's the problem here? that's pretty common on linux systems and something the AWS CLI uses.
Or is the problem the fact that this dev is untrusted and is executing a possibly malicious script on your machine?
"curl-to-shell pipe to install" - what's the problem here? that's pretty common on linux systems and something the AWS CLI uses.
Or is the problem the fact that this dev is untrusted and is executing a possibly malicious script on your machine?
I've run Linux without meaningful package management, as that was kind of the style of the time 30 years ago with Slackware. It can quickly become untenable.
There's no real difference between an uninspected script that gets piped straight from the URL into the shell, or a similarly-uninspected make&&sudo make install routine from a tarball. They can both execute code that does bad things (whether unintentionally or deliberately), and they can both leave a mess that is hard to cleaned up.
I've found that it is better to just avoid going down that road to begin with. Whether distro-specific packages, Docker containers, flatpaks, or whatever: All of these make housekeeping easier.
For reasons my machine with a beefy GPU is stuck on an older set of Nvidia drivers. I've got them pinned with apt. The ollama installer fucked everything up by updating stuff that apparently wasn't pinned. After I had fun cleaning up that fucking mess I found it overwrote my custom systemd service file so I had to go in and fix that.
Curl-to-shell is a bullshit antipattern. I have no interest in going back to the dark days of expanding tarballs to / and hoping for the best.
And when the new distro-provided nVidia driver does something garish like, say, break XFCE, then it's easy(ish) to roll it back using distro tools and pin it there. After that, just wait until some other more-functional combination of shakes loose in the distro channel.
When a new nVidia driver shows up that promises a fix but the distro hasn't packaged it yet, then the temptation to just download and run the installer that's on nVidia's website. But using nVidia's special-sauce installer taints the system in ways that distro tools deliberately seek to avoid.
And: Oh, man. I'd almost forgotten about the binary tarballs that were intended to be simply dumped into /, where they'd just tromp on whatever. Sure, it was fast. And for some people, some times, it even worked. Sometimes, it didn't work. Other times, it broke other things that had been working. And it left a mess behind every single time.
A little bit of a mess isn't necessarily devastating on a personal system. But the mess accumulates every time such an unmanaged installation process happens until it eventually overwhelms to the point that even the most functionally-disorganized of people become dysfunctional.
I’m not sure how your machine is configured but mine has permission boundaries and security policies that make sure programs are behaving properly. I don’t run everything with my personal user context.
If someone wants to be reckless they can be. If someone doesn't, they also have that ability.
But really, there is no reason not to use prebuilt packages for distribution. Curlpiping needs to die.
Furthermore, you can be sure that theversion that you download is the same version it has always been and it is the same version everyone else sees. Curl|bash can mean getting a version of the code that is different from everybody else.