fix(installer): harden greenfield detector contracts

This commit is contained in:
2026-08-05 17:46:58 -05:00
parent 99e28d4100
commit 3edde464b3
18 changed files with 924 additions and 190 deletions
+11 -16
View File
@@ -7,20 +7,21 @@ Mosaic gives you a unified launcher for Claude Code, Codex, OpenCode, and Pi —
## Quick Install
```bash
bash -o pipefail -c 'curl -fsSL https://mosaicstack.dev/install.sh | bash'
d="$(mktemp -d)" && trap 'rm -rf "$d"' EXIT && curl -fsSL -o "$d/install.sh" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh -o "$d/install.sh.sha256" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh.sha256 && (cd "$d" && test -s install.sh && sha256sum -c install.sh.sha256 && bash install.sh)
```
Or use the direct URL:
```bash
bash <(curl -fsSL https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh)
```
The published installer body must be non-empty and match its versioned SHA-256
sidecar before it executes. A failed fetch, HTTP-200 empty body, or digest
mismatch is fatal. Because both files come from the same repository and trust
domain, this detects corruption or inconsistent publication—not repository or
server compromise. Independently signed release provenance is explicitly
deferred by the greenfield-install PRD.
The installer auto-launches the setup wizard, which walks you through gateway install and verification. Flags for non-interactive use:
```bash
bash <(curl -fsSL …) --yes # Accept all defaults
bash <(curl -fsSL …) --yes --no-auto-launch # Install only, skip wizard
(cd "$d" && bash install.sh --yes) # Accept all defaults
(cd "$d" && bash install.sh --yes --no-auto-launch) # Install only, skip wizard
```
This installs both components:
@@ -348,16 +349,10 @@ Each stage has a dispatch mode (`exec` for research/review, `yolo` for coding),
## Upgrading
Run the installer again — it handles upgrades automatically:
Run the same verified installer flow again — it handles upgrades automatically:
```bash
bash -o pipefail -c 'curl -fsSL https://mosaicstack.dev/install.sh | bash'
```
Or use the direct URL:
```bash
bash <(curl -fsSL https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh)
d="$(mktemp -d)" && trap 'rm -rf "$d"' EXIT && curl -fsSL -o "$d/install.sh" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh -o "$d/install.sh.sha256" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh.sha256 && (cd "$d" && test -s install.sh && sha256sum -c install.sh.sha256 && bash install.sh)
```
Or use the CLI: