Documentation
¶
Overview ¶
Package selfupdate replaces the running binary with a newer release.
Fetch the release asset for this GOOS/GOARCH, verify its SHA-256 against the checksums the release ships, and rename it over the current executable. Nothing is executed before it is verified, and a failed verification leaves the running binary untouched.
On Unix the dashboard notices the replacement on its own: internal/selfreload watches the executable and re-execs into whatever is there now, so an update applied from another terminal takes effect without anyone quitting. Windows cannot exec over a running image, so the dashboard exits and asks for a restart instead.
Index ¶
Constants ¶
const DefaultRepo = "maci0/toktop"
DefaultRepo is the GitHub repository releases are fetched from.
Variables ¶
This section is empty.
Functions ¶
func Apply ¶
Apply downloads, verifies, and installs the release over the running executable. It returns the path that was replaced.
The new binary is written next to the current one (same filesystem, so the rename is atomic) and only renamed after its checksum matches. A failed verification leaves the running binary untouched. If the destination already matches the release checksum, the asset is not fetched or replaced.
func AssetName ¶
AssetName is the binary this platform needs from a release. It must match what the Makefile's dist target produces, or self-update finds nothing.
func ChecksumFor ¶
ChecksumFor finds one file's expected hash in a `sha256sum` style listing ("<hex> <name>", with an optional binary-mode asterisk).
func ChecksumListing ¶
ChecksumListing pulls checksums.txt out of the tar.gz the release ships it in. Entries are matched by base name, so a wrapper directory around the file does not matter; everything else in the archive is skipped.
func ValidateRepo ¶ added in v0.6.0
ValidateRepo reports whether repo is a GitHub owner/name, the only shape interpolated into the releases API path. Anything else is path traversal, a query string, or log injection into the error that names the URL.
Types ¶
type Release ¶
type Release struct {
TagName string `json:"tag_name"`
HTMLURL string `json:"html_url"`
Assets []struct {
Name string `json:"name"`
URL string `json:"browser_download_url"`
Size int64 `json:"size"`
} `json:"assets"`
}
Release is the subset of a GitHub release that matters here.
func Check ¶
Check queries the latest release. It is never called on the startup path: a version check must not stand between the user and the dashboard.