Skip to content

feat(scripts): mirror acceleration for install scripts (NETPANEL_MIRROR) - #99

Merged
PIKACHUIM merged 2 commits into
PIKACHUIM:mainfrom
suantea:feat/install-mirror-accel
Sep 23, 2026
Merged

PIKACHUIM merged 2 commits into
PIKACHUIM:mainfrom
suantea:feat/install-mirror-accel

Conversation

@suantea

@suantea suantea commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • install.sh / install.ps1 now support the NETPANEL_MIRROR env var to pick a download mirror: ghproxy / fastgit / direct
  • Default auto: try direct GitHub download first, fall back to mirrors automatically on failure
  • On download failure the error message hints at mirror usage

Motivation

Users in mainland China often fail to download binaries from GitHub directly. This makes the install scripts work out of the box with automatic fallback, and lets users force a mirror when needed.

Notes

This is part 2 of 3 split from #96 (deploy ease-of-use), kept single-topic per review preference.

- install.sh / install.ps1 支持 NETPANEL_MIRROR 环境变量
- 可选 ghproxy / fastgit / direct,默认 auto:先直连,失败自动回退镜像
- 下载失败时提示镜像用法
pikachuren

This comment was marked as outdated.

P0 NETPANEL_MIRROR=direct 导致安装必然失败:
原分支链为 if ghproxy / elif fastgit / elif MIRROR != "direct",当值为
direct 时三个分支全不命中,mirror_prefixes 保持空数组,后面的
for prefix in "${mirror_prefixes[@]}" 一次都不执行 → 直接落到
"下载失败",即用户显式要求"仅直连"时反而完全无法安装。
改为 else 分支兜底:direct 仅直连,auto 为直连 + 两个镜像。

P1 镜像下载无任何完整性校验:
try_download 下载后直接 chmod +x 交给 install_binary 以 root 安装,
全程无 sha256 校验,而 auto 模式会静默改用第三方镜像。
新增 verify_checksum,复用发行流程已发布的 SHA256SUMS.txt
(.github/workflows/release.yml 会产出),无论二进制来自哪个源都用
该清单校验,清单本身固定取自 GitHub 直连。校验失败即中止安装;
清单/工具不可得时仅告警不阻断,兼容离线与精简环境。

校验匹配用 awk 比较第二列,不用 grep -E "(^|/)name$":该写法在
macOS 自带 BSD grep 上不匹配,会静默跳过全部校验。

验证:bash -n 通过;direct 生成 1 个下载源(原为 0)、auto 生成 3 个;
verify_checksum 正向通过、篡改中止(退出码 1)、清单缺失仅告警不阻断。

@pikachuren pikachuren left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙏 感谢 @suantea 提交!
🤖 AI 自动审核声明:本评审报告由 AI 自动生成,当前使用 Claude Opus 5 模型进行分析。
⚠️ AI 分析结果仅供参考,可能存在误判或遗漏。如您发现任何问题或有不同意见,欢迎随时提出讨论和纠正。
⚠️ 重要提醒:即使 AI 评审认为代码质量良好且建议合并,最终是否合并仍需由项目维护者进行人工判定。项目维护者会综合考虑代码质量、项目规划、技术方向、团队资源等多方面因素做出是否合并的决策。

🔄 增量评审:上轮 → 本轮

本轮新增 1 个 commit(ee7ac536 → 2c5c5e1c),改动文件:scripts/install.sh

新增改动的问题:

  • 💡 [P2] scripts/install.sh:157 — 校验清单固定走直连 github_base/SHA256SUMS.txt。在网络受限环境下会 warn 后跳过校验,等于默认无完整性保障。建议在文档里写明「离线/受限网络安装无校验」,或允许通过环境变量指定可信清单源。

旧问题解决情况:

  • ✅ NETPANEL_MIRROR=direct 的语义错误 → 已显式拆开:direct 只保留直连,auto 才依次追加镜像前缀
  • ✅ 镜像源下载无完整性校验 → 新增 verify_checksum,按发行版附带的 SHA256SUMS.txt 逐项校验(镜像不可信 ⇒ 清单固定取可信来源),并用 awk 精确匹配第二列文件名以规避 BSD grep 的差异。已核对 error() 定义为 echo ... >&2; exit 1,校验失败会中止安装,这段逻辑正确。

🎯 结论:✅ Approve — 直连/镜像分支语义修复正确,镜像源完整性校验补得到位

@PIKACHUIM
PIKACHUIM merged commit a13130f into PIKACHUIM:main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants