#!/bin/sh
# Install Caedos on macOS or Linux:
#
# curl -fsSL https://caedos.com/install.sh | sh
#
# This downloads the build for this computer from the latest release at
# https://github.com/caedos-os/caedos-run/releases and checks it against the
# release's SHA256SUMS. When OpenSSL 3 is installed, it also checks that
# SHA256SUMS is signed by the Caedos release key. Then it puts `caedos` in
# ~/.local/bin, and its license and notices in ~/.local/share/doc/caedos.
# It needs no sudo, and it changes nothing else.
#
# Settings:
# CAEDOS_VERSION=v0.1.0 install that release instead of the latest
# CAEDOS_INSTALL_DIR=
put caedos there instead of ~/.local/bin
#
# Why a script on a Mac: Apple hasn't notarized Caedos yet, so macOS blocks it
# when a browser downloaded it. macOS doesn't flag what curl downloads.
set -eu
# The public half of the Caedos release key, also shown on caedos.com/security.
RELEASE_KEY='-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEAeBpo421IZkUVLfc27/YSr+nebeFyfTgixtQjpPQCoUQ=
-----END PUBLIC KEY-----'
say() { printf '%s\n' "$*"; }
fail() { printf 'caedos install: %s\n' "$*" >&2; exit 1; }
main() {
case "$(uname -s)" in
Linux) os=linux ;;
Darwin) os=darwin ;;
*) fail "this script is for macOS and Linux. On Windows, run this in PowerShell: irm https://caedos.com/install.ps1 | iex" ;;
esac
case "$(uname -m)" in
x86_64 | amd64) arch=x64 ;;
arm64 | aarch64) arch=arm64 ;;
*) fail "there's no Caedos build for $(uname -m) processors yet." ;;
esac
# A Mac with Apple silicon says x86_64 to a shell running under Rosetta.
if [ "$os" = darwin ] && [ "$(sysctl -n sysctl.proc_translated 2>/dev/null || true)" = 1 ]; then arch=arm64; fi
name="caedos-$os-$arch"
releases=https://github.com/caedos-os/caedos-run/releases
case "${CAEDOS_VERSION:-}" in
'') from="$releases/latest/download" ;;
v*) from="$releases/download/$CAEDOS_VERSION" ;;
*) from="$releases/download/v$CAEDOS_VERSION" ;;
esac
bin="${CAEDOS_INSTALL_DIR:-$HOME/.local/bin}"
doc="${XDG_DATA_HOME:-$HOME/.local/share}/doc/caedos"
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
say "Downloading $name.tar.gz"
for file in "$name.tar.gz" SHA256SUMS SHA256SUMS.sig; do
curl -fsSL -o "$tmp/$file" "$from/$file" || fail "couldn't download $from/$file"
done
printf '%s\n' "$RELEASE_KEY" > "$tmp/release-key.pem"
case "$(openssl version 2>/dev/null || true)" in
"OpenSSL "[3-9]*)
openssl pkeyutl -verify -pubin -inkey "$tmp/release-key.pem" -rawin \
-in "$tmp/SHA256SUMS" -sigfile "$tmp/SHA256SUMS.sig" > /dev/null 2>&1 \
|| fail "SHA256SUMS isn't signed by the Caedos release key. Nothing was installed."
say "Signature OK" ;;
*) say "Signature not checked: that needs OpenSSL 3. The checksum is checked either way." ;;
esac
want="$(awk -v f="$name.tar.gz" '$2 == f || $2 == "*" f { print $1 }' "$tmp/SHA256SUMS")"
if command -v sha256sum > /dev/null 2>&1; then
got="$(sha256sum "$tmp/$name.tar.gz")"
else
got="$(shasum -a 256 "$tmp/$name.tar.gz")"
fi
got="${got%% *}"
[ -n "$want" ] && [ "$got" = "$want" ] || fail "$name.tar.gz doesn't match SHA256SUMS. Nothing was installed."
say "Checksum OK"
tar -xzf "$tmp/$name.tar.gz" -C "$tmp"
mkdir -p "$bin" "$doc"
# Copy beside the old one, then rename over it: a caedos that's running keeps going.
cp "$tmp/$name/caedos" "$bin/.caedos.new"
chmod 755 "$bin/.caedos.new"
mv -f "$bin/.caedos.new" "$bin/caedos"
cp "$tmp/$name/LICENSE" "$tmp/$name/THIRD_PARTY_NOTICES" "$doc/"
installed="$("$bin/caedos" version < /dev/null 2>&1)" || fail "caedos is in $bin, but it didn't run on this computer: $installed"
say "Installed $installed in $bin"
say "License and notices: $doc"
case ":$PATH:" in
*":$bin:"*) run=caedos ;;
*)
run="$bin/caedos"
say ""
case "${SHELL:-}" in
*/fish)
say "$bin isn't on your PATH. To run plain \`caedos\`, run this once:"
say " fish_add_path \"$bin\"" ;;
*)
case "${SHELL:-}" in
*/zsh) rc="~/.zshrc" ;;
*/bash) if [ "$os" = darwin ]; then rc="~/.bash_profile"; else rc="~/.bashrc"; fi ;;
*) rc="your shell's startup file" ;;
esac
say "$bin isn't on your PATH. To run plain \`caedos\`, add this line to $rc and open a new terminal:"
say " export PATH=\"$bin:\$PATH\"" ;;
esac
;;
esac
say ""
say "Start it: $run start"
say "Then connect your AI: https://caedos.com/start"
}
main "$@"