fix(updater): download via curl with resume instead of Chromium fetch

Chromium's network stack restarts requests mid-stream on flaky Wi-Fi,
yielding a right-sized but corrupt gzip (progress hits 100% three times,
then 'archive corrupt'). curl resumes with HTTP Range so a dropped
connection picks up where it stopped, retries internally, and the whole
file is still byte-count + gunzip verified before handoff. Falls back to
the fetch pipeline when curl is absent.
This commit is contained in:
avi 2026-10-05 00:25:03 -05:00
commit 9afe49c378
2 changed files with 83 additions and 30 deletions

4
package-lock.json generated
View file

@ -1,12 +1,12 @@
{ {
"name": "folio", "name": "folio",
"version": "0.1.8", "version": "0.1.10",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "folio", "name": "folio",
"version": "0.1.8", "version": "0.1.10",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@tiptap/core": "^2.27.2", "@tiptap/core": "^2.27.2",

View file

@ -1220,18 +1220,71 @@ handleIpc("folio:performUpdate", async () => {
app.getPath("temp"), app.getPath("temp"),
`folio-update-${Date.now()}.tar.gz` `folio-update-${Date.now()}.tar.gz`
); );
// Downloads of the ~100MB asset have twice truncated near the end while // Downloads go through curl, not Chromium's network stack: on flaky Wi-Fi
// the server copy stayed intact. The old 2-byte magic check could not // the Electron net stack restarts requests mid-stream, producing a
// see that, so the detached installer failed after the app had quit and // right-sized but corrupt gzip ("100% three times, then failed"). curl
// the update silently no-oped. Now: retry the download up to 3 times, // resumes with HTTP Range (-C -) so a dropped connection continues where
// require the advertised byte count, and gunzip the whole file before // it left off instead of restarting, and retries internally. We still
// handing off. A corrupt file is deleted and the user gets a real error. // verify the exact byte count and gunzip the whole file before handoff.
const { Readable } = await import("stream");
const { createWriteStream } = await import("fs");
const { pipeline } = await import("stream/promises");
const total = Number(asset.size) || 0; const total = Number(asset.size) || 0;
let lastError = ""; let lastError = "";
let downloaded = false; let downloaded = false;
const { spawn } = await import("child_process");
const haveCurl = await new Promise<boolean>((resolve) => {
const p = spawn("curl", ["--version"], { stdio: "ignore" });
p.on("error", () => resolve(false));
p.on("close", (code) => resolve(code === 0));
});
if (haveCurl) {
for (let attempt = 1; attempt <= 3 && !downloaded; attempt++) {
const code = await new Promise<number>((resolve) => {
const c = spawn(
"curl",
[
"-fsSL",
"-C", "-", // resume a partial file
"--max-time", "900",
"--retry", "5", "--retry-delay", "2", "--retry-all-errors",
"--connect-timeout", "15",
"-o", tarball,
asset.browser_download_url,
],
{ stdio: "ignore" }
);
const timer = setInterval(() => {
try {
getWindow()?.webContents.send("folio:update-progress", {
received: fs.statSync(tarball).size,
total,
});
} catch {
/* file not created yet */
}
}, 1000);
c.on("error", () => { clearInterval(timer); resolve(-1); });
c.on("close", (rc) => { clearInterval(timer); resolve(rc ?? -1); });
});
if (code !== 0) {
lastError = `Download failed (curl exit ${code}).`;
continue;
}
const size = fs.existsSync(tarball) ? fs.statSync(tarball).size : 0;
if (looksTruncated(size, total)) {
lastError = `Download truncated (${size}/${total} bytes).`;
continue;
}
if (!(await verifyArchiveGzip(tarball))) {
lastError = "Downloaded archive is corrupt (gzip stream incomplete).";
fs.rmSync(tarball, { force: true }); // corrupted resume file must not poison the next attempt
continue;
}
downloaded = true;
}
} else {
// No curl on PATH: fall back to the in-process fetch pipeline.
const { Readable } = await import("stream");
const { createWriteStream } = await import("fs");
const { pipeline } = await import("stream/promises");
for (let attempt = 1; attempt <= 3 && !downloaded; attempt++) { for (let attempt = 1; attempt <= 3 && !downloaded; attempt++) {
try { try {
const res = await fetch(asset.browser_download_url, { const res = await fetch(asset.browser_download_url, {
@ -1262,6 +1315,7 @@ handleIpc("folio:performUpdate", async () => {
lastError = `Download failed: ${(e as Error).message}`; lastError = `Download failed: ${(e as Error).message}`;
} }
} }
}
if (!downloaded) { if (!downloaded) {
fs.rmSync(tarball, { force: true }); fs.rmSync(tarball, { force: true });
return { return {
@ -1294,7 +1348,6 @@ handleIpc("folio:performUpdate", async () => {
// systemd-run puts the script in its own transient unit that outlives us; // systemd-run puts the script in its own transient unit that outlives us;
// verified to survive on this machine. Fall back to a detached spawn for // verified to survive on this machine. Fall back to a detached spawn for
// non-systemd sessions. // non-systemd sessions.
const { spawn } = await import("child_process");
let handedOff = false; let handedOff = false;
try { try {
const { execFileSync } = await import("child_process"); const { execFileSync } = await import("child_process");