Skip to content

fix(update-check): detect nix and linuxbrew installs on linux - #415

Open
BenyD wants to merge 3 commits into
Infisical:mainfrom
BenyD:fix/update-check-nix-linuxbrew
Open

BenyD wants to merge 3 commits into
Infisical:mainfrom
BenyD:fix/update-check-nix-linuxbrew

Conversation

@BenyD

@BenyD BenyD commented Sep 27, 2026

Copy link
Copy Markdown

Re-raising #344, which GitHub closed automatically when I deleted my fork. Code and tests are unchanged from the original, including the follow-up commit that bounds the Linuxbrew match to linuxbrew/. Sorry for the new number.


Description 📣

On Linux, getUpdateInstructions never inspects the executable path outside the npm check. It falls through to getLinuxPackageManager(), which only probes which package managers happen to exist on the machine, so a Nix install on Debian or Ubuntu is told to run apt-get install infisical for a binary living in the immutable Nix store.

Homebrew-on-Linux hits the same gap, since /home/linuxbrew/.linuxbrew/ does not match the /homebrew/ substring the darwin branch checks for.

This mirrors the existing darwin handling: Nix returns no instruction rather than a wrong one, matching the darwin nix returns empty case already in the tests. Linuxbrew returns the brew command.

Fixes the Linux side of #226. The macOS path in that report already returns no instruction for Nix installs, via the existing darwin nix returns empty handling.

Type ✨

  • Bug fix
  • New feature
  • Improvement
  • Breaking change
  • Documentation

Tests 🛠️

Added two cases to TestGetUpdateInstructions, and two steps to the integration-linux job following the existing /tmp/homebrew and npm patterns.

Worth noting for review: the linux nix returns empty unit case only asserts anything on a machine that actually has a package manager installed. On a dev Mac it passes with or without this change, because getLinuxPackageManager() returns empty there anyway. On the ubuntu runner, where apt-get is present, it fails without the fix. That is why the integration step matters here, and I left a comment above it explaining the same thing.

go test ./packages/util/ -run TestGetUpdateInstructions -v
--- PASS: TestGetUpdateInstructions/linux_nix_returns_empty (0.00s)
--- PASS: TestGetUpdateInstructions/linux_linuxbrew (0.00s)
PASS
ok      github.com/Infisical/infisical-merge/packages/util   0.523s

Verified the new tests are meaningful by stashing the change in check-for-update.go and re-running: linux_linuxbrew fails as expected.


The linux branch of getUpdateInstructions never inspected execPath outside
the npm check, falling through to getLinuxPackageManager(), which only
probes which package managers exist on the machine. A nix install on
Debian or Ubuntu was told to run 'apt-get install infisical' for a binary
in the immutable nix store.

Homebrew-on-Linux hit the same gap, since /home/linuxbrew/.linuxbrew/ does
not match the /homebrew/ substring the darwin branch checks.

Mirrors the existing darwin behaviour: nix returns no instruction rather
than a wrong one. Adds unit cases and integration steps to the
integration-linux job.

Partially addresses Infisical/infisical#226
Review feedback: a bare "linuxbrew" substring also classified unrelated
paths such as /opt/linuxbrew-tools as Homebrew installs.

Uses "linuxbrew/" rather than a fully bounded "/linuxbrew/" so both real
layouts still match: the multi-user default (/home/linuxbrew/.linuxbrew)
and the single-user prefix (~/.linuxbrew), where the component is preceded
by a dot rather than a slash.

Adds a single-user case and a negative case for /opt/linuxbrew-tools, plus
a notExpected field on the test table to express the negative assertion.
@greptile-apps

greptile-apps Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5 Tier: plus

[Low risk] Adds detection for nix and linuxbrew package managers.

The PR appears safe to merge; no outstanding finding or new actionable defect was identified.

Summary

This PR adds Linux executable-path detection for Nix and Linuxbrew update instructions.

  • Nix-store binaries receive no update command; Linuxbrew binaries receive the brew command.
  • Unit and Linux integration tests cover both paths and the narrower Linuxbrew match.

Reviews (2) · Last reviewed commit: "fix(update-check): match the .linuxbrew ..."

Comment thread packages/util/check-for-update.go Outdated
The trailing-slash match still classified an unrelated directory such as
/home/user/linuxbrew/bin as a Homebrew install and printed a brew upgrade
command that cannot update that binary.

Both documented Homebrew-on-Linux layouts put the prefix at .linuxbrew, so
match that instead. Adds a regression test for the plain linuxbrew path.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant