From 027ad6f672028fac77bbe43fbf80cce0aee9b238 Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Thu, 8 Oct 2026 15:00:39 -0400 Subject: [PATCH] DRY pass #2, batch 7, F21: update.rs reads installer markers one way (#5372) update.rs read_marker(): read the installer's marker file, parse it, and log one that doesn't parse. adopt_installer_channel and adopt_installer_server each wrote that out; they already shared adopt(). normalize_server's doc now says why it stays apart from compat::normalize_base_url: one tidies what a person types, the other refuses anything odd in what a script wrote. The tauri.conf updater endpoint stays: read_source already documents that it is never consulted, and removing it is a config change CI would be the first to try. rustfmt --check is clean in the CI image. Co-Authored-By: Claude Opus 5.5 --- desktop/src-tauri/src/update.rs | 46 ++++++++++++++++++++------------- 1 file changed, 28 insertions(+), 18 deletions(-) diff --git a/desktop/src-tauri/src/update.rs b/desktop/src-tauri/src/update.rs index efaf71b..9a558ad 100644 --- a/desktop/src-tauri/src/update.rs +++ b/desktop/src-tauri/src/update.rs @@ -171,6 +171,11 @@ impl Source { /// reason: this value is spliced into every update URL, and an address carrying a /// query, a fragment or whitespace is a paste gone wrong rather than a place to /// fetch from. +/// +/// Deliberately stricter than `sync::compat::normalize_base_url`, which tidies what a +/// person types into Sync (it supplies a missing `https://`, and lets a path or +/// query through for the probe to judge). This one checks a value a script wrote, +/// where anything unusual is a fault to refuse rather than a typo to forgive. fn normalize_server(raw: &str) -> Option { let trimmed = raw.trim().trim_end_matches('/'); let rest = trimmed @@ -267,15 +272,8 @@ fn self_update_blocker() -> Option { /// Windows installer that has no channel concept — and none of that should keep the /// app from opening. pub fn adopt_installer_channel(db: &Db, data_dir: &Path) { - let path = data_dir.join(INSTALL_MARKER); - let Ok(raw) = std::fs::read_to_string(&path) else { - return; - }; - let Some(channel) = Channel::from_marker(&raw) else { - log::warn!( - "ignoring an unreadable install channel marker at {}", - path.display() - ); + let Some(channel) = read_marker(data_dir, INSTALL_MARKER, "channel", Channel::from_marker) + else { return; }; match adopt(db, CHANNEL_PREF, CHANNEL_SEED_PREF, channel.as_str()) { @@ -292,15 +290,7 @@ pub fn adopt_installer_channel(db: &Db, data_dir: &Path) { /// and for the same reasons: once per new marker value, so a choice made in the app /// afterwards sticks, and reinstalling from a different server is honoured. pub fn adopt_installer_server(db: &Db, data_dir: &Path) { - let path = data_dir.join(SERVER_MARKER); - let Ok(raw) = std::fs::read_to_string(&path) else { - return; - }; - let Some(server) = normalize_server(&raw) else { - log::warn!( - "ignoring an unreadable install server marker at {}", - path.display() - ); + let Some(server) = read_marker(data_dir, SERVER_MARKER, "server", normalize_server) else { return; }; match adopt(db, SERVER_PREF, SERVER_SEED_PREF, &server) { @@ -310,6 +300,26 @@ pub fn adopt_installer_server(db: &Db, data_dir: &Path) { } } +/// The installer's marker `name` in `data_dir`, parsed. `None` when there is none, +/// which is ordinary, or when it doesn't parse, which is logged and stepped over. +fn read_marker( + data_dir: &Path, + name: &str, + what: &str, + parse: impl Fn(&str) -> Option, +) -> Option { + let path = data_dir.join(name); + let raw = std::fs::read_to_string(&path).ok()?; + let parsed = parse(&raw); + if parsed.is_none() { + log::warn!( + "ignoring an unreadable install {what} marker at {}", + path.display() + ); + } + parsed +} + /// Write `value` to `pref` unless this same marker value was already applied. /// Returns whether anything changed. fn adopt(db: &Db, pref: &str, seed_pref: &str, value: &str) -> Result {