Skip to content

Couch installer v0.1.0

Pre-release
Pre-release

Choose a tag to compare

@dangerouslaser dangerouslaser released this 17 Sep 19:17
7f76f50

Couch installer v0.1.0 (draft)

Tag: installer-v0.1.0 · Repository: Couch-OS/couch-installer · Prerelease

The first installer release published from the installer's own repository. The
installer now versions and ships independently of the Couch OS: installer-v…
tags belong to the installer, v… tags remain Couch OS runtime releases. An
installer-only fix can keep the same OS payload, and an OS release no longer
requires a new installer build.

Nothing about the on-device write path or the wire protocol changes here. This
release carries the same installation transaction as the installer published
with Couch v0.1.0-alpha.20260916.170, built from the installer repository's
own source.

Install

Linux x64 and macOS, from an interactive terminal:

curl --fail --location --proto '=https' --tlsv1.2 \
  https://github.com/Couch-OS/couch-installer/releases/download/installer-v0.1.0/install.sh | sh

Windows x64, from PowerShell:

Invoke-RestMethod 'https://github.com/Couch-OS/couch-installer/releases/download/installer-v0.1.0/install.ps1' | Invoke-Expression

The launcher downloads only the host, terminal and installer.json from this
release, checks each one's byte size and SHA-256 against the values written into
the script, and starts nothing on a mismatch. There is no latest URL and no
fallback to an unverified executable.

What it installs

installer.json is a schema-2 descriptor. It names the installer and the OS
separately:

Installer version v0.1.0
Installer source commit 7f76f500d020ea2142adb4cf469ad2d15c86f9f3
OS version v0.1.0-alpha.20260916.170
OS source commit de2c0ecda41102816c9121c421dfdede5b704dbc
Installation protocol 1
Device model sanytron-ha100

The OS payload is pinned at its immutable URL in Couch-OS/couch, by byte size
and SHA-256:

https://github.com/Couch-OS/couch/releases/download/v0.1.0-alpha.20260916.170/couch-v0.1.0-alpha.20260916.170-ha100-public-inputs.tar.gz
69729275 bytes
fa5b88eaaf347dbcab8d2dc69906eb8d4d05e72ed9274f10aaaead4787c88f0a

This is the same archive the previous installer used. It is served
byte-for-byte identically by the retained dangerouslaser/couch archive, and
the host accepts either owner, so existing published descriptors keep working.

Assets

Asset What it is
install.sh, install.ps1 Generated launchers with every asset pin inlined
installer.json Schema-2 release descriptor
couch-installer-host-…, couch-installer-tui-… Native host and terminal UI for Linux x64, universal macOS and Windows x64
build-receipts.tar.gz Per-platform build receipts: exact commit, target, rustc -vV, cargo -vV, toolchain and sysroot hashes, binary hashes
couch-installer-source.tar.gz Installer corresponding source
release-provenance.json, SHA256SUMS Provenance record and digests for every asset

Binaries were built by the repository's Build installer binaries workflow,
run 35260505555,
from commit 7f76f500d020ea2142adb4cf469ad2d15c86f9f3 with
rustc 1.98.1 (48a229cea 2026-09-01). The macOS binaries are lipo-combined
x86_64 + arm64 and ad-hoc signed. No binary was built on a developer machine.

Corresponding source

couch-installer-source.tar.gz covers this exact commit, all four locked Cargo
workspaces with their vendored dependency sources, dependency notices, and one
audited Rust standard-library source component. Its scope is installer:
os_source_covered is false. The selected OS release keeps its own
corresponding-source archive, which an installer-scoped archive cannot replace.

Verified

  • couch-installer-host verify-public against this descriptor and the pinned
    payload accepted the archive and extracted all six public OS inputs with no
    device access, both with this release's macOS host and with a host freshly
    built from the release commit. The archive's manifest matches the OS identity
    and every file pin.
  • The host accepts installation protocol 1 and refuses 0 and 2.
  • Frozen Windows launcher acceptance ran the unmodified generated install.ps1
    and these real binaries in a Windows ConPTY, requested exactly the three
    release assets, selected Cancel, exited 0, and created no installer session.

Not established by this release

  • Physical installation, restore or recovery acceptance on an HA100.
  • Release signatures.
  • That every downloadable native binary used the audited Rust source component;
    the build receipts record each platform's compiler identity for that
    comparison.