Repository navigation
4.2.0c
API layer
- Introduce
Update.fetch_raw_api(...)that performs a single-shot v3 request
and, on failure, falls back to v2. We suppress chatter on a v3 success; on
fallback we emit one concise notice to aid support triage. The first working
endpoint becomes the new default for subsequent calls. :contentReference[oaicite:0]{index=0} :contentReference[oaicite:1]{index=1} - Replace ad-hoc JSON fetches with
decode_json_metadata(...), which reads
once and caches by URL to reduce network churn. :contentReference[oaicite:2]{index=2}
Integrity & security
- Paper artifact downloads now always print a positive, single-line checksum
confirmation on success and explicitly state when integrity checks are
skipped (either forced or unavailable from the API). :contentReference[oaicite:3]{index=3} - Script self-upgrade gains a separate SHA-256 verification path that derives
the sidecar URL fromGITHUB_RAW(.../.server_update.py.sha), prints the
remote hash suffix before download, and validates post-download prior to
install. This is isolated from the Paper jar flow. :contentReference[oaicite:4]{index=4} :contentReference[oaicite:5]{index=5}
Networking & timeouts
- Classify network failures with precise exits: timeout, HTTP, URL, connection,
and unreachable. v2 is attempted on v3 timeouts/HTTP/URL/connection errors
before fatal; both failing yields a single consolidated fatal. :contentReference[oaicite:6]{index=6} :contentReference[oaicite:7]{index=7} - Tight, explicit timeouts on GitHub release fetch and sidecar download to keep
CLI snappy and predictable during outages. :contentReference[oaicite:8]{index=8} :contentReference[oaicite:9]{index=9}
UX / operator feedback
- Standardize the upgrade transcript: “Starting Download”, progress bar, “Integrity
test passed …”, and final completion banners; batch mode prints compact lines. :contentReference[oaicite:10]{index=10} - Add explicit “Integrity check skipped” lines when disabled or when the API
lacks a checksum, so logs are unambiguous. :contentReference[oaicite:11]{index=11}
CLI & flags
--server-versionreports local version/build and the remote build + full
SHA256 from the API, aligning with the integrity display style elsewhere. (Code paths flow through the same metadata decode/cache as other commands.) :contentReference[oaicite:12]{index=12}- Force/skip semantics emit clear one-liners (e.g. forced upgrade, skipped
integrity/version check) to make intentional behavior obvious in logs. :contentReference[oaicite:13]{index=13}
Refactors & readability
- Rename legacy “get vs _get” split into descriptive roles:
- “wire” →
fetch_raw_api(returns a live HTTP stream with v3→v2 fallback) - “decode” →
decode_json_metadata(parses + caches JSON)
This reduces ambiguity between “fetching bytes” and “parsing structures.” :contentReference[oaicite:14]{index=14} :contentReference[oaicite:15]{index=15}
- “wire” →
Safety & recovery
- Guard installs behind verified checksums; integrity mismatch prints an
Expected/Actual diff and terminates with an actionable fatal. :contentReference[oaicite:16]{index=16} - Self-upgrade refuses to operate on frozen binaries and exits cleanly. :contentReference[oaicite:17]{index=17}
Docs & comments
- Strengthened docstrings and inline explanations around version/build selection,
API fallbacks, and integrity rationale to help future maintainers. :contentReference[oaicite:18]{index=18} - The networking stack is now predictable: v3 once, v2 once, then fail—no loops,
no silent hangs, and clear reasons on exit.