Three root causes were causing failures on non-x86_64-Linux platforms:
1. Single SHA256 per package: the pinned fallback checksum in
formatted_packages.py was a single value computed for linux-x86_64 only.
Downloads on linux-aarch64, macos-x86_64, and macos-aarch64 produced
different binaries with different digests, so verification always failed
on those platforms when the fetch_latest resolver was unavailable.
Fix: replace the single `sha256` field with a `sha256_map` dict keyed by
"{os}-{arch}" (e.g. "linux-aarch64", "macos-arm64"). Added the correct
pinned digests for all four supported platforms for both Go 1.26.3 and
Firecracker 1.15.1, fetched from official sources.
2. Case-sensitive SHA256 comparison: _sha256_of() always returns lowercase
hex, but checksums returned by external APIs could be uppercase.
_verify() compared them without normalising case, causing false mismatches.
Fix: new resolved_sha256 property always returns a lowercased digest;
_resolve_latest() also lowercases the dynamically-fetched sha before
storing it.
3. Firecracker not skipped on macOS: _resolve_latest_firecracker() returns
None on macOS (firecracker is Linux-only), causing a fallback to the
pinned linux binary URL with a linux-only checksum map entry. The download
and verification would both fail misleadingly.
Fix: explicit early-continue guard in install_custom_packages() when
name == "firecracker" and IS_MACOS.
Adds curl, ncurses-devel, xz (tool), libxml2-devel, and xmlsec1-devel to
SYSTEM_PACKAGES to cover the full pyenv/CPython build dependency set.
Also adds apt-get overrides for all Fedora-named Python build packages
(bzip2-devel → libbz2-dev, openssl-devel → libssl-dev, etc.) so they
resolve to the correct Debian/Ubuntu package names at install time.
Adds corresponding brew overrides for the new packages.
https://claude.ai/code/session_01P3CkL5oXzkTvayityg3uaH
Detect Darwin automatically and, on macOS, install the Xcode Command
Line Tools and Homebrew as the first actions before any package work.
Route system packages through brew (formulae and casks), skip the
Flatpak section entirely, refuse to run as root (brew won't), and
adjust custom-package URL/install-path templates with new {os}, {os_go},
{os_zig}, {os_nvim} substitutions. Architecture detection remains
dynamic on both Apple Silicon and Intel.
https://claude.ai/code/session_01R2CnCeEBYT5QoHiwxczDNq
- Add zsh to SYSTEM_PACKAGES
- Detect RHEL-family vs Debian-family from /etc/os-release ID/ID_LIKE
(falls back to PKG_MGR if os-release is unreadable)
- ensure_zsh_default sets zsh as the invoking user's login shell after
system install: usermod -s on RHEL-family (chsh under default
authselect refuses other-user changes), chsh -s elsewhere; SUDO_USER
is preferred so sudo invocations target the real user
- Add oh-my-zsh to CUSTOM_PACKAGES; the installer runs the official
unattended script (requires zsh + git, which are already installed by
this point) and rewrites ZSH_THEME to "gnzh" in ~/.zshrc
- As a final step, run 'zsh -c "source ~/.zshrc"' to validate the rc
file (the user's interactive shell is unaffected — they need a new
terminal to pick up the new default shell)
pip is unusual among the custom packages because it ships inside CPython
itself, so it doesn't need a URL or archive. The handler bootstraps it
from the standard-library wheel via 'python3 -m ensurepip --upgrade' and
then self-upgrades to the latest version. Detection uses
'python3 -m pip --version' instead of a filesystem path.
- Move SYSTEM_PACKAGES, FLATPAK_PACKAGES, and CUSTOM_PACKAGES into
formatted_packages.py as typed Python data; drop the bespoke parser
- Custom package URLs are now string templates with {version}, {arch},
and {arch_go} substitutions, so the same entry works on x86_64 and
aarch64 without hand-editing the URL
- Add best-effort latest-version resolvers for Go, Firecracker, and Zig
(using go.dev JSON, GitHub releases, and ziglang index.json
respectively); on any failure the pinned version + sha256 are used
and the fallback is logged
- Make Neovim's archive name and install dir arch-aware (x86_64/arm64)
- Document that --no-gui skips the entire Flatpak section, including
installing flatpak itself