#!/bin/sh # Big MacD installer — https://join.bigmacd.com/install # # Carries no token and never sees an invite code (spec §4 step 3). It checks this Mac, downloads # the menu-bar app and its detached signature, verifies the signature against the release key # pinned below, installs the app into ~/Applications and opens it. Re-running it updates the app. # Test overrides: BIGMACD_BASE_URL, BIGMACD_INSTALL_DIR, BIGMACD_NO_OPEN, BIGMACD_NO_QUIT (never # quit a running app), BIGMACD_MACOS_VERSION. # Read it before you run it: curl -fsSL https://join.bigmacd.com/install | less set -eu BASE_URL="${BIGMACD_BASE_URL:-https://join.bigmacd.com}" INSTALL_DIR="${BIGMACD_INSTALL_DIR:-$HOME/Applications}" APP=BigMacD.app MIN_MACOS_MAJOR=14 # the app uses macOS 14 window APIs (Plan 7b) # Release signing key (ECDSA P-256, AWS KMS in bigmacd-release). Key ID: alias/bigmacd-release-prod RELEASE_KEY='-----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEdK0jh2zYA3uZ/Jtp+5EZdRjmpWu7 sX64WLOANgEqHGwk52jmKTADq8nD7slqjXETbo3VX8UwkiDqCnq5xcnmpg== -----END PUBLIC KEY-----' die() { printf 'Big MacD installer: %s\n' "$1" >&2; exit 1; } main() { [ "$(uname -s)" = Darwin ] || die "this installer is for macOS only." [ "$(sysctl -n hw.optional.arm64 2>/dev/null || echo 0)" = 1 ] || die "Big MacD needs a Mac with Apple silicon (M1 or later)." ver="${BIGMACD_MACOS_VERSION:-$(sw_vers -productVersion)}" # override for tests only major=$(printf '%s' "$ver" | cut -d. -f1) [ "$major" -ge "$MIN_MACOS_MAJOR" ] 2>/dev/null || die "Big MacD needs macOS $MIN_MACOS_MAJOR or later (this Mac has $ver)." tmp=$(mktemp -d "${TMPDIR:-/tmp}/bigmacd-install.XXXXXX") trap 'rm -rf "$tmp"' EXIT trap 'exit 130' INT TERM # an interrupt stops the install; the EXIT trap cleans up printf 'Downloading Big MacD...\n' curl -fsSL -o "$tmp/app.zip" "$BASE_URL/app/latest.zip" || die "download failed. Check your connection and run the command again." curl -fsSL -o "$tmp/app.zip.sig" "$BASE_URL/app/latest.zip.sig" || die "download failed. Check your connection and run the command again." printf '%s\n' "$RELEASE_KEY" > "$tmp/release.pem" /usr/bin/openssl dgst -sha256 -verify "$tmp/release.pem" -signature "$tmp/app.zip.sig" "$tmp/app.zip" >/dev/null 2>&1 \ || die "signature check failed: the download is not a Big MacD release. Nothing was installed. If a release was just published, run the command again." /usr/bin/ditto -x -k "$tmp/app.zip" "$tmp/x" || die "the download is damaged. Nothing was installed." [ -d "$tmp/x/$APP" ] || die "the download does not contain $APP. Nothing was installed." xattr -dr com.apple.quarantine "$tmp/x/$APP" 2>/dev/null || true mkdir -p "$INSTALL_DIR" if [ -z "${BIGMACD_NO_QUIT:-}" ] && pgrep -xq BigMacD 2>/dev/null; then osascript -e 'quit app "BigMacD"' >/dev/null 2>&1 || true sleep 2 fi rm -rf "$INSTALL_DIR/$APP.old" [ -d "$INSTALL_DIR/$APP" ] && mv "$INSTALL_DIR/$APP" "$INSTALL_DIR/$APP.old" mv "$tmp/x/$APP" "$INSTALL_DIR/$APP" rm -rf "$INSTALL_DIR/$APP.old" printf 'Installed %s/%s\n' "$INSTALL_DIR" "$APP" if [ -z "${BIGMACD_NO_OPEN:-}" ]; then open "$INSTALL_DIR/$APP" fi } # The whole script is one function call, so a download cut short runs nothing. main "$@"