Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,15 @@ jobs:
echo "/home/linuxbrew/.linuxbrew/bin:/usr/bin:/bin" >> "${GITHUB_PATH}"
fi

- name: Test installation permissions
run: |
if [[ "${RUNNER_OS}" != "macOS" ]]
then
sudo apt-get update
sudo apt-get install --yes ruby ruby-minitest
fi
/usr/bin/ruby tests/test_install.rb

- name: Uninstall GitHub Actions Homebrew
run: |
if which brew &>/dev/null
Expand All @@ -91,6 +100,34 @@ jobs:

- run: /bin/bash uninstall.sh -f >/dev/null

- name: Install as a non-admin user into a provisioned prefix
run: |
if [[ "${RUNNER_OS}" = "macOS" ]]
then
sudo sysadminctl -addUser brewtest -password "$(uuidgen)" -shell /bin/bash
else
sudo useradd --create-home --user-group --shell /bin/bash brewtest
fi
if id -Gn brewtest | grep -Eq '(^| )(admin|sudo|wheel)( |$)'
then
echo "The test account must not be an administrator."
exit 1
fi
sudo install -d -o brewtest -g "$(id -gn brewtest)" -m 0755 /opt/brew
sudo -i -u brewtest /usr/bin/env HOMEBREW_NO_SUDO=1 NONINTERACTIVE=1 \
/bin/bash -s -- --path /opt/brew < install.sh
if [[ "${RUNNER_OS}" = "macOS" && "$(id -gn brewtest)" = staff ]]
then
test -z "$(find /opt/brew ! -type l \( -perm -0020 -o -perm -0002 \))"
fi
sudo -i -u brewtest /usr/bin/env HOMEBREW_NO_SUDO=1 /opt/brew/bin/brew config
sudo -i -u brewtest /usr/bin/env HOMEBREW_NO_SUDO=1 /opt/brew/bin/brew install --force-bottle ack
sudo -i -u brewtest /opt/brew/bin/ack --version
test -z "$(find /opt/brew ! -user brewtest -o ! -group "$(id -gn brewtest)")"
# These generated files survive removal of the Cellar.
sudo -i -u brewtest /bin/rm -f /opt/brew/lib/ld.so /opt/brew/share/info/dir
sudo /usr/bin/env NONINTERACTIVE=1 /bin/bash uninstall.sh --path /opt/brew

- name: Install into custom prefixes non-interactively
run: |
case "$(uname)" in
Expand Down
12 changes: 11 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,9 @@

More installation information and options: <https://docs.brew.sh/Installation>.

If you're on macOS, try out our new `.pkg` installer. Download it from [Homebrew's latest GitHub release](https://github.com/Homebrew/brew/releases/latest).
For MDM deployments on Apple Silicon Macs, we recommend the `.pkg` installer from [Homebrew's latest GitHub release](https://github.com/Homebrew/brew/releases/latest).
Use [`HOMEBREW_PKG_USER`](https://docs.brew.sh/Installation) to select an existing non-root account to own the installation.
Installing without Git or developer tools requires a package release containing [Homebrew/brew#24062](https://github.com/Homebrew/brew/pull/24062).

If you are running Linux or WSL, [there are some pre-requisite packages to install](https://docs.brew.sh/Homebrew-on-Linux#requirements).

Expand Down Expand Up @@ -38,6 +40,14 @@ For example, to install non-interactively into `/opt/brew`:
NONINTERACTIVE=1 /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" -- --path /opt/brew
```

The installing account does not need administrator membership when the prefix is writable.
On macOS, falling back to the `staff` group removes group and other write permissions from the prefix and cache.
Set `HOMEBREW_NO_SUDO=1` to prevent sudo calls; missing sudo, recognised privilege failures and explicit policy denials are also detected automatically.
Filesystem operations try without sudo before requesting elevation when needed.
Installations without sudo skip the system PATH file; follow the printed shell setup instructions instead.
Command Line Tools installation is skipped without sudo and CLT installation failures are non-fatal.
The shell installer aborts if Git is missing or unusable; a working Git on `PATH` or supplied by Xcode is supported.

## Uninstall Homebrew

```bash
Expand Down
Loading
Loading