curl-fs.sl Field notes on four letters

Four flags. What they promise, and what they leave to trust.

Tap the command to read it as a domain.
The flags

Four switches

f --fail

If the server answers 400 or above, print nothing to stdout and exit with code 22.

Without itA 404 page arrives as HTML on stdout, exit code 0, and sh tries to run <!DOCTYPE html>.

s --silent

Hide the progress meter and error messages. Nothing on stderr unless you ask for it.

Without itA transfer table scrolls past on stderr in the middle of your install log.

S --show-error

Used with -s: stay quiet about progress, but still say why it failed.

Without it-s swallows errors too. A dead host fails with no message at all.

L --location

Follow 3xx redirects to wherever the script actually lives now.

Without itYou download a tiny “Moved Permanently” page instead of the installer.

The bench

What reaches sh

Stderr is dim. Stdout is what the shell runs.

Flags
Server says

        
curl exit0 sh runs
The ritual

Fail loudly, then look

The flags catch a bad download. They do not read the script.

The one-liner

You run whatever the server sends.

curl -fsSL https://example.com/install.sh | sh

The two-step

Save it, read it, then run it.

curl -fsSLo install.sh https://example.com/install.sh
less install.sh
sh install.sh
In the wild

In the wild

Each link is curl-fs.sl/<url>|sh. Scores stick for a day.

Loading installers…

New Should I pipe this to sh? Paste a script. Get a verdict.