AliandLucas Nogueira 2a9c29e004 fix(updater): restore the current app when a macOS install fails (fix #3505, #3506) (#3578)
* fix(updater): restore the current app when a macOS install fails

On macOS `install_inner` moved the installed app into a `TempDir` backup and
then renamed the new bundle into place. Neither of the two steps after that
move restored the app on failure, and the `TempDir` deleted the backup on
every exit path, so a failed final rename left the user with no app at the
install path and no way back. The privileged fallback had the same shape:
`rm -rf` the app, then `mv` the new one in.

Both moves are now `replace_bundle`, which renames the current app to the
backup, renames the staged bundle into place, and renames the backup back if
that second step fails. The privileged script moves the current app aside,
moves the new one in, and restores on failure; it deletes the previous bundle
only after the new one is in place. The temp and install locations are
compared with `st_dev` before anything moves, returning the existing
`TempDirNotOnSameMountPoint` rather than failing after the app has already
been moved, and the staged bundle root is set to 0755 because `tempfile`
creates it 0700 and that mode followed it into `/Applications`.

Two unit tests cover `replace_bundle`: the staged bundle ends up in place with
the previous one in the backup, and a failed second rename leaves the current
bundle where it was and returns that error.

Closes #3505, closes #3506.

* fix(updater): exchange the current and new bundles atomically on APFS

Even with the restore in place there was a moment between the two renames
where the install path held nothing, and a process killed in that moment
left the previous app in the temp dir rather than where it belonged.

`swap_bundle` calls `renamex_np` with `RENAME_SWAP`, which exchanges the two
directories in one step so the install path always holds one of the two. The
previous app ends up in the extraction temp dir and is removed with it. Where
the file system does not support the swap (`ENOTSUP`, or `EINVAL` on older
systems) the two-rename path with the restore is used as before, and a
`PermissionDenied` from either still goes to the privileged fallback.

`libc` is added for the macOS target only; it was already in the lockfile
through tauri. One macOS test checks the exchange and skips on a file system
that reports `ENOTSUP`.

* fix(updater): keep the previous app when it cannot be restored

If the restore rename also failed, the previous app was left only in the backup TempDir and deleted with it. Keep the backup in that case and return Error::PreviousAppNotRestored with its path.

* fix(updater): quote the paths in the privileged macOS install script

The paths went into single-quoted sh words inside an AppleScript string unescaped, so a quote in the app path broke the command (run as root) or panicked on the compile expect. Quote them for sh and AppleScript, and report script failures instead of panicking.

* fix(updater): fall back to moving the bundles on any swap error

Only ENOTSUP and EINVAL got the two-rename fallback, so volumes reporting EOPNOTSUPP or ENOSYS for RENAME_SWAP failed every update. Fall back on anything but a permission error, and have the swap test skip only off APFS.

* fix(updater): stage the macOS update on the app's volume

When the system temp dir was on another volume than the app, every update was refused. Create the temp dirs next to the app in that case, and compare the install path itself rather than what a symlink there points to.

* test(updater): update a macOS app on another volume than the temp dir

Runs the app from APFS and HFS+ disk images, covering the atomic swap and the two-rename fallback with the update staged next to the app.

* fix(updater): swap the bundles atomically in the privileged macOS install

The admin path ran two mv calls, leaving the install path empty between them. Run renamex_np with RENAME_SWAP as root through osascript's JavaScript bridge, and only fall back to the moves where the swap fails.

* add test

* cleanup

---------

Co-authored-by: Lucas Nogueira <lucas@tauri.app>
2026-10-05 09:28:11 -03:00
2026-09-01 17:38:21 +08:00
2026-09-30 19:19:08 -03:00
2026-09-30 17:56:45 -03:00
2022-12-14 18:54:05 +01:00
2022-12-14 18:54:05 +01:00
2022-12-14 18:54:05 +01:00
2026-09-26 14:46:48 -03:00

Official Tauri Plugins

This repo and all plugins require a Rust version of at least 1.90

Plugins Found Here

Win Mac Lin iOS And
autostart Automatically launch your app at system startup. ✅ ✅ ✅ ❌ ❌
barcode-scanner Allows your mobile application to use the camera to scan QR codes, EAN-13 and other kinds of barcodes. ? ? ? ✅ ✅
biometric Prompt the user for biometric authentication on Android and iOS. ? ? ? ✅ ✅
cli Parse arguments from your Command Line Interface ✅ ✅ ✅ ❌ ❌
clipboard-manager Read and write to the system clipboard. ✅ ✅ ✅ ✅ ✅
deep-link Set your Tauri application as the default handler for an URL. ✅ ✅ ✅ ✅ ✅
dialog Native system dialogs for opening and saving files along with message dialogs. ✅ ✅ ✅ ✅ ✅
fs Access the file system. ✅ ✅ ✅ ? ?
geolocation Get and track current device position. ? ? ? ✅ ✅
global-shortcut Register global shortcuts. ✅ ✅ ✅ ? ?
haptics Haptic feedback and vibrations. ? ? ? ✅ ✅
http Access the HTTP client written in Rust. ✅ ✅ ✅ ✅ ✅
localhost Use a localhost server in production apps. ✅ ✅ ✅ ? ?
log Configurable logging. ✅ ✅ ✅ ✅ ✅
nfc Read and write NFC tags on Android and iOS. ? ? ? ✅ ✅
notification Send message notifications (brief auto-expiring OS window element) to your user. Can also be used with the Notification Web API. ✅ ✅ ✅ ✅ ✅
opener Open files and URLs using their default application. ✅ ✅ ✅ ✅ ✅
os Read information about the operating system. ✅ ✅ ✅ ✅ ✅
persisted-scope Persist runtime scope changes on the filesystem. ✅ ✅ ✅ ? ?
positioner Move windows to common locations. ✅ ✅ ✅ ❌ ❌
process This plugin provides APIs to access the current process. To spawn child processes, see the shell plugin. ✅ ✅ ✅ ? ?
shell Access the system shell. Allows you to spawn child processes and manage files and URLs using their default application. ✅ ✅ ✅ ? ?
single-instance Ensure a single instance of your tauri app is running. ✅ ✅ ✅ ❌ ❌
sql Interface with SQL databases. ✅ ✅ ✅ ✅ ✅
store Persistent key value storage. ✅ ✅ ✅ ✅ ✅
stronghold Encrypted, secure database. ✅ ✅ ✅ ? ?
updater In-app updates for Tauri applications. ✅ ✅ ✅ ❌ ❌
upload Tauri plugin for file uploads through HTTP. ✅ ✅ ✅ ✅ ✅
websocket Open a WebSocket connection using a Rust client in JS. ✅ ✅ ✅ ? ?
window-state Persist window sizes and positions. ✅ ✅ ✅ ❌ ❌
  • ✅: (Partially) Supported
  • ❌: Not supported
  • ? : Unknown/Untested or Planned

Contributing

PRs accepted. Please make sure to read the Contributing Guide before making a pull request.

Partners

CrabNebula

For the complete list of sponsors please visit our website and Open Collective.

Languages
Rust 57.2%
TypeScript 25.2%
Kotlin 9.4%
Swift 5.8%
JavaScript 1.5%
Other 0.8%