Skip to content

Read config files as UTF-8 and keep durable profile backups - #9

Merged
26zl merged 1 commit into
mainfrom
fix/utf8-reads-and-durable-backups
Oct 11, 2026
Merged

26zl merged 1 commit into
mainfrom
fix/utf8-reads-and-durable-backups

Conversation

@26zl

@26zl 26zl commented Oct 11, 2026

Copy link
Copy Markdown
Owner

Draft: install/uninstall paths are Windows-specific and can't be fully exercised here (no winget/elevation/ssh.exe), so the runtime effect is verified by reasoning + parse/analyzer only.

Fix B1 - UTF-8 reads (setup.ps1)

On Windows PowerShell 5.1 a bare Get-Content -Raw decodes with the system ANSI code page, so non-ASCII (e.g. the Norwegian letters) in settings got corrupted and then written back. Added -Encoding UTF8 to the Get-Content -Raw reads of:

  • user-settings.json (Save-WizardChoices + merge step)
  • Windows Terminal settings.json (the read-back before rewrite)
  • theme.json / terminal-config.json bundle temp files
  • the downloaded Oh My Posh theme (validation read)
  • the wizard state file

Writes already use [IO.File]::WriteAllText(..., UTF8Encoding(false)) (no BOM), so only reads needed fixing. No Set-Content -Encoding UTF8 introduced (that would BOM on PS5.1 and trip CI).

Fix B2 - durable backups

  • setup.ps1: on first install, save a one-time profile.original.ps1. The existing oldprofile*.ps1 rotation (keep 5) never matches that name, so the user's pre-install profile is no longer lost after 5 installs.
  • Uninstall-Profile: if profile.original.ps1 exists, restore it over the profile (and drop the marker) instead of just deleting; otherwise the previous remove behavior is unchanged (so the -WhatIf "Remove profile file" path is preserved).
  • Update-Profile: back up the current profile to a rotated oldprofile.<stamp>.ps1 (keep 5) before overwriting it.
  • sed helper: read via the repo's Get-Utf8FileText (BOM-aware UTF-8) and write a single .bak of the pre-edit content before rewriting.

Fix C - README (install-wizard section)

The "Install Wizard" section recommended -SkipHashCheck as the "Default trusted-download flow". Reworded it to match the already-review-first Quick Install block at the top: run with no hash flag (prints hashes, stops), then re-run with -ExpectedSha256; -SkipHashCheck is labelled the unverified fallback. Added a one-line note that a signed-release / tag-pinning model is a maintainer follow-up (did not redesign the release model).

Verification

  • Parser::ParseFile clean on setup.ps1 and the profile.
  • PSScriptAnalyzer (CI exclude set) on both: 0 findings.
  • No non-ASCII and no Set-Content -Encoding UTF8 in the changed .ps1 files.
  • Unverified here: the actual install/uninstall/update file operations (need Windows + elevation); the sed .bak behavior is reasoned, not run. No workflows touched.

Follow-ups for the owner

  • The existing tests/test.ps1 uninstall sandboxes don't create profile.original.ps1, so they still exercise the plain-remove path; a case covering original-restore would be worth adding.
  • The profile already reads most settings via Get-Utf8FileText; a sweep for any remaining bare Get-Content -Raw | ConvertFrom-Json there could be a small follow-up.

On Windows PowerShell 5.1 a bare Get-Content -Raw decodes with the system
ANSI code page, so non-ASCII (e.g. aao) in settings was corrupted and then
written back. Profile backups also rotated by time keeping five, so the
user's original profile was lost after five installs and Uninstall-Profile
restored nothing.

- setup.ps1: add -Encoding UTF8 to the Get-Content -Raw reads of
  user-settings.json, Windows Terminal settings.json, theme.json,
  terminal-config.json, the OMP theme, and the wizard state file.
- setup.ps1: on first install, save a one-time profile.original.ps1 that
  the oldprofile* rotation never deletes.
- Uninstall-Profile: restore profile.original.ps1 instead of just removing
  the profile.
- Update-Profile: back up the current profile before overwriting (rotated,
  latest five; the immutable original is never matched).
- sed: read UTF-8 (BOM-aware) via Get-Utf8FileText and keep a .bak.
- README: make the review-first hash flow the recommended default in the
  install-wizard section; -SkipHashCheck is the unverified fallback.
@26zl
26zl marked this pull request as ready for review October 11, 2026 14:11
@26zl
26zl merged commit ee8da91 into main Oct 11, 2026
5 of 6 checks passed
@26zl
26zl deleted the fix/utf8-reads-and-durable-backups branch October 11, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant