User Story
As someone whose shell exports XDG_CONFIG_HOME,
I want install.sh to use the same config directory as the openshell CLI,
so that installing and reinstalling OpenShell just work.
Problem Statement
The CLI keeps each gateway's entry and client certificates under $XDG_CONFIG_HOME/openshell when that variable is set. The installer always uses ~/.config/openshell instead, in two places:
- The readiness check, which connects to the gateway with the client certificates it expects to find there.
- The cleanup that removes an old
openshell entry before adding it again.
With the variable set, the installer and the CLI look in different directories.
Impact / Why This Matters
With XDG_CONFIG_HOME pointing somewhere other than ~/.config:
- On macOS, the install fails whenever
~/.config/openshell has no client certificates for the gateway, or has old ones. The installer waits 30s and exits 1.
- On macOS and Linux, running the installer a second time exits 1 with "Gateway 'openshell' already exists". When the gateway is already registered, the installer removes the entry and adds it again. But it removes it from
~/.config/openshell, and the CLI's entry is under $XDG_CONFIG_HOME/openshell. That entry is still there, so adding it again fails.
The gateway itself keeps running in both cases. On Linux the first run works only because the gateway service also writes a copy of its client certificates to ~/.config/openshell when it starts, so the readiness check happens to find current ones there.
The workarounds don't really work. Unsetting XDG_CONFIG_HOME just for the install puts the gateway entry under ~/.config, so the CLI in your normal shell can't find it afterwards. Running openshell gateway remove openshell before a reinstall avoids the "already exists" error, but not the certificate check on macOS. And nothing in the installer's output mentions the variable.
Acceptance Criteria
With XDG_CONFIG_HOME set and XDG_STATE_HOME unset:
In general:
With both XDG_CONFIG_HOME and XDG_STATE_HOME set, the Linux install fails for a different reason, that maybe is not as important, and not described in this issue.
Reproduction Steps
export XDG_CONFIG_HOME="$(mktemp -d)", and make sure ~/.config/openshell/gateways/openshell doesn't exist.
- Run
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh.
- On macOS it waits 30s, prints
mTLS client bundle is not ready under ~/.config/..., and exits 1. On Linux it succeeds.
- Run it again. Both platforms stop with
Gateway 'openshell' already exists.
Environment
- OpenShell 0.1.2, installer from
main at 9cb72baa2. The installer code involved is the same on current main.
- macOS 26.2 arm64, Homebrew 7.0.7, run as the logged-in user
- Ubuntu 26.04 x86_64, deb package, run as root, Docker 29.1.3
Logs
# macOS, no certificates under ~/.config
mTLS client bundle is not ready under ~/.config/openshell/gateways/openshell/mtls
openshell: error: local gateway listener did not become reachable at https://localhost:17670/ within 30s
# macOS, old certificates under ~/.config
curl: (60) SSL certificate problem: unable to get local issuer certificate
# macOS and Linux, second run
openshell: local gateway already exists; removing and re-adding it...
Error: × Gateway 'openshell' already exists.
User Story
As someone whose shell exports
XDG_CONFIG_HOME,I want
install.shto use the same config directory as theopenshellCLI,so that installing and reinstalling OpenShell just work.
Problem Statement
The CLI keeps each gateway's entry and client certificates under
$XDG_CONFIG_HOME/openshellwhen that variable is set. The installer always uses~/.config/openshellinstead, in two places:openshellentry before adding it again.With the variable set, the installer and the CLI look in different directories.
Impact / Why This Matters
With
XDG_CONFIG_HOMEpointing somewhere other than~/.config:~/.config/openshellhas no client certificates for the gateway, or has old ones. The installer waits 30s and exits 1.~/.config/openshell, and the CLI's entry is under$XDG_CONFIG_HOME/openshell. That entry is still there, so adding it again fails.The gateway itself keeps running in both cases. On Linux the first run works only because the gateway service also writes a copy of its client certificates to
~/.config/openshellwhen it starts, so the readiness check happens to find current ones there.The workarounds don't really work. Unsetting
XDG_CONFIG_HOMEjust for the install puts the gateway entry under~/.config, so the CLI in your normal shell can't find it afterwards. Runningopenshell gateway remove openshellbefore a reinstall avoids the "already exists" error, but not the certificate check on macOS. And nothing in the installer's output mentions the variable.Acceptance Criteria
With
XDG_CONFIG_HOMEset andXDG_STATE_HOMEunset:~/.config/openshellhas no client certificates for the gateway, and when it has old ones.openshell statusin the same shell shows the gateway.In general:
XDG_CONFIG_HOMEunset or empty, the installer keeps using~/.config/openshell.mise run test:install-shcovers unset, empty, set, and set-with-spaces values.With both
XDG_CONFIG_HOMEandXDG_STATE_HOMEset, the Linux install fails for a different reason, that maybe is not as important, and not described in this issue.Reproduction Steps
export XDG_CONFIG_HOME="$(mktemp -d)", and make sure~/.config/openshell/gateways/openshelldoesn't exist.curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh.mTLS client bundle is not ready under ~/.config/..., and exits 1. On Linux it succeeds.Gateway 'openshell' already exists.Environment
mainat9cb72baa2. The installer code involved is the same on currentmain.Logs