From c317b139d671d4c510fb30d4752dd71d732e34ea Mon Sep 17 00:00:00 2001 From: Kelly Michels Date: Tue, 15 Sep 2026 19:44:30 -0500 Subject: [PATCH] docs(readme): give the download-and-verify path a PowerShell form (#85) "Downloading without cloning" was bash only, in the README of a PowerShell toolkit. It is also the first thing a stranger does, so the one section aimed squarely at newcomers was the one they could not run: `sha256sum` and `unzip` are not Windows commands at all, and `&&` is a parse error in PowerShell 5.1 rather than a wrong result. PowerShell goes first here, because these commands are PowerShell - Get-FileHash against the .sha256, Expand-Archive, then zchecksums.cmd for the contents. The bash form stays below it, matching how "Verifying what you downloaded" already leads with zchecksums and offers sha256sum second. Tested against releases/zscripts-v1.0.0.0.9.zip: the comparison returns True. It also gets a note, because the output invites a wrong conclusion - Get-FileHash prints upper case and the .sha256 file holds lower, so the two strings look different side by side. PowerShell's -eq is case-insensitive on strings, so the check is right and the eyes are wrong. Twins regenerated; the Pester twin-sync test passes. Co-authored-by: Claude Opus 5 --- README.md | 18 ++++++++++++++++++ README.txt | 16 ++++++++++++++++ 2 files changed, 34 insertions(+) diff --git a/README.md b/README.md index 53fdeac..3263379 100644 --- a/README.md +++ b/README.md @@ -411,6 +411,24 @@ Verification walks its channels in trust order — docker-network `viaProxy`, th Each release is packaged as a zip in [`releases/`](releases/) — grab the latest `zscripts-v*.zip`, check it, unzip, done: +**Windows · PowerShell** — these commands are a PowerShell toolkit, so this is +most people's path. `sha256sum` and `unzip` are not Windows commands: + +```powershell +$zip = "zscripts-v1.0.0.0.0.zip" +(Get-FileHash $zip -Algorithm SHA256).Hash -eq (Get-Content "$zip.sha256").Split()[0] # True = good +Expand-Archive $zip -DestinationPath zscripts +cd zscripts +.\zchecksums.cmd # verify the contents +``` + +`Get-FileHash` prints the hash in **upper** case and the `.sha256` file holds it +in lower — they look different side by side and are not. `-eq` on strings is +case-insensitive in PowerShell, so the comparison above is right; trust the +`True`, not your eyes. + +**macOS · Linux · Git Bash · WSL** + ```bash sha256sum -c zscripts-v1.0.0.0.0.zip.sha256 # verify the download unzip zscripts-v1.0.0.0.0.zip -d zscripts # extract diff --git a/README.txt b/README.txt index 9f85b98..ecfa367 100644 --- a/README.txt +++ b/README.txt @@ -384,6 +384,22 @@ Downloading without cloning Each release is packaged as a zip in releases/ (releases/) — grab the latest zscripts-v*.zip, check it, unzip, done: +Windows · PowerShell — these commands are a PowerShell toolkit, so this is +most people's path. sha256sum and unzip are not Windows commands: + + $zip = "zscripts-v1.0.0.0.0.zip" + (Get-FileHash $zip -Algorithm SHA256).Hash -eq (Get-Content "$zip.sha256").Split()[0] # True = good + Expand-Archive $zip -DestinationPath zscripts + cd zscripts + .\zchecksums.cmd # verify the contents + +Get-FileHash prints the hash in upper case and the .sha256 file holds it +in lower — they look different side by side and are not. -eq on strings is +case-insensitive in PowerShell, so the comparison above is right; trust the +True, not your eyes. + +macOS · Linux · Git Bash · WSL + sha256sum -c zscripts-v1.0.0.0.0.zip.sha256 # verify the download unzip zscripts-v1.0.0.0.0.zip -d zscripts # extract cd zscripts && sha256sum -c CHECKSUMS.txt # verify the contents