bug: install.sh ignores XDG_CONFIG_HOME for the local gateway config
Maintainers usually reply within 1 day
@fede-kamel is already working on this.
Since Oct 1, 2026.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 88/100
Research direction
Start in install.sh by inspecting the readiness check and cleanup paths that currently use the local gateway configuration directory. Run mise run test:install-sh, covering unset, empty, set, and set-with-spaces XDG_CONFIG_HOME values. Done means the installer and CLI use the same directory, the listed reinstall scenarios exit 0, and the acceptance checks pass.
Written by the indexing model from the issue text.
Description
User Story
As someone whose shell exports XDG_CONFIG_HOME,
I want install.sh to use the same config directory as the openshell CLI,
so that installing and reinstalling OpenShell just work.
Problem Statement
The CLI keeps each gateway's entry and client certificates under $XDG_CONFIG_HOME/openshell when that variable is set. The installer always uses ~/.config/openshell instead, in two places:
- The readiness check, which connects to the gateway with the client certificates it expects to find there.
- The cleanup that removes an old
openshellentry before adding it again.
With the variable set, the installer and the CLI look in different directories.
Impact / Why This Matters
With XDG_CONFIG_HOME pointing somewhere other than ~/.config:
- On macOS, the install fails whenever
~/.config/openshellhas no client certificates for the gateway, or has old ones. The installer waits 30s and exits 1. - On macOS and Linux, running the installer a second time exits 1 with "Gateway 'openshell' already exists". When the gateway is already registered, the installer removes the entry and adds it again. But it removes it from
~/.config/openshell, and the CLI's entry is under$XDG_CONFIG_HOME/openshell. That entry is still there, so adding it again fails.
The gateway itself keeps running in both cases. On Linux the first run works only because the gateway service also writes a copy of its client certificates to ~/.config/openshell when it starts, so the readiness check happens to find current ones there.
The workarounds don't really work. Unsetting XDG_CONFIG_HOME just for the install puts the gateway entry under ~/.config, so the CLI in your normal shell can't find it afterwards. Running openshell gateway remove openshell before a reinstall avoids the "already exists" error, but not the certificate check on macOS. And nothing in the installer's output mentions the variable.
Acceptance Criteria
With XDG_CONFIG_HOME set and XDG_STATE_HOME unset:
- The installer exits 0 when
~/.config/openshellhas no client certificates for the gateway, and when it has old ones. - After the install,
openshell statusin the same shell shows the gateway. - Running the installer a second time exits 0.
In general:
- With
XDG_CONFIG_HOMEunset or empty, the installer keeps using~/.config/openshell. -
mise run test:install-shcovers unset, empty, set, and set-with-spaces values.
With both XDG_CONFIG_HOME and XDG_STATE_HOME set, the Linux install fails for a different reason, that maybe is not as important, and not described in this issue.
Reproduction Steps
export XDG_CONFIG_HOME="$(mktemp -d)", and make sure~/.config/openshell/gateways/openshelldoesn't exist.- Run
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh. - On macOS it waits 30s, prints
mTLS client bundle is not ready under ~/.config/..., and exits 1. On Linux it succeeds. - Run it again. Both platforms stop with
Gateway 'openshell' already exists.
Environment
- OpenShell 0.1.2, installer from
mainat9cb72baa2. The installer code involved is the same on currentmain. - macOS 26.2 arm64, Homebrew 7.0.7, run as the logged-in user
- Ubuntu 26.04 x86_64, deb package, run as root, Docker 29.1.3
Logs
# macOS, no certificates under ~/.config
mTLS client bundle is not ready under ~/.config/openshell/gateways/openshell/mtls
openshell: error: local gateway listener did not become reachable at https://localhost:17670/ within 30s
# macOS, old certificates under ~/.config
curl: (60) SSL certificate problem: unable to get local issuer certificate
# macOS and Linux, second run
openshell: local gateway already exists; removing and re-adding it...
Error: × Gateway 'openshell' already exists.
- Dominant language
- Rust
- Stars
- 15.4k
- Forks
- 1.7k
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 366
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NVIDIA/OpenShell
-
state:triage-needed
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
docs: document workspace and provider label capabilitiesPossibly taken @johntmyers claimed this 3 days ago. Openarea:docs
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NVIDIA/OpenShell#4250 · 2 comments ·
Maintainers usually reply within 1 day
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentPossibly taken @feloy claimed this 4 days ago. Openstate:triage-needed
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
state:triage-needed
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NVIDIA/OpenShell#3995 · 2 comments ·
Maintainers usually reply within 1 day
-
OCSF shorthand renders Unknown and Other severities as [INFO]Possibly taken @ericcurtin claimed this 9 days ago. Openstate:triage-needed
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
All issues in NVIDIA/OpenShell
Similar issues
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesOpen
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
maniator/verticopolis#880 ·
Maintainers usually reply within 1 day
-
IO.get_env on Node truncates names at embedded NULPossibly taken @Yi-111-a claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
HigherOrderCO/Bend#1449 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day