From 31bd20149c56728ea0240c09f365df193df5515a Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Sun, 21 Jun 2026 01:31:27 -0700 Subject: [PATCH] fix(install.ps1): forward UNSLOTH_PYTORCH_MIRROR into the WSL installer The WoA+NVIDIA WSL2 fallback bridges UNSLOTH_NO_LLAMA_CUDA / UNSLOTH_PYTHON / UNSLOTH_SKIP_WSL_WINDOWS_SHORTCUT into the distro, but not UNSLOTH_PYTORCH_MIRROR. install.sh's get_torch_index_url() reads it (as does install.ps1's own native Get-TorchIndexUrl), yet Windows env vars don't cross into WSL -- so a mirror-required / restricted-network install silently fell back to download.pytorch.org inside the distro even though the outer installer honored the mirror. Forward it alongside the other vars, guarded by a strict http(s)-URL allow-list (no shell metacharacters) and single-quoted so the value can't break out of the bash -lc string. Verified: legit mirror URLs (incl. host:port and query strings) forward; space/';'/$()/quote-injection and non-http schemes are rejected. Addresses Codex review P2 (install.ps1). --- install.ps1 | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/install.ps1 b/install.ps1 index f797b80296..089ba2b8bb 100644 --- a/install.ps1 +++ b/install.ps1 @@ -2093,6 +2093,14 @@ exit 0 # Forward a user Python pin (install.sh reads UNSLOTH_PYTHON, but Windows env vars don't cross # into WSL unless bridged). Numeric-only guard (e.g. 3.12) prevents injection. if ($env:UNSLOTH_PYTHON -and ($env:UNSLOTH_PYTHON -match '^[0-9][0-9.]*$')) { $_fwdEnv += "export UNSLOTH_PYTHON=$($env:UNSLOTH_PYTHON); " } + # Forward a custom PyTorch wheel mirror. install.sh reads UNSLOTH_PYTORCH_MIRROR (get_torch_index_url) + # but, like the other Windows env vars, it doesn't cross into WSL -- so a mirror-required / restricted- + # network install would silently fall back to download.pytorch.org inside the distro even though the + # outer installer honored the mirror. Strict http(s)-URL allow-list (no shell metachars) + single-quote + # so the value can't break out of the bash -lc string. + if ($env:UNSLOTH_PYTORCH_MIRROR -and ($env:UNSLOTH_PYTORCH_MIRROR -match '^https?://[A-Za-z0-9._~:/?#@%+=&-]+$')) { + $_fwdEnv += "export UNSLOTH_PYTORCH_MIRROR='$($env:UNSLOTH_PYTORCH_MIRROR)'; " + } # install.ps1 owns the WoA shortcut (one canonical "Unsloth Studio.lnk" with a # %USERPROFILE%\.unsloth icon that renders on WoA). Tell install.sh to skip its own # WSL .lnk so we don't get a duplicate whose %LOCALAPPDATA% icon renders blank.