System Update internals
The browser-side installer for immutable OS releases, including real byte downloads, SHA-256 checks, OPFS writes and pending-version staging.
System flow
Fetch release
Download each file
Verify size/hash
Write OPFS
Read back
Verify again
Set pending
Source map
- app/cdn/update/page.tsx
- components/cdn/apps/builtins/SystemUpdateApp.tsx
- lib/cdn/os/client-os-updater.ts
Real install work
System Update streams the real release files rather than animating a fake timer. Every downloaded file is checked against the immutable release descriptor before it is written to the browser OS version directory.
Verify what was actually installed
After writing the slot, the updater reopens the files from OPFS and re-hashes them. This catches storage/write corruption and makes the pending marker represent a verified local slot, not merely a successful network response.
Restart is the activation boundary
Setting pending-version does not modify the already-running JavaScript. A restart/reload transfers control to the bootstrap, which decides whether the pending slot can become active.