mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 16:02:03 +00:00
fix(windows): replace the managed CLI launcher with a native one (#24094)
* docs(security): add the antivirus clearance path for future releases Every AV false positive here has been handled one vendor and one shipped version at a time. Document the programs that clear future releases instead -- signer and product enrollment rather than per-build sample submission -- and add a script that reports an RC's current detection state by hash, so a verdict is found before users meet it in an issue report. Hash lookup only by default; --upload transmits the artifact and stays manual. * fix(windows): replace the managed CLI launcher with a native one resources\bin\orca.exe was a csc-compiled MSIL assembly: a small, freshly compiled .NET image in a user-writable directory that mutates environment variables and proxies a child process. That is the shape .NET dropper heuristics are trained on, and every verdict against it named the family -- MSILHeracles from two vendors, Wacatac!ml from a third. Signing the file does not change its shape, so signing never cleared it. Rebuild it in Rust. Same resolution, same environment contract, same argv passthrough that keeps newline-bearing orchestration bodies intact (#8374), and the child still inherits our environment block rather than an explicit map, so a block carrying both PATH and Path survives (#12046). The PE now carries publisher, version, icon and an asInvoker manifest from build.rs. Refs #23383 * ci(windows): install the Rust toolchain before building the CLI launcher The hosted runners happen to ship cargo, but a real Windows dev box does not -- verified on our own Windows QA host, where cargo and rustc were both absent. Relying on the image means a future image change fails deep inside electron-builder's native hook instead of at an obvious step.
This commit is contained in:
@@ -1159,9 +1159,27 @@ jobs:
|
||||
- name: Cache Windows CLI launcher
|
||||
uses: actions/cache@v5
|
||||
with:
|
||||
path: native/windows-cli-launcher/.build
|
||||
# Why the cargo directories ride along: a hit on .build skips the build
|
||||
# entirely, but a miss otherwise recompiles the resource crate from a
|
||||
# cold registry.
|
||||
path: |
|
||||
native/windows-cli-launcher/.build
|
||||
native/windows-cli-launcher/target
|
||||
~/.cargo/registry
|
||||
key: windows-cli-launcher-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('native/windows-cli-launcher/**', 'config/scripts/build-windows-cli-launcher.mjs', 'resources/build/icon.ico', 'package.json') }}
|
||||
|
||||
# Why an explicit step rather than trusting the runner image: the packaged
|
||||
# CLI launcher is a native Rust binary, and a host without cargo fails deep
|
||||
# inside electron-builder's native hook instead of here.
|
||||
- name: Ensure the Rust toolchain for the Windows CLI launcher
|
||||
shell: pwsh
|
||||
run: |
|
||||
if (-not (Get-Command cargo -ErrorAction SilentlyContinue)) {
|
||||
rustup toolchain install stable --profile minimal
|
||||
rustup default stable
|
||||
}
|
||||
cargo --version
|
||||
|
||||
- name: Build package inputs
|
||||
run: pnpm run build:release:parallel
|
||||
|
||||
|
||||
@@ -1395,6 +1395,20 @@ jobs:
|
||||
node config/scripts/build-windows-process-tree-relay-addon.mjs --arch=x64
|
||||
node config/scripts/build-windows-process-tree-relay-addon.mjs --arch=arm64
|
||||
|
||||
# Why an explicit step rather than trusting the runner image: the packaged
|
||||
# CLI launcher is a native Rust binary, and a Windows host without cargo
|
||||
# fails deep inside electron-builder's native hook instead of here. Real
|
||||
# Windows dev machines do not have it by default either.
|
||||
- name: Ensure the Rust toolchain for the Windows CLI launcher
|
||||
if: matrix.platform == 'win'
|
||||
shell: pwsh
|
||||
run: |
|
||||
if (-not (Get-Command cargo -ErrorAction SilentlyContinue)) {
|
||||
rustup toolchain install stable --profile minimal
|
||||
rustup default stable
|
||||
}
|
||||
cargo --version
|
||||
|
||||
# Why ORCA_POSTHOG_WRITE_KEY here: this is the only build that
|
||||
# produces a published binary, so this is the only place the secret
|
||||
# needs to be in scope. The key is a PostHog *project* API key, not
|
||||
|
||||
Reference in New Issue
Block a user