mirror of
https://github.com/stablyai/orca.git
synced 2026-10-04 08:02:09 +00:00
* fix(ssh): launch the Windows relay outside sshd's job without WMI Win32-OpenSSH kills a session's job on close but allows breakaway. relay.js gains a one-shot launcher mode that starts the detached relay with CREATE_BREAKAWAY_FROM_JOB through the staged process-tree addon, so a standard user no longer needs a WMI Remote Enable grant. WMI stays as the fallback for a relay without the addon, and a refusal there is named. The Windows SSH-host lanes drop their WMI grant and assert the breakaway route and adoption. * fix(ssh): find runtime holds without WMI on a standard-user Windows host The store GC read held runtimes through Get-CimInstance Win32_Process, which WMI refuses to a standard user's SSH logon, so the pass kept every runtime. On a refusal it now reads this account's own process image paths through Get-Process. * build(relay): ship the Windows relay launcher addon in every desktop package macOS and Linux packages carried Windows relays without windows-process-tree.node, so a legacy-runtime relay they uploaded to a Windows SSH host could not launch outside sshd's job and fell back to WMI, which a standard user is refused. A reusable Windows job now compiles the x64 and arm64 addons once and uploads them; release-cut, release-mac-build, and the hourly/daily/adhoc mac builds download them before build:release and require both arches. Staging now rejects a binary with the wrong PE machine, the ReadProcessMemory import, or no spawnOutsideJob export, so a stale pre-launcher build cannot ship. * ci(ssh): run the Windows SSH-host lanes when the relay process-tree build scripts change The staging and gyp-rebuild scripts decide which windows-process-tree addon the relay ships, so a change to either must re-prove the Windows host cells. * test(ci): find the mac orcad-template download by artifact name The release mac job now also downloads the relay Windows process-tree addons, so the first download-artifact step is no longer the template's. --------- Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
72 lines
2.5 KiB
YAML
72 lines
2.5 KiB
YAML
name: Relay Windows process-tree addons
|
|
|
|
# Why a reusable workflow: every desktop package ships relays for Windows SSH hosts,
|
|
# but only a Windows runner can compile the addon that launches a relay outside
|
|
# sshd's job. macOS and Linux packaging jobs download this artifact into
|
|
# .build/windows-process-tree before `pnpm build:release` stages it.
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
ref:
|
|
description: Commit or tag to build; must match what the packaging job checks out.
|
|
required: true
|
|
type: string
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
# Why windows-2022: windows-latest moved to VS 2026 before node-gyp could detect
|
|
# it. GitHub-hosted, so release-cut's SignPath provenance rule still holds.
|
|
runs-on: windows-2022
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ inputs.ref }}
|
|
persist-credentials: false
|
|
|
|
# Plain setup rather than a composite action: `uses: ./` resolves from the
|
|
# checked-out ref, which may be a release tag that predates the action.
|
|
- name: Setup pnpm
|
|
uses: pnpm/setup@v2
|
|
with:
|
|
install: false
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version-file: package.json
|
|
cache: pnpm
|
|
cache-dependency-path: pnpm-lock.yaml
|
|
|
|
# Why host-only: the addon is compiled from the patched source pnpm
|
|
# materializes, and arm64 cross-compiles through node-gyp --arch.
|
|
- name: Install dependencies
|
|
uses: nick-fields/retry@v4
|
|
with:
|
|
timeout_minutes: 10
|
|
max_attempts: 3
|
|
retry_wait_seconds: 30
|
|
command: pnpm install --frozen-lockfile
|
|
|
|
# The build script refuses unpatched source and checks each output's PE
|
|
# machine, ReadProcessMemory import, and spawnOutsideJob export.
|
|
- name: Build Windows process-table addons for the relay
|
|
shell: bash
|
|
run: |
|
|
node config/scripts/build-windows-process-tree-relay-addon.mjs --arch=x64
|
|
node config/scripts/build-windows-process-tree-relay-addon.mjs --arch=arm64
|
|
|
|
- name: Upload relay addons
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: relay-windows-process-tree
|
|
path: .build/windows-process-tree/
|
|
if-no-files-found: error
|
|
retention-days: 7
|
|
# A rerun attempt re-uploads under the same name, which is otherwise refused.
|
|
overwrite: true
|