Files
orca/config/scripts/packaged-orcad-template.cjs
T
OrcaWinandm4air 554f7f4ce5 feat(packaging): ship the orcad server template in desktop builds (#24155)
* build(orcad): merge per-runner prebuild slot trees into one matrix

Each node-server lane builds only its own node-pty slot. Release CI needs
their union before `build:orcad-prebuilds --require-slots` and the
template build can run; merge-orcad-prebuilds.mjs verifies every lane's
files against its own manifest, refuses duplicate slots and mismatched
node-pty/N-API/Node-header builds, then writes one merged manifest.

* build(orcad): keep agent-browser out of the desktop deployment template

The template rides inside every desktop build (design D2). Seven ~10 MB
agent-browser binaries would be ~76 MB, more than the rest of the template;
design D2's package contents never listed it, and a slot without one
already reports no headless browser. ORCAD_OMIT_AGENT_BROWSER=1 skips the
copy; standalone build:orcad still includes it.

* feat(packaging): ship the orcad deployment template in desktop builds

Design D2: the server JS and every target's addons ship inside the app,
as out/relay does; the ~120 MB Node runtimes stay excluded and are
downloaded on demand. electron-builder copies out/orcad-template to
Resources/orcad-template on every desktop OS, which is the first path
materializeOrcadArtifact tries (process.resourcesPath).

Platform signing rewrites native bytes the template manifest hashes:
- macOS: the tree is signIgnored (codesign rejects its ELF/PE payloads);
  afterPack signs the darwin targets' Mach-O files with the app identity,
  as notarization requires, then reseals only those manifest entries.
- Windows: SignPath signs after packaging, so release CI reseals from the
  inner-signing list (packaged-orcad-template.cjs --reseal-signed).
Every other file must still match the build's hashes; afterPack verifies.

ORCA_REQUIRE_ORCAD_TEMPLATE=1 makes a missing template fail beforePack and
afterPack; without it a build ships none and SSH relays keep the legacy
path. verify-packaged-orcad-template.test.mjs's "unused, excluded"
contract is reversed on purpose.

* ci(release): build the orcad template from qualified lanes and package it

node-server-tests.yml becomes callable with a ref and build_template.
With build_template, each lane that owns a release slot (macOS, Windows,
the glibc 2.28 and Alpine lanes, and the glibc 2.17 compat lane) uploads
its qualified out/orcad-prebuilds, the Windows lane also uploads both
process-table addons, and desktop_template merges them, gates the full
matrix plus the compat slot with --require-slots, runs
build:orcad-template and uploads the orcad-template artifact.

release-cut calls it at the release tag beside the other gates. The
build and build-mac jobs wait for it, download it into out/orcad-template
(the mac workflow from the parent run), and require it via
ORCA_REQUIRE_ORCAD_TEMPLATE. The Windows signing staging skips the
template's Linux/macOS payloads, and a reseal step records SignPath's
bytes before the installer rebuild. A template-scoped concurrency group
keeps a release call and main's push runs from cancelling each other.

* test(orcad): keep the packaged-lookup imports clear of the compat-slot import edits

* ci(orcad): let a rerun lane replace its template artifacts

upload-artifact v4 refuses a second upload under an existing name in the same
run, so rerunning a flaky node-server lane during a release would fail at the
upload instead of re-qualifying the slot.

* ci(node-server): build the template's Windows addons before the lane switches to Node 18

The addon build script imports TypeScript, which Node 18 cannot load, so every
build_template run (release-cut included) failed on windows-2022.

* fix(build): ship the orcad template's shared node_modules

electron-builder's extraResources filter always drops the root node_modules of
a source directory, so packaged apps lost orcad-template/node_modules and the
afterPack verify failed. Copy it through its own resource entry.

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
2026-10-01 04:01:26 -07:00

184 lines
7.3 KiB
JavaScript

/**
* The orcad deployment template inside desktop builds (design D2): JS plus every target's
* addons, never a Node runtime. SSH relays and managed orcad deploys materialize a target's
* slot from it (src/main/ssh/orcad-artifact-materializer.ts, `process.resourcesPath`).
*
* node config/scripts/packaged-orcad-template.cjs --reseal-signed <appDir> <signedListFile>
*
* reseals after an out-of-band signer (SignPath) rewrote template binaries in `<appDir>`.
*/
const { createHash } = require('node:crypto')
const {
closeSync,
existsSync,
openSync,
readFileSync,
readSync,
readdirSync,
writeFileSync
} = require('node:fs')
const { join, relative, resolve, sep } = require('node:path')
const {
ORCAD_TEMPLATE_MANIFEST_FILENAME,
ORCAD_TEMPLATE_TARGETS_DIR
} = require('../../src/shared/orcad-artifacts.ts')
const { verifyPackagedOrcadTemplate } = require('./verify-packaged-orcad-template.cjs')
const ORCAD_TEMPLATE_RESOURCE_DIR = 'orcad-template'
const orcadTemplateExtraResource = { from: 'out/orcad-template', to: ORCAD_TEMPLATE_RESOURCE_DIR }
// Why a second entry: electron-builder's copy filter always drops a source's root node_modules.
const orcadTemplateNodeModulesExtraResource = {
from: `${orcadTemplateExtraResource.from}/node_modules`,
to: `${ORCAD_TEMPLATE_RESOURCE_DIR}/node_modules`
}
// Why the whole tree: codesign rejects its ELF/PE payloads, and the darwin ones are signed in
// afterPack so their new hashes can be resealed into the manifest before the app is sealed.
const orcadTemplateMacSignIgnore = ['/orcad-template/']
// Mach-O thin (both byte orders, 32/64-bit) and fat headers.
const MACH_O_MAGICS = new Set(['feedface', 'feedfacf', 'cefaedfe', 'cffaedfe', 'cafebabe'])
/** Release packaging sets it; dev and local builds may ship without the template. */
function isOrcadTemplateRequired(env = process.env) {
return env.ORCA_REQUIRE_ORCAD_TEMPLATE === '1'
}
// Why: electron-builder only warns on a missing extraResources source.
function assertOrcadTemplateBuilt(projectDir = join(__dirname, '..', '..'), env = process.env) {
const manifest = join(
projectDir,
orcadTemplateExtraResource.from,
ORCAD_TEMPLATE_MANIFEST_FILENAME
)
if (isOrcadTemplateRequired(env) && !existsSync(manifest)) {
throw new Error(
`ORCA_REQUIRE_ORCAD_TEMPLATE=1 but ${manifest} is missing; download the merged template ` +
'from the release template job, or build it with `pnpm build:orcad-template`.'
)
}
}
function sha256(path) {
return createHash('sha256').update(readFileSync(path)).digest('hex')
}
function isMachO(path) {
const fd = openSync(path, 'r')
try {
const header = Buffer.alloc(4)
return readSync(fd, header, 0, 4, 0) === 4 && MACH_O_MAGICS.has(header.toString('hex'))
} finally {
closeSync(fd)
}
}
/** Template-relative paths of the darwin targets' Mach-O files, which macOS signing rewrites. */
function findOrcadTemplateMachOFiles(templateDir) {
const targetsDir = join(templateDir, ORCAD_TEMPLATE_TARGETS_DIR)
return readdirSync(targetsDir)
.filter((target) => target.startsWith('darwin-'))
.flatMap((target) =>
readdirSync(join(targetsDir, target), { recursive: true, withFileTypes: true })
.filter((entry) => entry.isFile() && isMachO(join(entry.parentPath, entry.name)))
.map((entry) =>
relative(templateDir, join(entry.parentPath, entry.name)).split(sep).join('/')
)
)
.sort()
}
/**
* Re-records the hashes of files a platform signer rewrote. Only the named files move; every
* other file must still match what the template build recorded, which the verify after this
* enforces, so a reseal cannot launder an unrelated change.
*/
function resealOrcadTemplateManifest(templateDir, signedPaths) {
const manifestPath = join(templateDir, ORCAD_TEMPLATE_MANIFEST_FILENAME)
const manifest = JSON.parse(readFileSync(manifestPath, 'utf8'))
for (const path of signedPaths) {
const segments = path.split('/')
const target =
segments[0] === ORCAD_TEMPLATE_TARGETS_DIR ? manifest.targets?.[segments[1]] : undefined
const filename = segments.slice(2).join('/')
const digest = () => sha256(join(templateDir, ...segments))
if (target?.files && Object.hasOwn(target.files, filename)) {
target.files[filename] = digest()
} else if (target && target.browserName === filename) {
target.browserSha256 = digest()
} else if (!target && Object.hasOwn(manifest.commonSha256 ?? {}, path)) {
manifest.commonSha256[path] = digest()
} else {
throw new Error(`[packaged-orcad-template] ${path} is not a template manifest entry`)
}
}
writeFileSync(manifestPath, `${JSON.stringify(manifest, null, 2)}\n`)
}
/**
* afterPack: sign the darwin payloads on macOS (notarization requires every nested Mach-O to
* carry the app's Developer ID), reseal, then verify the exact bytes that ship.
*/
async function finalizePackagedOrcadTemplate(resourcesDir, options) {
const { platform, env = process.env, signMacBinary } = options
const templateDir = join(resourcesDir, ORCAD_TEMPLATE_RESOURCE_DIR)
if (!existsSync(templateDir)) {
if (isOrcadTemplateRequired(env)) {
throw new Error(`Packaged app is missing the orcad deployment template: ${templateDir}`)
}
// SSH relays then keep the legacy host-Node path (ssh-relay-pinned-node.ts).
console.log('[packaged-orcad-template] skipped: this build ships no orcad template')
return
}
if (platform === 'darwin') {
const machO = findOrcadTemplateMachOFiles(templateDir)
for (const path of machO) {
await signMacBinary(join(templateDir, ...path.split('/')))
}
resealOrcadTemplateManifest(templateDir, machO)
}
verifyPackagedOrcadTemplate(resourcesDir)
}
/** `inner-signing-list.txt` lines are app-relative Windows paths; keep the template's. */
function resealSignedWindowsApp(appDir, signedListFile) {
const prefix = `resources/${ORCAD_TEMPLATE_RESOURCE_DIR}/`
const signed = readFileSync(signedListFile, 'utf8')
.split(/\r?\n/)
.map((line) => line.trim().replaceAll('\\', '/'))
.filter((line) => line.startsWith(prefix))
.map((line) => line.slice(prefix.length))
const resourcesDir = join(appDir, 'resources')
if (!existsSync(join(resourcesDir, ORCAD_TEMPLATE_RESOURCE_DIR))) {
if (isOrcadTemplateRequired()) {
throw new Error(`Signed app is missing the orcad deployment template under ${resourcesDir}`)
}
console.log('[packaged-orcad-template] skipped reseal: this build ships no orcad template')
return
}
resealOrcadTemplateManifest(join(resourcesDir, ORCAD_TEMPLATE_RESOURCE_DIR), signed)
verifyPackagedOrcadTemplate(resourcesDir)
console.log(`[packaged-orcad-template] resealed ${signed.length} signed template file(s)`)
}
module.exports = {
ORCAD_TEMPLATE_RESOURCE_DIR,
assertOrcadTemplateBuilt,
finalizePackagedOrcadTemplate,
findOrcadTemplateMachOFiles,
isOrcadTemplateRequired,
orcadTemplateExtraResource,
orcadTemplateNodeModulesExtraResource,
orcadTemplateMacSignIgnore,
resealOrcadTemplateManifest,
resealSignedWindowsApp
}
if (require.main === module) {
const [flag, appDir, signedListFile] = process.argv.slice(2)
if (flag !== '--reseal-signed' || !appDir || !signedListFile) {
console.error('usage: packaged-orcad-template.cjs --reseal-signed <appDir> <signedListFile>')
process.exit(2)
}
resealSignedWindowsApp(resolve(appDir), resolve(signedListFile))
}