mirror of
https://github.com/stablyai/orca.git
synced 2026-10-04 16:02:08 +00:00
* build(orcad): merge per-runner prebuild slot trees into one matrix Each node-server lane builds only its own node-pty slot. Release CI needs their union before `build:orcad-prebuilds --require-slots` and the template build can run; merge-orcad-prebuilds.mjs verifies every lane's files against its own manifest, refuses duplicate slots and mismatched node-pty/N-API/Node-header builds, then writes one merged manifest. * build(orcad): keep agent-browser out of the desktop deployment template The template rides inside every desktop build (design D2). Seven ~10 MB agent-browser binaries would be ~76 MB, more than the rest of the template; design D2's package contents never listed it, and a slot without one already reports no headless browser. ORCAD_OMIT_AGENT_BROWSER=1 skips the copy; standalone build:orcad still includes it. * feat(packaging): ship the orcad deployment template in desktop builds Design D2: the server JS and every target's addons ship inside the app, as out/relay does; the ~120 MB Node runtimes stay excluded and are downloaded on demand. electron-builder copies out/orcad-template to Resources/orcad-template on every desktop OS, which is the first path materializeOrcadArtifact tries (process.resourcesPath). Platform signing rewrites native bytes the template manifest hashes: - macOS: the tree is signIgnored (codesign rejects its ELF/PE payloads); afterPack signs the darwin targets' Mach-O files with the app identity, as notarization requires, then reseals only those manifest entries. - Windows: SignPath signs after packaging, so release CI reseals from the inner-signing list (packaged-orcad-template.cjs --reseal-signed). Every other file must still match the build's hashes; afterPack verifies. ORCA_REQUIRE_ORCAD_TEMPLATE=1 makes a missing template fail beforePack and afterPack; without it a build ships none and SSH relays keep the legacy path. verify-packaged-orcad-template.test.mjs's "unused, excluded" contract is reversed on purpose. * ci(release): build the orcad template from qualified lanes and package it node-server-tests.yml becomes callable with a ref and build_template. With build_template, each lane that owns a release slot (macOS, Windows, the glibc 2.28 and Alpine lanes, and the glibc 2.17 compat lane) uploads its qualified out/orcad-prebuilds, the Windows lane also uploads both process-table addons, and desktop_template merges them, gates the full matrix plus the compat slot with --require-slots, runs build:orcad-template and uploads the orcad-template artifact. release-cut calls it at the release tag beside the other gates. The build and build-mac jobs wait for it, download it into out/orcad-template (the mac workflow from the parent run), and require it via ORCA_REQUIRE_ORCAD_TEMPLATE. The Windows signing staging skips the template's Linux/macOS payloads, and a reseal step records SignPath's bytes before the installer rebuild. A template-scoped concurrency group keeps a release call and main's push runs from cancelling each other. * test(orcad): keep the packaged-lookup imports clear of the compat-slot import edits * ci(orcad): let a rerun lane replace its template artifacts upload-artifact v4 refuses a second upload under an existing name in the same run, so rerunning a flaky node-server lane during a release would fail at the upload instead of re-qualifying the slot. * ci(node-server): build the template's Windows addons before the lane switches to Node 18 The addon build script imports TypeScript, which Node 18 cannot load, so every build_template run (release-cut included) failed on windows-2022. * fix(build): ship the orcad template's shared node_modules electron-builder's extraResources filter always drops the root node_modules of a source directory, so packaged apps lost orcad-template/node_modules and the afterPack verify failed. Copy it through its own resource entry. --------- Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
184 lines
7.3 KiB
JavaScript
184 lines
7.3 KiB
JavaScript
/**
|
|
* The orcad deployment template inside desktop builds (design D2): JS plus every target's
|
|
* addons, never a Node runtime. SSH relays and managed orcad deploys materialize a target's
|
|
* slot from it (src/main/ssh/orcad-artifact-materializer.ts, `process.resourcesPath`).
|
|
*
|
|
* node config/scripts/packaged-orcad-template.cjs --reseal-signed <appDir> <signedListFile>
|
|
*
|
|
* reseals after an out-of-band signer (SignPath) rewrote template binaries in `<appDir>`.
|
|
*/
|
|
const { createHash } = require('node:crypto')
|
|
const {
|
|
closeSync,
|
|
existsSync,
|
|
openSync,
|
|
readFileSync,
|
|
readSync,
|
|
readdirSync,
|
|
writeFileSync
|
|
} = require('node:fs')
|
|
const { join, relative, resolve, sep } = require('node:path')
|
|
const {
|
|
ORCAD_TEMPLATE_MANIFEST_FILENAME,
|
|
ORCAD_TEMPLATE_TARGETS_DIR
|
|
} = require('../../src/shared/orcad-artifacts.ts')
|
|
const { verifyPackagedOrcadTemplate } = require('./verify-packaged-orcad-template.cjs')
|
|
|
|
const ORCAD_TEMPLATE_RESOURCE_DIR = 'orcad-template'
|
|
const orcadTemplateExtraResource = { from: 'out/orcad-template', to: ORCAD_TEMPLATE_RESOURCE_DIR }
|
|
// Why a second entry: electron-builder's copy filter always drops a source's root node_modules.
|
|
const orcadTemplateNodeModulesExtraResource = {
|
|
from: `${orcadTemplateExtraResource.from}/node_modules`,
|
|
to: `${ORCAD_TEMPLATE_RESOURCE_DIR}/node_modules`
|
|
}
|
|
// Why the whole tree: codesign rejects its ELF/PE payloads, and the darwin ones are signed in
|
|
// afterPack so their new hashes can be resealed into the manifest before the app is sealed.
|
|
const orcadTemplateMacSignIgnore = ['/orcad-template/']
|
|
|
|
// Mach-O thin (both byte orders, 32/64-bit) and fat headers.
|
|
const MACH_O_MAGICS = new Set(['feedface', 'feedfacf', 'cefaedfe', 'cffaedfe', 'cafebabe'])
|
|
|
|
/** Release packaging sets it; dev and local builds may ship without the template. */
|
|
function isOrcadTemplateRequired(env = process.env) {
|
|
return env.ORCA_REQUIRE_ORCAD_TEMPLATE === '1'
|
|
}
|
|
|
|
// Why: electron-builder only warns on a missing extraResources source.
|
|
function assertOrcadTemplateBuilt(projectDir = join(__dirname, '..', '..'), env = process.env) {
|
|
const manifest = join(
|
|
projectDir,
|
|
orcadTemplateExtraResource.from,
|
|
ORCAD_TEMPLATE_MANIFEST_FILENAME
|
|
)
|
|
if (isOrcadTemplateRequired(env) && !existsSync(manifest)) {
|
|
throw new Error(
|
|
`ORCA_REQUIRE_ORCAD_TEMPLATE=1 but ${manifest} is missing; download the merged template ` +
|
|
'from the release template job, or build it with `pnpm build:orcad-template`.'
|
|
)
|
|
}
|
|
}
|
|
|
|
function sha256(path) {
|
|
return createHash('sha256').update(readFileSync(path)).digest('hex')
|
|
}
|
|
|
|
function isMachO(path) {
|
|
const fd = openSync(path, 'r')
|
|
try {
|
|
const header = Buffer.alloc(4)
|
|
return readSync(fd, header, 0, 4, 0) === 4 && MACH_O_MAGICS.has(header.toString('hex'))
|
|
} finally {
|
|
closeSync(fd)
|
|
}
|
|
}
|
|
|
|
/** Template-relative paths of the darwin targets' Mach-O files, which macOS signing rewrites. */
|
|
function findOrcadTemplateMachOFiles(templateDir) {
|
|
const targetsDir = join(templateDir, ORCAD_TEMPLATE_TARGETS_DIR)
|
|
return readdirSync(targetsDir)
|
|
.filter((target) => target.startsWith('darwin-'))
|
|
.flatMap((target) =>
|
|
readdirSync(join(targetsDir, target), { recursive: true, withFileTypes: true })
|
|
.filter((entry) => entry.isFile() && isMachO(join(entry.parentPath, entry.name)))
|
|
.map((entry) =>
|
|
relative(templateDir, join(entry.parentPath, entry.name)).split(sep).join('/')
|
|
)
|
|
)
|
|
.sort()
|
|
}
|
|
|
|
/**
|
|
* Re-records the hashes of files a platform signer rewrote. Only the named files move; every
|
|
* other file must still match what the template build recorded, which the verify after this
|
|
* enforces, so a reseal cannot launder an unrelated change.
|
|
*/
|
|
function resealOrcadTemplateManifest(templateDir, signedPaths) {
|
|
const manifestPath = join(templateDir, ORCAD_TEMPLATE_MANIFEST_FILENAME)
|
|
const manifest = JSON.parse(readFileSync(manifestPath, 'utf8'))
|
|
for (const path of signedPaths) {
|
|
const segments = path.split('/')
|
|
const target =
|
|
segments[0] === ORCAD_TEMPLATE_TARGETS_DIR ? manifest.targets?.[segments[1]] : undefined
|
|
const filename = segments.slice(2).join('/')
|
|
const digest = () => sha256(join(templateDir, ...segments))
|
|
if (target?.files && Object.hasOwn(target.files, filename)) {
|
|
target.files[filename] = digest()
|
|
} else if (target && target.browserName === filename) {
|
|
target.browserSha256 = digest()
|
|
} else if (!target && Object.hasOwn(manifest.commonSha256 ?? {}, path)) {
|
|
manifest.commonSha256[path] = digest()
|
|
} else {
|
|
throw new Error(`[packaged-orcad-template] ${path} is not a template manifest entry`)
|
|
}
|
|
}
|
|
writeFileSync(manifestPath, `${JSON.stringify(manifest, null, 2)}\n`)
|
|
}
|
|
|
|
/**
|
|
* afterPack: sign the darwin payloads on macOS (notarization requires every nested Mach-O to
|
|
* carry the app's Developer ID), reseal, then verify the exact bytes that ship.
|
|
*/
|
|
async function finalizePackagedOrcadTemplate(resourcesDir, options) {
|
|
const { platform, env = process.env, signMacBinary } = options
|
|
const templateDir = join(resourcesDir, ORCAD_TEMPLATE_RESOURCE_DIR)
|
|
if (!existsSync(templateDir)) {
|
|
if (isOrcadTemplateRequired(env)) {
|
|
throw new Error(`Packaged app is missing the orcad deployment template: ${templateDir}`)
|
|
}
|
|
// SSH relays then keep the legacy host-Node path (ssh-relay-pinned-node.ts).
|
|
console.log('[packaged-orcad-template] skipped: this build ships no orcad template')
|
|
return
|
|
}
|
|
if (platform === 'darwin') {
|
|
const machO = findOrcadTemplateMachOFiles(templateDir)
|
|
for (const path of machO) {
|
|
await signMacBinary(join(templateDir, ...path.split('/')))
|
|
}
|
|
resealOrcadTemplateManifest(templateDir, machO)
|
|
}
|
|
verifyPackagedOrcadTemplate(resourcesDir)
|
|
}
|
|
|
|
/** `inner-signing-list.txt` lines are app-relative Windows paths; keep the template's. */
|
|
function resealSignedWindowsApp(appDir, signedListFile) {
|
|
const prefix = `resources/${ORCAD_TEMPLATE_RESOURCE_DIR}/`
|
|
const signed = readFileSync(signedListFile, 'utf8')
|
|
.split(/\r?\n/)
|
|
.map((line) => line.trim().replaceAll('\\', '/'))
|
|
.filter((line) => line.startsWith(prefix))
|
|
.map((line) => line.slice(prefix.length))
|
|
const resourcesDir = join(appDir, 'resources')
|
|
if (!existsSync(join(resourcesDir, ORCAD_TEMPLATE_RESOURCE_DIR))) {
|
|
if (isOrcadTemplateRequired()) {
|
|
throw new Error(`Signed app is missing the orcad deployment template under ${resourcesDir}`)
|
|
}
|
|
console.log('[packaged-orcad-template] skipped reseal: this build ships no orcad template')
|
|
return
|
|
}
|
|
resealOrcadTemplateManifest(join(resourcesDir, ORCAD_TEMPLATE_RESOURCE_DIR), signed)
|
|
verifyPackagedOrcadTemplate(resourcesDir)
|
|
console.log(`[packaged-orcad-template] resealed ${signed.length} signed template file(s)`)
|
|
}
|
|
|
|
module.exports = {
|
|
ORCAD_TEMPLATE_RESOURCE_DIR,
|
|
assertOrcadTemplateBuilt,
|
|
finalizePackagedOrcadTemplate,
|
|
findOrcadTemplateMachOFiles,
|
|
isOrcadTemplateRequired,
|
|
orcadTemplateExtraResource,
|
|
orcadTemplateNodeModulesExtraResource,
|
|
orcadTemplateMacSignIgnore,
|
|
resealOrcadTemplateManifest,
|
|
resealSignedWindowsApp
|
|
}
|
|
|
|
if (require.main === module) {
|
|
const [flag, appDir, signedListFile] = process.argv.slice(2)
|
|
if (flag !== '--reseal-signed' || !appDir || !signedListFile) {
|
|
console.error('usage: packaged-orcad-template.cjs --reseal-signed <appDir> <signedListFile>')
|
|
process.exit(2)
|
|
}
|
|
resealSignedWindowsApp(resolve(appDir), resolve(signedListFile))
|
|
}
|