mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 00:02:10 +00:00
* docs(security): add the antivirus clearance path for future releases Every AV false positive here has been handled one vendor and one shipped version at a time. Document the programs that clear future releases instead -- signer and product enrollment rather than per-build sample submission -- and add a script that reports an RC's current detection state by hash, so a verdict is found before users meet it in an issue report. Hash lookup only by default; --upload transmits the artifact and stays manual. * fix(windows): replace the managed CLI launcher with a native one resources\bin\orca.exe was a csc-compiled MSIL assembly: a small, freshly compiled .NET image in a user-writable directory that mutates environment variables and proxies a child process. That is the shape .NET dropper heuristics are trained on, and every verdict against it named the family -- MSILHeracles from two vendors, Wacatac!ml from a third. Signing the file does not change its shape, so signing never cleared it. Rebuild it in Rust. Same resolution, same environment contract, same argv passthrough that keeps newline-bearing orchestration bodies intact (#8374), and the child still inherits our environment block rather than an explicit map, so a block carrying both PATH and Path survives (#12046). The PE now carries publisher, version, icon and an asInvoker manifest from build.rs. Refs #23383 * ci(windows): install the Rust toolchain before building the CLI launcher The hosted runners happen to ship cargo, but a real Windows dev box does not -- verified on our own Windows QA host, where cargo and rustc were both absent. Relying on the image means a future image change fails deep inside electron-builder's native hook instead of at an obvious step.
123 lines
4.0 KiB
JavaScript
123 lines
4.0 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
import { spawnSync } from 'node:child_process'
|
|
import { createHash } from 'node:crypto'
|
|
import { copyFileSync, existsSync, mkdirSync, readFileSync, rmSync, writeFileSync } from 'node:fs'
|
|
import { dirname, join, resolve } from 'node:path'
|
|
import { pathToFileURL } from 'node:url'
|
|
|
|
export function windowsCliLauncherFingerprint(inputPaths, version) {
|
|
const hash = createHash('sha256').update(version)
|
|
for (const inputPath of inputPaths) {
|
|
hash.update('\0').update(readFileSync(inputPath))
|
|
}
|
|
return hash.digest('hex')
|
|
}
|
|
|
|
export function shouldReuseCompiledWindowsCliLauncher(outputPath, fingerprint) {
|
|
const fingerprintPath = `${outputPath}.sha256`
|
|
return (
|
|
existsSync(outputPath) &&
|
|
existsSync(fingerprintPath) &&
|
|
readFileSync(fingerprintPath, 'utf8') === fingerprint
|
|
)
|
|
}
|
|
|
|
/**
|
|
* The four-part numeric version Windows records in the PE. A prerelease suffix
|
|
* survives only in ProductVersion, which is a free-form string.
|
|
*/
|
|
export function windowsCliLauncherFileVersion(version) {
|
|
const match = /^(\d+)\.(\d+)\.(\d+)(?:-[0-9A-Za-z.-]+)?(?:\+[0-9A-Za-z.-]+)?$/.exec(version ?? '')
|
|
if (!match || match.slice(1).some((part) => Number(part) > 65534)) {
|
|
throw new Error(`Invalid Windows CLI launcher version: ${version}`)
|
|
}
|
|
return `${match.slice(1).join('.')}.0`
|
|
}
|
|
|
|
function defaultOutputPath(projectRoot) {
|
|
return join(projectRoot, 'native', 'windows-cli-launcher', '.build', 'orca.exe')
|
|
}
|
|
|
|
function readArg(name) {
|
|
const index = process.argv.indexOf(name)
|
|
return index !== -1 ? process.argv[index + 1] : undefined
|
|
}
|
|
|
|
if (process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href) {
|
|
if (process.platform !== 'win32') {
|
|
// Why: electron-builder treats a skipped native build like success and can
|
|
// continue toward a Windows package whose declared orca.exe does not exist.
|
|
throw new Error(
|
|
'Windows CLI launcher compilation requires a Windows host; refusing to package without it.'
|
|
)
|
|
}
|
|
|
|
const repoRoot = resolve(import.meta.dirname, '../..')
|
|
const crateRoot = join(repoRoot, 'native', 'windows-cli-launcher')
|
|
const manifestPath = join(crateRoot, 'Cargo.toml')
|
|
const iconPath = join(repoRoot, 'resources', 'build', 'icon.ico')
|
|
const { version } = JSON.parse(readFileSync(join(repoRoot, 'package.json'), 'utf8'))
|
|
// Throws on a version the PE cannot represent, before anything is compiled.
|
|
windowsCliLauncherFileVersion(version)
|
|
const fingerprint = windowsCliLauncherFingerprint(
|
|
[
|
|
join(crateRoot, 'src', 'main.rs'),
|
|
join(crateRoot, 'build.rs'),
|
|
manifestPath,
|
|
join(crateRoot, 'app.manifest'),
|
|
iconPath,
|
|
join(repoRoot, 'config/scripts/build-windows-cli-launcher.mjs')
|
|
],
|
|
version
|
|
)
|
|
const outputPath = readArg('--output') ?? defaultOutputPath(repoRoot)
|
|
|
|
mkdirSync(dirname(outputPath), { recursive: true })
|
|
if (shouldReuseCompiledWindowsCliLauncher(outputPath, fingerprint)) {
|
|
console.log(`[native-build] reusing Windows CLI launcher at ${outputPath}`)
|
|
process.exit(0)
|
|
}
|
|
|
|
rmSync(`${outputPath}.sha256`, { force: true })
|
|
const targetDirectory = join(crateRoot, 'target')
|
|
const result = spawnSync(
|
|
'cargo',
|
|
[
|
|
'build',
|
|
'--release',
|
|
'--locked',
|
|
'--manifest-path',
|
|
manifestPath,
|
|
'--target-dir',
|
|
targetDirectory
|
|
],
|
|
{
|
|
cwd: crateRoot,
|
|
stdio: 'inherit',
|
|
env: {
|
|
...process.env,
|
|
ORCA_LAUNCHER_VERSION: version,
|
|
ORCA_LAUNCHER_ICON: iconPath
|
|
}
|
|
}
|
|
)
|
|
|
|
if (result.signal) {
|
|
process.kill(process.pid, result.signal)
|
|
}
|
|
if (result.error) {
|
|
// Why named explicitly: a bare ENOENT here reads as a missing source file
|
|
// rather than a host without the toolchain the packaged CLI needs.
|
|
throw new Error(
|
|
`Unable to run cargo for the Windows CLI launcher: ${result.error.message}. Install Rust (https://rustup.rs) and retry.`
|
|
)
|
|
}
|
|
if (result.status !== 0) {
|
|
process.exit(result.status ?? 1)
|
|
}
|
|
|
|
copyFileSync(join(targetDirectory, 'release', 'orca.exe'), outputPath)
|
|
writeFileSync(`${outputPath}.sha256`, fingerprint)
|
|
}
|