mirror of
https://github.com/stablyai/orca.git
synced 2026-10-04 16:02:08 +00:00
* build(orcad): merge per-runner prebuild slot trees into one matrix Each node-server lane builds only its own node-pty slot. Release CI needs their union before `build:orcad-prebuilds --require-slots` and the template build can run; merge-orcad-prebuilds.mjs verifies every lane's files against its own manifest, refuses duplicate slots and mismatched node-pty/N-API/Node-header builds, then writes one merged manifest. * build(orcad): keep agent-browser out of the desktop deployment template The template rides inside every desktop build (design D2). Seven ~10 MB agent-browser binaries would be ~76 MB, more than the rest of the template; design D2's package contents never listed it, and a slot without one already reports no headless browser. ORCAD_OMIT_AGENT_BROWSER=1 skips the copy; standalone build:orcad still includes it. * feat(packaging): ship the orcad deployment template in desktop builds Design D2: the server JS and every target's addons ship inside the app, as out/relay does; the ~120 MB Node runtimes stay excluded and are downloaded on demand. electron-builder copies out/orcad-template to Resources/orcad-template on every desktop OS, which is the first path materializeOrcadArtifact tries (process.resourcesPath). Platform signing rewrites native bytes the template manifest hashes: - macOS: the tree is signIgnored (codesign rejects its ELF/PE payloads); afterPack signs the darwin targets' Mach-O files with the app identity, as notarization requires, then reseals only those manifest entries. - Windows: SignPath signs after packaging, so release CI reseals from the inner-signing list (packaged-orcad-template.cjs --reseal-signed). Every other file must still match the build's hashes; afterPack verifies. ORCA_REQUIRE_ORCAD_TEMPLATE=1 makes a missing template fail beforePack and afterPack; without it a build ships none and SSH relays keep the legacy path. verify-packaged-orcad-template.test.mjs's "unused, excluded" contract is reversed on purpose. * ci(release): build the orcad template from qualified lanes and package it node-server-tests.yml becomes callable with a ref and build_template. With build_template, each lane that owns a release slot (macOS, Windows, the glibc 2.28 and Alpine lanes, and the glibc 2.17 compat lane) uploads its qualified out/orcad-prebuilds, the Windows lane also uploads both process-table addons, and desktop_template merges them, gates the full matrix plus the compat slot with --require-slots, runs build:orcad-template and uploads the orcad-template artifact. release-cut calls it at the release tag beside the other gates. The build and build-mac jobs wait for it, download it into out/orcad-template (the mac workflow from the parent run), and require it via ORCA_REQUIRE_ORCAD_TEMPLATE. The Windows signing staging skips the template's Linux/macOS payloads, and a reseal step records SignPath's bytes before the installer rebuild. A template-scoped concurrency group keeps a release call and main's push runs from cancelling each other. * test(orcad): keep the packaged-lookup imports clear of the compat-slot import edits * ci(orcad): let a rerun lane replace its template artifacts upload-artifact v4 refuses a second upload under an existing name in the same run, so rerunning a flaky node-server lane during a release would fail at the upload instead of re-qualifying the slot. * ci(node-server): build the template's Windows addons before the lane switches to Node 18 The addon build script imports TypeScript, which Node 18 cannot load, so every build_template run (release-cut included) failed on windows-2022. * fix(build): ship the orcad template's shared node_modules electron-builder's extraResources filter always drops the root node_modules of a source directory, so packaged apps lost orcad-template/node_modules and the afterPack verify failed. Copy it through its own resource entry. --------- Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
141 lines
5.1 KiB
JavaScript
141 lines
5.1 KiB
JavaScript
import { createHash } from 'node:crypto'
|
|
import { appendFile, mkdtemp, readFile, rm, writeFile } from 'node:fs/promises'
|
|
import { createRequire } from 'node:module'
|
|
import { tmpdir } from 'node:os'
|
|
import { join } from 'node:path'
|
|
import { afterEach, describe, expect, it, vi } from 'vitest'
|
|
import {
|
|
ORCAD_TEMPLATE_MANIFEST_FILENAME,
|
|
ORCAD_TEMPLATE_TARGETS_DIR
|
|
} from '../../src/shared/orcad-artifacts.ts'
|
|
import { writeOrcadTemplateTestFixture } from './orcad-template-test-fixture.mjs'
|
|
|
|
const require = createRequire(import.meta.url)
|
|
const {
|
|
assertOrcadTemplateBuilt,
|
|
finalizePackagedOrcadTemplate,
|
|
findOrcadTemplateMachOFiles,
|
|
resealOrcadTemplateManifest,
|
|
resealSignedWindowsApp
|
|
} = require('./packaged-orcad-template.cjs')
|
|
|
|
const PTY = 'node_modules/node-pty/build/Release/pty.node'
|
|
const MACH_O_64 = Buffer.from([0xcf, 0xfa, 0xed, 0xfe, 1, 2, 3, 4])
|
|
const roots = []
|
|
|
|
afterEach(async () => {
|
|
vi.restoreAllMocks()
|
|
await Promise.all(roots.splice(0).map((root) => rm(root, { recursive: true, force: true })))
|
|
})
|
|
|
|
async function tempRoot() {
|
|
const root = await mkdtemp(join(tmpdir(), 'orca-packaged-orcad-'))
|
|
roots.push(root)
|
|
return root
|
|
}
|
|
|
|
/** The fixture template, with darwin-arm64's pty.node made a real Mach-O as the build leaves it. */
|
|
async function createResources() {
|
|
const resourcesDir = await tempRoot()
|
|
const templateDir = await writeOrcadTemplateTestFixture(resourcesDir)
|
|
const ptyPath = join(templateDir, ORCAD_TEMPLATE_TARGETS_DIR, 'darwin-arm64', ...PTY.split('/'))
|
|
await writeFile(ptyPath, MACH_O_64)
|
|
const manifestPath = join(templateDir, ORCAD_TEMPLATE_MANIFEST_FILENAME)
|
|
const manifest = JSON.parse(await readFile(manifestPath, 'utf8'))
|
|
manifest.targets['darwin-arm64'].files[PTY] = createHash('sha256').update(MACH_O_64).digest('hex')
|
|
await writeFile(manifestPath, JSON.stringify(manifest))
|
|
return { resourcesDir, templateDir, ptyPath, manifestPath }
|
|
}
|
|
|
|
const quietly = () => vi.spyOn(console, 'log').mockImplementation(() => {})
|
|
|
|
describe('packaged orcad template', () => {
|
|
it('signs only darwin Mach-O payloads on macOS and reseals their new bytes', async () => {
|
|
quietly()
|
|
const { resourcesDir, templateDir, ptyPath } = await createResources()
|
|
const signed = []
|
|
const signMacBinary = async (path) => {
|
|
signed.push(path)
|
|
await appendFile(path, 'codesign-blob')
|
|
}
|
|
|
|
await finalizePackagedOrcadTemplate(resourcesDir, { platform: 'darwin', signMacBinary })
|
|
|
|
expect(signed).toEqual([ptyPath])
|
|
expect(findOrcadTemplateMachOFiles(templateDir)).toEqual([`targets/darwin-arm64/${PTY}`])
|
|
})
|
|
|
|
it('verifies without signing on Windows and Linux packages', async () => {
|
|
quietly()
|
|
const { resourcesDir } = await createResources()
|
|
const signMacBinary = vi.fn()
|
|
|
|
for (const platform of ['win32', 'linux']) {
|
|
await finalizePackagedOrcadTemplate(resourcesDir, { platform, signMacBinary })
|
|
}
|
|
expect(signMacBinary).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('still rejects a changed file that no signer touched', async () => {
|
|
quietly()
|
|
const { resourcesDir, templateDir } = await createResources()
|
|
await writeFile(join(templateDir, 'orcad.js'), 'tampered')
|
|
|
|
await expect(
|
|
finalizePackagedOrcadTemplate(resourcesDir, {
|
|
platform: 'darwin',
|
|
signMacBinary: async () => {}
|
|
})
|
|
).rejects.toThrow('orcad.js checksum mismatch')
|
|
})
|
|
|
|
it('refuses to reseal a path the manifest never listed', async () => {
|
|
const { templateDir } = await createResources()
|
|
|
|
expect(() =>
|
|
resealOrcadTemplateManifest(templateDir, ['targets/darwin-arm64/unlisted.node'])
|
|
).toThrow('is not a template manifest entry')
|
|
expect(() => resealOrcadTemplateManifest(templateDir, ['targets/win32-x64'])).toThrow(
|
|
'is not a template manifest entry'
|
|
)
|
|
})
|
|
|
|
it('fails a required build without the template and lets a dev build skip it', async () => {
|
|
quietly()
|
|
const resourcesDir = await tempRoot()
|
|
const env = { ORCA_REQUIRE_ORCAD_TEMPLATE: '1' }
|
|
|
|
await expect(
|
|
finalizePackagedOrcadTemplate(resourcesDir, { platform: 'linux', env })
|
|
).rejects.toThrow('missing the orcad deployment template')
|
|
await expect(
|
|
finalizePackagedOrcadTemplate(resourcesDir, { platform: 'linux', env: {} })
|
|
).resolves.toBeUndefined()
|
|
expect(() => assertOrcadTemplateBuilt(resourcesDir, env)).toThrow(
|
|
'ORCA_REQUIRE_ORCAD_TEMPLATE=1'
|
|
)
|
|
expect(() => assertOrcadTemplateBuilt(resourcesDir, {})).not.toThrow()
|
|
})
|
|
|
|
it('reseals the Windows files SignPath returned, by their app-relative list', async () => {
|
|
quietly()
|
|
const appDir = await tempRoot()
|
|
const templateDir = await writeOrcadTemplateTestFixture(join(appDir, 'resources'))
|
|
const conpty = 'node_modules/node-pty/build/Release/conpty.node'
|
|
await appendFile(
|
|
join(templateDir, ORCAD_TEMPLATE_TARGETS_DIR, 'win32-x64', ...conpty.split('/')),
|
|
'authenticode'
|
|
)
|
|
const list = join(appDir, 'inner-signing-list.txt')
|
|
await writeFile(
|
|
list,
|
|
[
|
|
'Orca.exe',
|
|
`resources\\orcad-template\\targets\\win32-x64\\${conpty.replaceAll('/', '\\')}`
|
|
].join('\r\n')
|
|
)
|
|
|
|
expect(() => resealSignedWindowsApp(appDir, list)).not.toThrow()
|
|
})
|
|
})
|