Commit graph

50 commits

Author SHA1 Message Date
Peter Steinberger
16be7f0f27
feat(macos): run the private app runtime on the OpenClaw Bun fork (#161603)
* feat(macos): run the private app runtime on the OpenClaw Bun fork

* fix(macos): let the bundled runtime load unsigned plugin addons

* test(macos): remove obsolete worker pruning closure tests

* test(macos): drop stale packaging test imports

* test(macos): migrate CI scope cases to runtime paths
2026-09-30 01:27:03 -07:00
Dallin Romney
6b799dc6ad
fix: select one signing identity for macOS distribution builds (#157861) 2026-09-25 11:49:30 -07:00
Peter Steinberger
299ea7c393
fix(scripts): run macOS tooling under /bin/bash and make the framework-merge fixture self-contained (#141884)
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures

Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.

Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.

* fix(scripts): keep guarded portable scripts bash 3.2 compatible

* fix(scripts): keep macOS Bash CI coverage green

Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.

Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.

* docs(install): use system Bash in install and recovery commands

Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.

Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.

* fix(scripts): preserve streamed installs and CI packing

Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.

Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.

Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
2026-09-08 01:21:30 -07:00
Peter Steinberger
986c0d78f2 build(macos): bundle and install openclaw-mac 2026-09-07 13:05:37 -07:00
Peter Steinberger
dbb6e1f00b
feat(macos): connect gateways through browser sign-in and website handoff (#138745)
* feat(macos): connect saved gateways through browser sign-in

* fix(macos): preserve browser session observers across reconnect

* fix(macos): await WebKit cookie deletion

* test(macos): isolate dashboard startup and WebKit cleanup

* fix(macos): preserve browser account ownership across reconnects

Bind native connections and cached queued work to the verified browser account. Retire old account and media authority before replacement or removal, and restore the explicitly selected Gateway after app restart using the existing preference.

Keep removal completion tied to its original owner and correct native test fixtures that assumed unconfigured startup always selected Primary. Release-note context: personal Gateway sign-in now survives restart without changing the machine Primary connection.

* fix(macos): isolate profile notification values

Capture immutable receipt and removal values before entering MainActor callbacks. Remove redundant mutable test state while retaining the real HTTP response gate and explicit deletion wait.

* fix(macos): scope browser stores to credential registries

Use the existing app-profile Keychain namespace in persistent WebKit store identity, so named app profiles at the same Gateway cannot overwrite or clear each other’s cookies. Cover independent persistent cookie replacement and removal.

* test(macos): use localhost for pinned media fixtures

Exercise real TLS through the certificate’s local hostname, retaining exact pins, origin and redirect checks, and cancellation timing. macOS ATS rejects the fixture’s untrusted IP-literal certificate before media authority checks; production trust policy remains unchanged.

* fix(macos): canonicalize gateway URLs before browser discovery

* fix(macos): apply TLS policy to streaming task challenges

* fix(macos): preserve browser state across account renewals

* chore(macos): refresh native localization source inventory

* test(macos): align browser preference fixtures with store lifetime

* fix(macos): initialize reconnect editor from saved gateway

* test(macos): evaluate gateway field predicate before expectation

* style(macos): format gateway editor documentation

* test(macos): retain browser store during account transitions
2026-09-05 03:11:56 -07:00
Peter Steinberger
dd4528b639
fix(macos): pair app builds with verified node workers (#131466)
Pair packaged apps with complete private arm64 and x86_64 workers whose full build identity matches the app. Preserve independently managed Gateways and complete recognized native-first state through the canonical initializer. Verify emitted-SDK filesystem calls, native capabilities, readiness and shutdown before app publication.

Derive elevation payloads without modifying canonical installed inputs. Preserve universal slices, resources and contained links; reject incomplete, malformed, escaping or mismatched payloads. Reuse descriptor-bound native inventory for signing while retaining the portable installer's independent distribution contract and every Foundation identity, entitlement, notarization and architecture gate.

Use the existing pinned-pnpm package path, including Corepack-only builders, and avoid recursive app-glob expansion. Centralize Mac CI ownership. Carry invocation-owned Git lock cleanup into main's canonical Git owner and regenerate its workflow projection, retaining lifetime fencing and pre-existing/junction-linked locks.

Fix the Android refresh race exposed by CI by removing the redundant reconnect after connect already replaces each role's socket. Preserve authentication, scopes and physical connection leases, with a controlled real-WebSocket regression.

Closes #131459
2026-08-29 14:47:55 -07:00
Harjoth Khara
3be7baa1a3
fix(macos): timestamp hash-pinned Developer ID signatures (#118989)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-26 10:39:41 -07:00
Peter Steinberger
04c9924c45
fix(macos): keep elevation host CUA-free (#125408)
* fix(macos): isolate elevation host from CUA

* fix(macos): fail closed on unsafe elevation rollback

* fix(macos): quarantine unsafe elevation state before recovery

* fix(macos): bind elevation recovery ownership
2026-08-17 17:03:04 -07:00
Peter Steinberger
49af98c12b
fix(macos): avoid codesign metadata SIGPIPE (#125281) 2026-08-17 09:17:47 -07:00
Peter Steinberger
3744af3d44
improve(mac): guard elevation signing identity against drift (#123764)
scripts/mac-elevation-host.sh ships as the portable installer added in
#123675, so it is deliberately self-contained and cannot source shared
constants. That forces it to duplicate ELEVATION_TEAM_ID and
ELEVATION_IDENTITY from scripts/codesign-mac-app.sh, with nothing keeping
the two copies in sync. Add a test asserting they agree, so rotation drift
fails at build time instead of on a target Mac.

Also document why the sign-time and install-time elevation verification
functions both exist: verify_elevation_app requires a notarized and stapled
bundle, so it cannot replace the sign-time check, and deleting that check
would defer every identity failure until after a notarization submission is
already spent.

No behavior change: no artifact bytes, filenames, modes, receipt fields,
signing, notarization, or install paths are touched.
2026-08-14 12:50:57 -07:00
Peter Steinberger
19ace6830b
feat(macos): add embedded CUA computer provider (#123635)
* feat(macos): embed CUA computer provider

* fix(macos): clarify embedded CUA trust posture

* fix(macos): contain embedded CUA daemon lifecycle

* fix(macos): reap orphaned CUA daemons

* fix(macos): record the spawned CUA daemon pid so reaping can terminate orphans

* chore(macos): refresh native i18n baseline for the computer control provider picker

* style(macos): satisfy swiftlint on the embedded CUA host and connect params

* refactor(gateway): move optional connect params to GatewayConnectOptions
2026-08-14 10:24:08 -07:00
Peter Steinberger
44dd983c0c
feat(mac): add canonical elevation host workflow (#123569)
* feat(mac): add canonical elevation host workflow

* fix(mac): clarify elevation host deployment

* test(ui): stabilize cloud startup effort flow

* fix(mac): fail closed on unknown TCC status

* test: synchronize async CI boundaries

* test: remove remaining CI timing races
2026-08-14 05:39:24 -07:00
Peter Steinberger
737982d5fe
fix(macos): adopt Peekaboo 4.1 bridge contracts (#123420)
* feat(macos): adopt checked Peekaboo bridge runtime

* fix(macos): preserve bridge snapshot retention

* docs(macos): clarify bridge client identity

* fix(macos): retry transient timestamp signing

* build(macos): pin embedded Peekaboo runtime

* fix(macos): expose embedded bridge source identity

* test(macos): isolate gateway launch agent hooks

(cherry picked from commit 7da18c5fee43fed7e8dfa42c4851f99d035b2a36)

* test(macos): pin gateway command mode

* fix(macos): preserve Peekaboo bridge provenance
2026-08-13 22:03:47 -07:00
Vincent Koc
e59d0b540e
fix(mac): reject invalid codesign args 2026-06-20 21:41:34 +02:00
Vincent Koc
e8cb2b5ab3
fix(mac): remove unused codesign entitlements 2026-05-26 12:19:42 +02:00
Vincent Koc
68f877ef66
fix(mac): clean codesign entitlement temps 2026-05-26 12:06:18 +02:00
Peter Steinberger
9fe74e391d
fix(macos): sign mlx tts helper before app binary 2026-04-23 16:49:53 +01:00
Peter Steinberger
e836b5b6d7
ci: isolate mlx from macos swift checks 2026-04-22 02:12:07 +01:00
Peter Steinberger
9a7160786a refactor: rename to openclaw 2026-01-30 03:16:21 +01:00
Peter Steinberger
6d16a658e5 refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
Peter Steinberger
8a20f44228 fix: improve gateway ssh auth handling 2026-01-22 06:54:08 +00:00
Peter Steinberger
50049fd220 chore(macos): drop time-sensitive notification entitlement toggle 2026-01-22 04:50:03 +00:00
Peter Steinberger
0b350d78d5 fix: harden macOS signing flow 2026-01-18 16:28:39 +00:00
Peter Steinberger
16bc4cdef3 chore: drop legacy Relay signing 2026-01-16 03:11:16 +00:00
Peter Steinberger
21ba04755b fix(macos): onboarding location + layout 2026-01-11 01:36:00 +01:00
Peter Steinberger
449bee9645 fix: bundle node runtime for mac app 2026-01-10 15:28:37 +01:00
Peter Steinberger
246adaa119 chore: rename project to clawdbot 2026-01-04 14:38:51 +00:00
Peter Steinberger
641080a0b6 fix: document macOS permission requirements 2026-01-03 20:05:22 +01:00
Jake
99c3fc1128 Scripts: Make ad-hoc fallback opt-in with stronger TCC warnings 2026-01-03 20:05:22 +01:00
Jake
8c7b2aa2d3 Scripts: Fallback to ad-hoc signing in codesign-mac-app.sh 2026-01-03 20:05:22 +01:00
Peter Steinberger
2a6248dad6 fix: add camera entitlement to macOS signing 2026-01-02 17:31:59 +01:00
Petter Blomberg
fe5e58af91 scripts: fix ad-hoc signing crashes and bash unbound variable error 2026-01-01 15:29:01 +01:00
Josh Palmer
ced271bec1 chore(macos): harden mktemp templates in codesign 2025-12-29 17:49:13 +01:00
Peter Steinberger
c54e4d0900 refactor: node tools and canvas host url 2025-12-27 01:36:29 +01:00
Peter Steinberger
02787b5674 build(mac): add notarize flow for release artifacts 2025-12-21 12:33:45 +01:00
Peter Steinberger
405ff0377a refactor(macos): bundle single relay binary 2025-12-20 19:35:30 +00:00
Peter Steinberger
849446ae17 refactor(cli): unify on clawdis CLI + node permissions 2025-12-20 02:08:04 +00:00
Peter Steinberger
2ef2136c2c fix(macos): sign bun gateway with jit entitlements 2025-12-19 19:24:49 +01:00
Peter Steinberger
98bbc73925 build(macos): bundle bun gateway 2025-12-19 19:21:26 +01:00
Peter Steinberger
bf41197b97 fix(mac): open settings for microphone permission 2025-12-12 19:25:21 +00:00
Peter Steinberger
e2ad0ed9f7 fix(mac): disable restricted time-sensitive entitlement 2025-12-12 19:20:47 +00:00
Peter Steinberger
d2158966db fix(mac): treat timeSensitive as best-effort 2025-12-12 18:58:07 +00:00
Peter Steinberger
337ae05ed8 build(mac): enable time-sensitive notifications 2025-12-12 18:40:09 +00:00
Peter Steinberger
a3bf2bdd8c chore: rename relay to gateway 2025-12-09 18:00:01 +00:00
Peter Steinberger
cf36f5a23b chore: guard host runtime and simplify packaging 2025-12-09 00:59:56 +01:00
Peter Steinberger
ddbe680a58 feat(macos): add Sparkle updates and release docs 2025-12-08 00:18:16 +01:00
Peter Steinberger
7efa152418 VoiceWake: document escape path and reset stale forward command 2025-12-07 18:23:34 +01:00
Peter Steinberger
f23b16db2b build: require signing identity for mac packaging 2025-12-07 04:38:45 +01:00
Peter Steinberger
21bb2fb03f Mac: add mic entitlement to signing helper 2025-12-06 23:52:54 +00:00
Peter Steinberger
b2e3013898 mac: add signing helper and document debug bundle 2025-12-07 00:30:58 +01:00