mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed. Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes. * fix(scripts): keep guarded portable scripts bash 3.2 compatible * fix(scripts): keep macOS Bash CI coverage green Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap. Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required. * docs(install): use system Bash in install and recovery commands Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body. Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock. * fix(scripts): preserve streamed installs and CI packing Keep public installer commands portable while replaying Darwin Bash 5.3+ stdin under system Bash through an immediately unlinked private temp file. Retain actionable sourced-install rejection and the SC2317-safe check. Restore the original CI packing policy and move the Bash policy scan into its existing macOS tooling owner without adding a routed test file. Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing tests; 23 selected installer tests under both PATH orders; planner cap and coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests; focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
125 lines
3.8 KiB
Bash
125 lines
3.8 KiB
Bash
#!/usr/bin/env bash
|
|
# Bash 5.3+ can deadlock writing heredoc pipes on macOS before the reader starts.
|
|
if [[ ${OSTYPE:-} == darwin* && $BASH != /bin/bash ]] && ((BASH_VERSINFO[0] > 5 || (BASH_VERSINFO[0] == 5 && BASH_VERSINFO[1] >= 3))); then
|
|
exec /bin/bash "$0" "$@"
|
|
fi
|
|
set -euo pipefail
|
|
|
|
profile_path="${1:-${RUNNER_TEMP:-/tmp}/openclaw-live.profile}"
|
|
|
|
mkdir -p "$(dirname "$profile_path")"
|
|
: >"$profile_path"
|
|
chmod 600 "$profile_path"
|
|
|
|
append_profile_env() {
|
|
local key="$1"
|
|
local value="${!key:-}"
|
|
if [[ -z "$value" || "$value" == "undefined" || "$value" == "null" ]]; then
|
|
return
|
|
fi
|
|
printf 'export %s=%q\n' "$key" "$value" >>"$profile_path"
|
|
}
|
|
|
|
write_secret_file() {
|
|
local destination="$1"
|
|
local source_env="$2"
|
|
local value="${!source_env:-}"
|
|
if [[ -z "$value" ]]; then
|
|
return
|
|
fi
|
|
mkdir -p "$(dirname "$destination")"
|
|
printf '%s' "$value" >"$destination"
|
|
chmod 600 "$destination"
|
|
}
|
|
|
|
activate_claude_oauth_access_token() {
|
|
local credentials="${OPENCLAW_CLAUDE_CREDENTIALS_JSON:-}"
|
|
if [[ -z "$credentials" ]]; then
|
|
return
|
|
fi
|
|
|
|
local access_token expires_at now_ms
|
|
local min_remaining_ms="$(( 90 * 60 * 1000 ))"
|
|
access_token="$(jq -r '.claudeAiOauth.accessToken // empty' <<<"$credentials" 2>/dev/null || true)"
|
|
expires_at="$(jq -r '.claudeAiOauth.expiresAt // 0' <<<"$credentials" 2>/dev/null || true)"
|
|
now_ms="$(( $(date +%s) * 1000 ))"
|
|
|
|
if [[ "$access_token" != sk-ant-oat* ]]; then
|
|
echo "::warning::Claude credentials JSON has no usable OAuth access token; keeping the configured Anthropic fallback." >&2
|
|
return
|
|
fi
|
|
# Stable live shards can run for an hour, so never shadow the fallback with
|
|
# a token that could expire before setup, retries, and cleanup complete.
|
|
if ! [[ "$expires_at" =~ ^[0-9]+$ ]] || (( expires_at <= now_ms + min_remaining_ms )); then
|
|
echo "::warning::Claude credentials JSON OAuth access token lacks 90 minutes of remaining life; keeping the configured Anthropic fallback." >&2
|
|
return
|
|
fi
|
|
|
|
echo "::add-mask::$access_token"
|
|
export ANTHROPIC_OAUTH_TOKEN="$access_token"
|
|
if [[ -n "${GITHUB_ENV:-}" ]]; then
|
|
printf 'ANTHROPIC_OAUTH_TOKEN=%s\n' "$access_token" >>"$GITHUB_ENV"
|
|
fi
|
|
}
|
|
|
|
activate_claude_oauth_access_token
|
|
|
|
for env_key in \
|
|
OPENAI_API_KEY \
|
|
OPENAI_BASE_URL \
|
|
ANTHROPIC_OAUTH_TOKEN \
|
|
ANTHROPIC_API_KEY \
|
|
ANTHROPIC_API_KEY_OLD \
|
|
ANTHROPIC_API_TOKEN \
|
|
BYTEPLUS_API_KEY \
|
|
CEREBRAS_API_KEY \
|
|
DEEPINFRA_API_KEY \
|
|
DEEPSEEK_API_KEY \
|
|
DASHSCOPE_API_KEY \
|
|
GROQ_API_KEY \
|
|
KIMI_API_KEY \
|
|
MODELSTUDIO_API_KEY \
|
|
MOONSHOT_API_KEY \
|
|
MISTRAL_API_KEY \
|
|
MINIMAX_API_KEY \
|
|
OPENCODE_API_KEY \
|
|
OPENCODE_ZEN_API_KEY \
|
|
OPENCLAW_LIVE_BROWSER_CDP_URL \
|
|
OPENCLAW_LIVE_SETUP_TOKEN \
|
|
OPENCLAW_LIVE_SETUP_TOKEN_MODEL \
|
|
OPENCLAW_LIVE_SETUP_TOKEN_PROFILE \
|
|
OPENCLAW_LIVE_SETUP_TOKEN_VALUE \
|
|
FACTORY_API_KEY \
|
|
GEMINI_API_KEY \
|
|
GOOGLE_API_KEY \
|
|
OPENROUTER_API_KEY \
|
|
QWEN_API_KEY \
|
|
FAL_KEY \
|
|
RUNWAY_API_KEY \
|
|
DEEPGRAM_API_KEY \
|
|
TOGETHER_API_KEY \
|
|
VYDRA_API_KEY \
|
|
XAI_API_KEY \
|
|
ZAI_API_KEY \
|
|
Z_AI_API_KEY \
|
|
BYTEPLUS_ACCESS_KEY_ID \
|
|
BYTEPLUS_SECRET_ACCESS_KEY \
|
|
CLAUDE_CODE_OAUTH_TOKEN \
|
|
FIREWORKS_API_KEY
|
|
do
|
|
append_profile_env "$env_key"
|
|
done
|
|
|
|
write_secret_file "$HOME/.codex/auth.json" OPENCLAW_CODEX_AUTH_JSON
|
|
write_secret_file "$HOME/.codex/config.toml" OPENCLAW_CODEX_CONFIG_TOML
|
|
write_secret_file "$HOME/.claude.json" OPENCLAW_CLAUDE_JSON
|
|
write_secret_file "$HOME/.claude/.credentials.json" OPENCLAW_CLAUDE_CREDENTIALS_JSON
|
|
write_secret_file "$HOME/.claude/settings.json" OPENCLAW_CLAUDE_SETTINGS_JSON
|
|
write_secret_file "$HOME/.claude/settings.local.json" OPENCLAW_CLAUDE_SETTINGS_LOCAL_JSON
|
|
write_secret_file "$HOME/.gemini/settings.json" OPENCLAW_GEMINI_SETTINGS_JSON
|
|
|
|
if [[ -n "${GITHUB_ENV:-}" ]]; then
|
|
{
|
|
echo "OPENCLAW_PROFILE_FILE=$profile_path"
|
|
} >>"$GITHUB_ENV"
|
|
fi
|