mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed. Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes. * fix(scripts): keep guarded portable scripts bash 3.2 compatible * fix(scripts): keep macOS Bash CI coverage green Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap. Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required. * docs(install): use system Bash in install and recovery commands Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body. Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock. * fix(scripts): preserve streamed installs and CI packing Keep public installer commands portable while replaying Darwin Bash 5.3+ stdin under system Bash through an immediately unlinked private temp file. Retain actionable sourced-install rejection and the SC2317-safe check. Restore the original CI packing policy and move the Bash policy scan into its existing macOS tooling owner without adding a routed test file. Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing tests; 23 selected installer tests under both PATH orders; planner cap and coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests; focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
54 lines
2.3 KiB
Bash
Executable file
54 lines
2.3 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Bash 5.3+ can deadlock writing heredoc pipes on macOS before the reader starts.
|
|
if [[ ${OSTYPE:-} == darwin* && $BASH != /bin/bash ]] && ((BASH_VERSINFO[0] > 5 || (BASH_VERSINFO[0] == 5 && BASH_VERSINFO[1] >= 3))); then
|
|
exec /bin/bash "$0" "$@"
|
|
fi
|
|
set -euo pipefail
|
|
|
|
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
source "$ROOT_DIR/scripts/lib/docker-build.sh"
|
|
|
|
BASE_IMAGE="${BASE_IMAGE:-openclaw-sandbox:bookworm-slim}"
|
|
TARGET_IMAGE="${TARGET_IMAGE:-openclaw-sandbox-common:bookworm-slim}"
|
|
PACKAGES="${PACKAGES:-curl wget jq coreutils grep python3 git ca-certificates golang-go rustc cargo unzip pkg-config libasound2-dev build-essential file}"
|
|
INSTALL_NODE="${INSTALL_NODE:-1}"
|
|
NODE_MAJOR="${NODE_MAJOR:-24}"
|
|
INSTALL_PNPM="${INSTALL_PNPM:-1}"
|
|
INSTALL_BUN="${INSTALL_BUN:-1}"
|
|
BUN_INSTALL_DIR="${BUN_INSTALL_DIR:-/opt/bun}"
|
|
INSTALL_BREW="${INSTALL_BREW:-1}"
|
|
BREW_INSTALL_DIR="${BREW_INSTALL_DIR:-/home/linuxbrew/.linuxbrew}"
|
|
FINAL_USER="${FINAL_USER:-sandbox}"
|
|
OPENCLAW_DOCKER_BUILD_USE_BUILDX="${OPENCLAW_DOCKER_BUILD_USE_BUILDX:-0}"
|
|
OPENCLAW_DOCKER_BUILD_CACHE_FROM="${OPENCLAW_DOCKER_BUILD_CACHE_FROM:-}"
|
|
OPENCLAW_DOCKER_BUILD_CACHE_TO="${OPENCLAW_DOCKER_BUILD_CACHE_TO:-}"
|
|
|
|
if ! docker image inspect "${BASE_IMAGE}" >/dev/null 2>&1; then
|
|
echo "Base image missing: ${BASE_IMAGE}"
|
|
echo "Building base image via scripts/sandbox-setup.sh..."
|
|
"$ROOT_DIR/scripts/sandbox-setup.sh"
|
|
fi
|
|
|
|
echo "Building ${TARGET_IMAGE} with: ${PACKAGES}"
|
|
|
|
docker_build_exec \
|
|
-t "${TARGET_IMAGE}" \
|
|
-f "$ROOT_DIR/scripts/docker/sandbox/Dockerfile.common" \
|
|
--build-arg BASE_IMAGE="${BASE_IMAGE}" \
|
|
--build-arg PACKAGES="${PACKAGES}" \
|
|
--build-arg INSTALL_NODE="${INSTALL_NODE}" \
|
|
--build-arg NODE_MAJOR="${NODE_MAJOR}" \
|
|
--build-arg INSTALL_PNPM="${INSTALL_PNPM}" \
|
|
--build-arg INSTALL_BUN="${INSTALL_BUN}" \
|
|
--build-arg BUN_INSTALL_DIR="${BUN_INSTALL_DIR}" \
|
|
--build-arg INSTALL_BREW="${INSTALL_BREW}" \
|
|
--build-arg BREW_INSTALL_DIR="${BREW_INSTALL_DIR}" \
|
|
--build-arg FINAL_USER="${FINAL_USER}" \
|
|
"$ROOT_DIR"
|
|
|
|
cat <<NOTE
|
|
Built ${TARGET_IMAGE}.
|
|
To use it, set agents.defaults.sandbox.docker.image to "${TARGET_IMAGE}" and restart.
|
|
If you want a clean re-create, remove old sandbox containers:
|
|
docker rm -f \$(docker ps -aq --filter label=openclaw.sandbox=1)
|
|
NOTE
|