mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed. Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes. * fix(scripts): keep guarded portable scripts bash 3.2 compatible * fix(scripts): keep macOS Bash CI coverage green Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap. Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required. * docs(install): use system Bash in install and recovery commands Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body. Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock. * fix(scripts): preserve streamed installs and CI packing Keep public installer commands portable while replaying Darwin Bash 5.3+ stdin under system Bash through an immediately unlinked private temp file. Retain actionable sourced-install rejection and the SC2317-safe check. Restore the original CI packing policy and move the Bash policy scan into its existing macOS tooling owner without adding a routed test file. Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing tests; 23 selected installer tests under both PATH orders; planner cap and coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests; focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
95 lines
2.4 KiB
Bash
Executable file
95 lines
2.4 KiB
Bash
Executable file
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
usage() {
|
|
cat <<'EOF'
|
|
Usage:
|
|
scripts/apple-release-source-check.sh --root <repository> --expected-commit <full-sha>
|
|
|
|
Verifies an Apple release build uses the clean checkout at the selected commit.
|
|
EOF
|
|
}
|
|
|
|
EXPECTED_COMMIT=""
|
|
ROOT_DIR=""
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
source "${SCRIPT_DIR}/lib/build-metadata.sh"
|
|
|
|
require_option_value() {
|
|
local option="$1"
|
|
local value="${2-}"
|
|
|
|
if [[ -z "${value}" || "${value}" == --* ]]; then
|
|
echo "Missing value for ${option}." >&2
|
|
usage >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
while [[ $# -gt 0 ]]; do
|
|
case "$1" in
|
|
--expected-commit)
|
|
require_option_value "$1" "${2-}"
|
|
EXPECTED_COMMIT="$2"
|
|
shift 2
|
|
;;
|
|
--root)
|
|
require_option_value "$1" "${2-}"
|
|
ROOT_DIR="$2"
|
|
shift 2
|
|
;;
|
|
-h | --help)
|
|
usage
|
|
exit 0
|
|
;;
|
|
*)
|
|
echo "Unknown argument: $1" >&2
|
|
usage >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
done
|
|
|
|
if [[ -z "${ROOT_DIR}" ]]; then
|
|
echo "Missing required --root." >&2
|
|
usage >&2
|
|
exit 1
|
|
fi
|
|
if [[ -z "${EXPECTED_COMMIT}" ]]; then
|
|
echo "Missing required --expected-commit." >&2
|
|
usage >&2
|
|
exit 1
|
|
fi
|
|
|
|
EXPECTED_COMMIT="$(openclaw_trim_build_metadata_value "${EXPECTED_COMMIT}")"
|
|
if ! openclaw_is_full_git_commit "${EXPECTED_COMMIT}"; then
|
|
echo "Apple release commit must be a full 40-character hexadecimal SHA." >&2
|
|
exit 1
|
|
fi
|
|
EXPECTED_COMMIT="$(printf '%s' "${EXPECTED_COMMIT}" | tr '[:upper:]' '[:lower:]')"
|
|
|
|
if ! CHECKOUT_COMMIT="$(git -C "${ROOT_DIR}" rev-parse --verify HEAD 2>/dev/null)"; then
|
|
echo "Apple release builds require a readable Git checkout." >&2
|
|
exit 1
|
|
fi
|
|
if ! openclaw_is_full_git_commit "${CHECKOUT_COMMIT}"; then
|
|
echo "Apple release checkout HEAD must be a full Git commit." >&2
|
|
exit 1
|
|
fi
|
|
CHECKOUT_COMMIT="$(printf '%s' "${CHECKOUT_COMMIT}" | tr '[:upper:]' '[:lower:]')"
|
|
|
|
if [[ "${EXPECTED_COMMIT}" != "${CHECKOUT_COMMIT}" ]]; then
|
|
echo "Apple release commit mismatch: metadata ${EXPECTED_COMMIT}, checkout ${CHECKOUT_COMMIT}." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! CHECKOUT_STATUS="$(git -C "${ROOT_DIR}" status --porcelain=v1 --untracked-files=all 2>/dev/null)"; then
|
|
echo "Apple release builds require a readable Git checkout." >&2
|
|
exit 1
|
|
fi
|
|
if [[ -n "${CHECKOUT_STATUS}" ]]; then
|
|
echo "Apple release builds require a clean Git checkout." >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Verified Apple release source: commit=${CHECKOUT_COMMIT} clean=true"
|