mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed. Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes. * fix(scripts): keep guarded portable scripts bash 3.2 compatible * fix(scripts): keep macOS Bash CI coverage green Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap. Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required. * docs(install): use system Bash in install and recovery commands Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body. Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock. * fix(scripts): preserve streamed installs and CI packing Keep public installer commands portable while replaying Darwin Bash 5.3+ stdin under system Bash through an immediately unlinked private temp file. Retain actionable sourced-install rejection and the SC2317-safe check. Restore the original CI packing policy and move the Bash policy scan into its existing macOS tooling owner without adding a routed test file. Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing tests; 23 selected installer tests under both PATH orders; planner cap and coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests; focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
133 lines
4.3 KiB
Bash
Executable file
133 lines
4.3 KiB
Bash
Executable file
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
ROOT=$(cd "$(dirname "$0")/.." && pwd)
|
|
ZIP=${1:?"Usage: $0 OpenClaw-<ver>.zip"}
|
|
FEED_URL=${2:-"https://raw.githubusercontent.com/openclaw/openclaw/main/appcast.xml"}
|
|
PRIVATE_KEY_FILE=${SPARKLE_PRIVATE_KEY_FILE:-}
|
|
|
|
find_generate_appcast() {
|
|
if [[ -n "${SPARKLE_GENERATE_APPCAST:-}" ]]; then
|
|
if [[ ! -x "$SPARKLE_GENERATE_APPCAST" ]]; then
|
|
echo "SPARKLE_GENERATE_APPCAST is not executable: $SPARKLE_GENERATE_APPCAST" >&2
|
|
return 1
|
|
fi
|
|
printf '%s\n' "$SPARKLE_GENERATE_APPCAST"
|
|
return 0
|
|
fi
|
|
|
|
local host_arch bundled_root bundled_tool
|
|
host_arch="$(uname -m)"
|
|
bundled_root="$ROOT/apps/macos/.build/$host_arch"
|
|
if [[ -d "$bundled_root" ]]; then
|
|
bundled_tool="$(find "$bundled_root" -type f -path "*/artifacts/sparkle/Sparkle/bin/generate_appcast" -print -quit)"
|
|
if [[ -n "$bundled_tool" ]]; then
|
|
printf '%s\n' "$bundled_tool"
|
|
return 0
|
|
fi
|
|
fi
|
|
|
|
if command -v generate_appcast >/dev/null 2>&1; then
|
|
command -v generate_appcast
|
|
return 0
|
|
fi
|
|
|
|
if [[ -d "$ROOT/apps/macos/.build" ]]; then
|
|
find "$ROOT/apps/macos/.build" -type f -path "*/artifacts/sparkle/Sparkle/bin/generate_appcast" -print -quit
|
|
fi
|
|
return 0
|
|
}
|
|
|
|
if [[ -z "$PRIVATE_KEY_FILE" ]]; then
|
|
echo "Set SPARKLE_PRIVATE_KEY_FILE to your ed25519 private key (Sparkle)." >&2
|
|
exit 1
|
|
fi
|
|
if [[ ! -f "$ZIP" ]]; then
|
|
echo "Zip not found: $ZIP" >&2
|
|
exit 1
|
|
fi
|
|
|
|
ZIP_DIR=$(cd "$(dirname "$ZIP")" && pwd)
|
|
ZIP_NAME=$(basename "$ZIP")
|
|
ZIP_BASE="${ZIP_NAME%.zip}"
|
|
VERSION=${SPARKLE_RELEASE_VERSION:-}
|
|
if [[ -z "$VERSION" ]]; then
|
|
# Accept legacy calver suffixes like -1 and prerelease forms like -alpha.1 / -beta.1 / .beta.1.
|
|
if [[ "$ZIP_NAME" =~ ^OpenClaw-([0-9]+(\.[0-9]+){1,2}([-.][0-9A-Za-z]+([.-][0-9A-Za-z]+)*)?)\.zip$ ]]; then
|
|
VERSION="${BASH_REMATCH[1]}"
|
|
else
|
|
echo "Could not infer version from $ZIP_NAME; set SPARKLE_RELEASE_VERSION." >&2
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
# Bash 3.2 treats an empty array as unset under nounset, so keep a required option.
|
|
APPCAST_ARGS=(--embed-release-notes)
|
|
if [[ "$VERSION" == *-alpha.* || "$VERSION" == *.alpha.* ]]; then
|
|
echo "Alpha releases do not ship via Sparkle: $VERSION" >&2
|
|
exit 1
|
|
fi
|
|
if [[ "$VERSION" == *-beta.* || "$VERSION" == *.beta.* ]]; then
|
|
APPCAST_ARGS+=(--channel beta)
|
|
elif [[ "$VERSION" =~ ^[0-9]{4}\.[1-9][0-9]*\.([0-9]+)$ && "${BASH_REMATCH[1]}" -ge 33 ]]; then
|
|
APPCAST_ARGS+=(--channel extended-stable)
|
|
fi
|
|
|
|
TMP_DIR="$(mktemp -d)"
|
|
NOTES_HTML=""
|
|
cleanup() {
|
|
rm -rf "$TMP_DIR"
|
|
if [[ -n "$NOTES_HTML" && "${KEEP_SPARKLE_NOTES:-0}" != "1" ]]; then
|
|
rm -f "$NOTES_HTML"
|
|
fi
|
|
}
|
|
trap cleanup EXIT
|
|
cp -f "$ZIP" "$TMP_DIR/$ZIP_NAME"
|
|
if [[ -f "$ROOT/appcast.xml" ]]; then
|
|
cp -f "$ROOT/appcast.xml" "$TMP_DIR/appcast.xml"
|
|
fi
|
|
|
|
NOTES_HTML="${ZIP_DIR}/${ZIP_BASE}.html"
|
|
if [[ -x "$ROOT/scripts/changelog-to-html.sh" ]]; then
|
|
"$ROOT/scripts/changelog-to-html.sh" "$VERSION" >"$NOTES_HTML"
|
|
else
|
|
echo "Missing scripts/changelog-to-html.sh; cannot generate HTML release notes." >&2
|
|
exit 1
|
|
fi
|
|
cp -f "$NOTES_HTML" "$TMP_DIR/${ZIP_BASE}.html"
|
|
|
|
DOWNLOAD_URL_PREFIX=${SPARKLE_DOWNLOAD_URL_PREFIX:-"https://github.com/openclaw/openclaw/releases/download/v${VERSION}/"}
|
|
|
|
GENERATE_APPCAST="$(find_generate_appcast)"
|
|
if [[ -z "$GENERATE_APPCAST" ]]; then
|
|
echo "generate_appcast not found. Install Sparkle tooling or build the mac app first so SwiftPM emits the Sparkle binaries." >&2
|
|
exit 1
|
|
fi
|
|
|
|
"$GENERATE_APPCAST" \
|
|
--ed-key-file "$PRIVATE_KEY_FILE" \
|
|
--download-url-prefix "$DOWNLOAD_URL_PREFIX" \
|
|
--link "$FEED_URL" \
|
|
"${APPCAST_ARGS[@]}" \
|
|
"$TMP_DIR"
|
|
|
|
APPCAST_PATH="$TMP_DIR/appcast.xml" APPCAST_VERSION="$VERSION" node <<'NODE'
|
|
const { readFileSync } = require("node:fs");
|
|
|
|
const appcastPath = process.env.APPCAST_PATH;
|
|
const version = process.env.APPCAST_VERSION;
|
|
const appcast = readFileSync(appcastPath, "utf8");
|
|
const item = [...appcast.matchAll(/<item(?:\s[^>]*)?>([\s\S]*?)<\/item>/gu)].find((match) =>
|
|
match[1]?.includes(`<sparkle:shortVersionString>${version}</sparkle:shortVersionString>`),
|
|
);
|
|
if (!item) {
|
|
throw new Error(`Generated appcast is missing release ${version}.`);
|
|
}
|
|
if (!/sparkle:edSignature="[^"]+"/u.test(item[1] ?? "")) {
|
|
throw new Error(`Generated appcast release ${version} is missing sparkle:edSignature.`);
|
|
}
|
|
NODE
|
|
|
|
cp -f "$TMP_DIR/appcast.xml" "$ROOT/appcast.xml"
|
|
|
|
echo "Appcast generated (appcast.xml). Upload alongside $ZIP at $FEED_URL"
|