mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-11 23:49:01 +02:00
fix(setup): Ubuntu 26.04 Playwright platform detect + silence the codesign false alarm
Two small setup papercuts: the Playwright platform probe now recognizes Ubuntu 26.04 instead of falling to the generic-Linux path, and macOS installs stop warning about a codesign "failure" that was actually the expected unsigned-adhoc path (the real signature check already gates binary launch). Contributed by @nuga0718 (PR #2113) and @lucascaro (PR #1758). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
4c4584db12
commit
0295b74b24
@@ -447,14 +447,46 @@ if [ "$NEEDS_BUILD" -eq 1 ]; then
|
||||
# macOS kills with SIGKILL (exit 137). The two-step remove+re-sign is
|
||||
# required because a naive `codesign -s - -f` fails when the existing
|
||||
# signature block is corrupt. This is idempotent and costs <1s.
|
||||
#
|
||||
# Some binaries (observed: find-browse, gstack-global-discover) also carry
|
||||
# trailing zero-padding AFTER the Mach-O LC_CODE_SIGNATURE region. macOS
|
||||
# codesign requires the signature to be the last content and extend to EOF,
|
||||
# so the padding triggers "main executable failed strict validation" on
|
||||
# re-sign (and "internal error in Code Signing subsystem" on remove). We
|
||||
# truncate that trailing slack to the end of LC_CODE_SIGNATURE first, which
|
||||
# lets the identical re-sign succeed. The binary runs either way: Bun's
|
||||
# adhoc code-page signature satisfies the kernel's exec check even when
|
||||
# `codesign --verify` is unhappy, so a re-sign failure only warns when the
|
||||
# binary is genuinely SIGKILL'd on exec (exit 137).
|
||||
# See: https://github.com/garrytan/gstack/issues/997
|
||||
if [ "$(uname -s)" = "Darwin" ] && [ "$(uname -m)" = "arm64" ]; then
|
||||
for _bin in browse/dist/browse browse/dist/find-browse design/dist/design make-pdf/dist/pdf bin/gstack-global-discover; do
|
||||
_bin_path="$SOURCE_GSTACK_DIR/$_bin"
|
||||
[ -f "$_bin_path" ] && [ -x "$_bin_path" ] || continue
|
||||
# Strip any trailing bytes past LC_CODE_SIGNATURE so codesign can re-sign.
|
||||
# otool prints the signature's dataoff+datasize; if the file is larger,
|
||||
# the extra bytes are Bun padding that breaks strict validation.
|
||||
_sig_end=$(otool -l "$_bin_path" 2>/dev/null | awk '/LC_CODE_SIGNATURE/{f=1} f&&/dataoff/{o=$2} f&&/datasize/{print o+$2; exit}')
|
||||
_fsize=$(stat -f%z "$_bin_path" 2>/dev/null)
|
||||
if [ -n "$_sig_end" ] && [ -n "$_fsize" ] && [ "$_sig_end" -gt 0 ] 2>/dev/null && [ "$_sig_end" -lt "$_fsize" ] 2>/dev/null; then
|
||||
_trunc_tmp=$(mktemp 2>/dev/null) || _trunc_tmp=""
|
||||
if [ -n "$_trunc_tmp" ] && head -c "$_sig_end" "$_bin_path" > "$_trunc_tmp" 2>/dev/null; then
|
||||
cat "$_trunc_tmp" > "$_bin_path" && chmod +x "$_bin_path"
|
||||
fi
|
||||
[ -n "$_trunc_tmp" ] && rm -f "$_trunc_tmp"
|
||||
fi
|
||||
codesign --remove-signature "$_bin_path" 2>/dev/null || true
|
||||
if ! codesign -s - -f "$_bin_path" 2>/dev/null; then
|
||||
log "warning: codesign failed for $_bin (binary may not run on Apple Silicon)"
|
||||
# Re-sign failed. Only warn if the binary genuinely cannot execute
|
||||
# (SIGKILL = exit 137). Otherwise Bun's adhoc code-page signature still
|
||||
# runs fine and the codesign --verify miss is cosmetic. set -e safe.
|
||||
_probe_rc=0
|
||||
"$_bin_path" --help >/dev/null 2>&1 || _probe_rc=$?
|
||||
if [ "$_probe_rc" -eq 137 ]; then
|
||||
log "warning: codesign failed for $_bin and it is SIGKILL'd on exec (exit 137) — it may not run on Apple Silicon"
|
||||
else
|
||||
log "note: codesign could not re-sign $_bin, but it executes fine (Bun adhoc signature); continuing"
|
||||
fi
|
||||
fi
|
||||
done
|
||||
fi
|
||||
@@ -520,11 +552,29 @@ if [ "$INSTALL_OPENCODE" -eq 1 ] && [ "$NEEDS_BUILD" -eq 0 ]; then
|
||||
fi
|
||||
|
||||
# 2. Ensure Playwright's Chromium is available
|
||||
# Detect Ubuntu 26.04: Playwright does not yet ship a native chromium build for
|
||||
# ubuntu26.04-x64. Override the platform to ubuntu24.04-x64 so the installer
|
||||
# picks the correct binary. This is safe because the ubuntu24.04 build runs
|
||||
# fine on ubuntu26.04 (same glibc lineage). See #2101.
|
||||
_PLAYWRIGHT_PLATFORM_OVERRIDE=""
|
||||
if [ -f /etc/os-release ]; then
|
||||
_os_id=$(grep '^ID=' /etc/os-release | cut -d= -f2 | tr -d '"')
|
||||
_os_ver=$(grep '^VERSION_ID=' /etc/os-release | cut -d= -f2 | tr -d '"')
|
||||
if [ "$_os_id" = "ubuntu" ] && [ "$_os_ver" = "26.04" ]; then
|
||||
_PLAYWRIGHT_PLATFORM_OVERRIDE="ubuntu24.04-x64"
|
||||
echo "Ubuntu 26.04 detected — using PLAYWRIGHT_HOST_PLATFORM_OVERRIDE=$_PLAYWRIGHT_PLATFORM_OVERRIDE"
|
||||
fi
|
||||
fi
|
||||
|
||||
if ! ensure_playwright_browser; then
|
||||
echo "Installing Playwright Chromium..."
|
||||
(
|
||||
cd "$SOURCE_GSTACK_DIR"
|
||||
bunx playwright install chromium
|
||||
if [ -n "$_PLAYWRIGHT_PLATFORM_OVERRIDE" ]; then
|
||||
PLAYWRIGHT_HOST_PLATFORM_OVERRIDE="$_PLAYWRIGHT_PLATFORM_OVERRIDE" bunx playwright install chromium
|
||||
else
|
||||
bunx playwright install chromium
|
||||
fi
|
||||
)
|
||||
|
||||
if [ "$IS_WINDOWS" -eq 1 ]; then
|
||||
|
||||
Reference in New Issue
Block a user