mirror of
https://github.com/openai/codex.git
synced 2026-08-23 13:09:46 +00:00
Sign bundled macOS helper binaries (#35264)
## Why The macOS release workflow fetched `rg` and zsh while assembling package archives, after the signing stage. This left the bundled helper executables outside the workflow's signing and notarization checks. ## What changed - Fetch, sign, notarize, and upload the pinned macOS `rg` and zsh binaries with the other release artifacts. - Build package archives from those signed helpers via `--rg-bin` and the new `--zsh-bin` override. - Verify the helpers' architecture, signatures, and absence of entitlements in the final package. ## Testing - Cover the prebuilt zsh override and verify that package assembly preserves the supplied helper binaries. GitOrigin-RevId: a3865c04fa2f0f4df32e627ee7202bc87bdc3241
This commit is contained in:
committed by
copyberry
parent
0d2a0aa76b
commit
a453588416
@@ -78,6 +78,6 @@ The patched zsh fork used by `shell_zsh_fork` is fetched from the DotSlash
|
||||
manifest at `scripts/codex_package/codex-zsh` when the selected target has a
|
||||
matching prebuilt artifact. Downloaded archives are cached under
|
||||
`$TMPDIR/codex-package/<target>-zsh` and installed at
|
||||
`codex-resources/zsh/bin/zsh`. Pass `--zsh-manifest` to use a different
|
||||
DotSlash manifest, such as the manifest published with a standalone zsh
|
||||
artifact release.
|
||||
`codex-resources/zsh/bin/zsh`. Pass `--zsh-bin` to package a prebuilt, signed
|
||||
executable, or `--zsh-manifest` to use a different DotSlash manifest, such as
|
||||
the manifest published with a standalone zsh artifact release.
|
||||
|
||||
@@ -98,7 +98,8 @@ def parse_args() -> argparse.Namespace:
|
||||
"targets, bwrap is built with Cargo."
|
||||
),
|
||||
)
|
||||
parser.add_argument(
|
||||
zsh_source = parser.add_mutually_exclusive_group()
|
||||
zsh_source.add_argument(
|
||||
"--zsh-manifest",
|
||||
type=Path,
|
||||
help=(
|
||||
@@ -106,6 +107,11 @@ def parse_args() -> argparse.Namespace:
|
||||
"scripts/codex_package/codex-zsh."
|
||||
),
|
||||
)
|
||||
zsh_source.add_argument(
|
||||
"--zsh-bin",
|
||||
type=Path,
|
||||
help="Optional prebuilt zsh executable instead of fetching from a manifest.",
|
||||
)
|
||||
parser.add_argument(
|
||||
"--codex-command-runner-bin",
|
||||
type=Path,
|
||||
@@ -182,7 +188,7 @@ def main() -> int:
|
||||
entrypoint_bin=source_outputs.entrypoint_bin,
|
||||
code_mode_host_bin=source_outputs.code_mode_host_bin,
|
||||
rg_bin=resolve_rg_bin(spec, args.rg_bin),
|
||||
zsh_bin=resolve_zsh_bin(spec, args.zsh_manifest),
|
||||
zsh_bin=resolve_zsh_bin(spec, args.zsh_manifest, zsh_bin=args.zsh_bin),
|
||||
bwrap_bin=source_outputs.bwrap_bin,
|
||||
codex_command_runner_bin=source_outputs.codex_command_runner_bin,
|
||||
codex_windows_sandbox_setup_bin=source_outputs.codex_windows_sandbox_setup_bin,
|
||||
|
||||
@@ -15,6 +15,56 @@ from codex_package.targets import TARGET_SPECS
|
||||
|
||||
|
||||
class PackageLayoutTest(unittest.TestCase):
|
||||
def test_macos_package_preserves_prebuilt_resource_binaries(self) -> None:
|
||||
for variant_name in ("codex", "codex-app-server"):
|
||||
for target in ("aarch64-apple-darwin", "x86_64-apple-darwin"):
|
||||
with self.subTest(variant=variant_name, target=target):
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
root = Path(temp_dir)
|
||||
package_dir = root / "package"
|
||||
package_dir.mkdir()
|
||||
rg_bin = touch_executable(root / "signed-rg")
|
||||
zsh_bin = touch_executable(root / "signed-zsh")
|
||||
rg_bin.write_bytes(b"signed ripgrep binary")
|
||||
zsh_bin.write_bytes(b"signed zsh binary")
|
||||
variant = PACKAGE_VARIANTS[variant_name]
|
||||
spec = TARGET_SPECS[target]
|
||||
inputs = PackageInputs(
|
||||
entrypoint_bin=touch_executable(
|
||||
root / variant.executable_stem
|
||||
),
|
||||
code_mode_host_bin=touch_executable(
|
||||
root / "codex-code-mode-host"
|
||||
),
|
||||
rg_bin=rg_bin,
|
||||
zsh_bin=zsh_bin,
|
||||
bwrap_bin=None,
|
||||
codex_command_runner_bin=None,
|
||||
codex_windows_sandbox_setup_bin=None,
|
||||
)
|
||||
|
||||
build_package_dir(package_dir, "1.2.3", variant, spec, inputs)
|
||||
validate_package_dir(
|
||||
package_dir, variant, spec, include_zsh=True
|
||||
)
|
||||
|
||||
self.assertEqual(
|
||||
{
|
||||
"rg": (package_dir / "codex-path" / "rg").read_bytes(),
|
||||
"zsh": (
|
||||
package_dir
|
||||
/ "codex-resources"
|
||||
/ "zsh"
|
||||
/ "bin"
|
||||
/ "zsh"
|
||||
).read_bytes(),
|
||||
},
|
||||
{
|
||||
"rg": b"signed ripgrep binary",
|
||||
"zsh": b"signed zsh binary",
|
||||
},
|
||||
)
|
||||
|
||||
def test_app_server_package_places_code_mode_host_beside_entrypoint(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
root = Path(temp_dir)
|
||||
|
||||
@@ -16,6 +16,20 @@ from codex_package.zsh import resolve_zsh_bin
|
||||
|
||||
|
||||
class ResolveZshBinTest(unittest.TestCase):
|
||||
def test_uses_prebuilt_executable_override(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
signed_zsh = Path(temp_dir) / "signed-zsh"
|
||||
signed_zsh.write_bytes(b"signed zsh binary")
|
||||
signed_zsh.chmod(0o755)
|
||||
|
||||
with patch("codex_package.zsh.fetch_dotslash_executable") as fetch:
|
||||
zsh_bin = resolve_zsh_bin(
|
||||
TARGET_SPECS["aarch64-apple-darwin"], zsh_bin=signed_zsh
|
||||
)
|
||||
|
||||
self.assertEqual(zsh_bin, signed_zsh.resolve())
|
||||
fetch.assert_not_called()
|
||||
|
||||
def test_uses_manifest_override(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
root = Path(temp_dir)
|
||||
|
||||
@@ -5,6 +5,7 @@ from pathlib import Path
|
||||
from .dotslash import fetch_dotslash_executable
|
||||
from .targets import REPO_ROOT
|
||||
from .targets import TargetSpec
|
||||
from .targets import resolve_input_path
|
||||
|
||||
|
||||
ZSH_MANIFEST = REPO_ROOT / "scripts" / "codex_package" / "codex-zsh"
|
||||
@@ -14,7 +15,12 @@ ZSH_RESOURCE_PATH = Path("zsh") / "bin" / "zsh"
|
||||
def resolve_zsh_bin(
|
||||
spec: TargetSpec,
|
||||
manifest_path: Path | None = None,
|
||||
*,
|
||||
zsh_bin: Path | None = None,
|
||||
) -> Path | None:
|
||||
if zsh_bin is not None:
|
||||
return resolve_input_path(zsh_bin, "zsh executable", "--zsh-bin")
|
||||
|
||||
return fetch_dotslash_executable(
|
||||
spec,
|
||||
manifest_path=manifest_path or ZSH_MANIFEST,
|
||||
|
||||
Reference in New Issue
Block a user