Skip to content

fix: fail-closed asar inspect and stop sharing main chunks - #5

Open
tanRdev wants to merge 4 commits into
mainfrom
cursor/fix-release-inspect-and-chunks-4209
Open

tanRdev wants to merge 4 commits into
mainfrom
cursor/fix-release-inspect-and-chunks-4209

Conversation

@tanRdev

@tanRdev tanRdev commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

Fixes the gaps from the post-v0.9.3 packaging review so another empty shared chunk cannot ship, and so the macOS release workflow matches what we actually publish.

What changed

Main process bundles are isolated. The second Rollup input (agentHostSessionServer) is what created out/main/chunks/*.js and the v0.9.3 crash class. Main now has a single index entry with inlineDynamicImports: true. The session server is still emitted by electron-vite’s ?modulePath import as its own file (agent-host-session-server-entry-*.js). A local production build now has no out/main/chunks/ directory.

inspectAsar fails closed. @electron/asar listPackage() returns /out/main/index.js; extractFile() expects the path without the slash. The inspector strips the prefix, throws on extract failures or zero JS files, and reports named imports whose target does not export that name. export * from and export { local as exported } from (including minified export*from / export{ot}from) are followed instead of treated as local/universal exports. export { ot as n } no longer counts as exporting ot. Named-export checks are limited to main-process files; asar node_modules is skipped.

CI packs a real unsigned electron-builder asar. After the desktop build, CI inspects apps/desktop/out, asserts the isolated main layout, then runs pack:mac:dir (electron-builder --mac dir --arm64 with CSC_IDENTITY_AUTO_DISCOVERY=false) so afterPack inspects the shipped asar. Job timeout is 45 minutes.

Release pipeline matches unsigned GitHub releases. release:mac no longer requires a Developer ID. Verify always inspects the asar; signing/notarization checks run only when the app is Developer ID-signed. A failed codesign -dv is treated as unsigned, not a hard failure. The release job gets the same 8GB Node heap CI needed. Publishing paginates GitHub releases, always sends --latest=true or --latest=false, never marks a prerelease latest, and compares stables only to other stables.

Tests

  • Inspect tests cover empty asar chunks, leading-slash listPackage paths, multiline missing named exports, export * / named re-export follow-through, minified forms, renderer skip, and asar node_modules skip.
  • Release-helper tests cover heap flags, adhoc vs Developer ID signatures, failed codesign -dv, latest-tag comparison, prereleases, and explicit --latest=false.
  • Layout tests cover the modulePath session-server spawn file.
  • Publish tests cover paginated gh api release listing and the CI pack:mac:dir step.
  • Full suite: 2097 passed, 2 skipped.
Open in Web Open in Cursor 

Stop sharing main-process chunks by building a single Vite entry and
letting ?modulePath emit the session server on its own. Teach the asar
inspector to strip listPackage paths, refuse extract failures, and catch
missing named exports. Align unsigned GitHub releases with the macOS
pipeline, raise the release-job heap, and only mark a tag latest when it
is actually newest.
@tanRdev
tanRdev marked this pull request as ready for review September 15, 2026 17:26
cursoragent and others added 3 commits September 16, 2026 01:55
Always pass --latest=true or --latest=false so publishing an older draft
cannot steal GitHub latest. Follow export * when checking named exports,
compare release tags as semver, pack the Vite out tree into asar in CI,
and assert the modulePath session-server file is present and referenced.
Follow named `export { local as exported } from` (including minified
forms) instead of treating brace re-exports as local. Limit named-export
checks to main-process files and skip asar `node_modules`. Pack a real
unsigned electron-builder dir in CI so afterPack inspects the shipped
asar. Paginate GitHub releases, never mark prereleases latest, and treat
a failed `codesign -dv` as unsigned.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants