Skip to content

Commit ff52ede

Browse files
chore(release): remove the Bun pin commentary
The compiler pin stays at 1.3.14. The extra notes restated the signing bug and made the Windows chmod comment look like the build still used 1.2.19. Co-authored-by: Cursor <cursoragent@cursor.com>
1 parent 09afb80 commit ff52ede

4 files changed

Lines changed: 19 additions & 26 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -77,8 +77,6 @@ jobs:
7777
- run: pnpm install --frozen-lockfile
7878

7979
# Binary compile uses `bun build --compile` CLI (not Bun.build API).
80-
# Pin 1.3.14: 1.2.19 grows darwin-x64 LC_CODE_SIGNATURE.datasize past
81-
# __LINKEDIT and rcodesign panics; 1.3.12 truncates arm64 signatures.
8280
# Keep this pin in sync with any local smoke tests of binary-compile.mjs.
8381
- uses: oven-sh/setup-bun@v2
8482
with:
@@ -154,8 +152,6 @@ jobs:
154152
- run: pnpm install --frozen-lockfile
155153

156154
# Binary compile uses `bun build --compile` CLI (not Bun.build API).
157-
# Pin 1.3.14: 1.2.19 grows darwin-x64 LC_CODE_SIGNATURE.datasize past
158-
# __LINKEDIT and rcodesign panics; 1.3.12 truncates arm64 signatures.
159155
# Keep this pin in sync with any local smoke tests of binary-compile.mjs.
160156
- uses: oven-sh/setup-bun@v2
161157
with:

‎docs/agents/publish.md‎

Lines changed: 17 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,7 @@ node tools/release/publish-channel.mjs --channel test --knowledge --dry-run
114114
- **认证**:npm OIDC Trusted Publishing(无 token),需要 `id-token: write` 权限;OSS 通道复用同一 OIDC token 向 FC 证明身份(见上文「OSS 通道」)
115115
- **GitHub Release**:`contents: write` + `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}`(stable / channel 均需)
116116
- **Node 版本**:24(npm 11.5+ 才支持 OIDC token 交换)
117-
- **Bun**:`oven-sh/setup-bun`,版本钉死在 workflow 中(当前 `1.3.14`)。不要退回 `1.2.19`:那个版本在 bundle 超过模板 `__BUN` 时会把 darwin-x64 的 `LC_CODE_SIGNATURE.datasize` 加到超出 `__LINKEDIT`,Linux 上的 `rcodesign sign` 解析 Mach-O 时 panic。也不要升到未验证的版本:`1.3.12` 会把 arm64 签名截断,`codesign` 直接拒绝
117+
- **Bun**:`oven-sh/setup-bun`,版本钉死在 workflow 中
118118
- **darwin 签名**:编完后 `binary-codesign.mjs` 对 darwin Mach-O 做 ad-hoc 重签,并按 Apple 的方式重算每一页 SHA-256(末页不补零)。对不上就中止发布。macOS runner 额外跑 `codesign --verify --strict`。Linux runner 用 `rcodesign 0.29.0 sign`;不要用 `rcodesign verify`(会拒绝 Apple 已通过的 ad-hoc 签名)。漏签时 Apple Silicon 会在启动时 SIGKILL
119119
- **Actions 版本**:checkout/setup-node/pnpm-action 均为 v6(Node 24 兼容)
120120
- **npm 配置**:当前 release tooling 发布的包(`bailian-cli-core` / `bailian-cli-runtime` / `bailian-cli-commands` / `bailian-cli` / `knowledge-studio-cli`)的 Trusted Publisher 指向 `modelstudioai/cli` 的 `publish.yml`;新增发布包时同步 npm Trusted Publisher
@@ -149,20 +149,19 @@ node tools/release/publish-channel.mjs --channel test --knowledge --dry-run
149149

150150
## 常见漏点(基于历史踩坑)
151151

152-
| 漏点 | 后果 |
153-
| ------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
154-
| 只升部分包,漏升 runtime/commands/kscli | 当前 check.mjs 按所选发布集合校验,但未选择 `knowledge-studio-cli` 时不会覆盖 kscli |
155-
| 新增发布包但没加 `tools/release/lib/packages.mjs` | CI 不会 bump/publish/校验该包 |
156-
| cli 升版号但 core 没升 | check.mjs 会拦下 |
157-
| 发版漏更 CHANGELOG,或分类写成规范外的 `优化`/`Improved` | 用户看不到本次变更,分类与历史不一致 |
158-
| `1.0.0` 当 beta 直接发 | 占了 `latest` tag,所有用户被强升,撤回成本极高 |
159-
| README 写的 bin 名实际 `package.json.bin` 没注册 | 用户复制命令报 `command not found` |
160-
| Node 徽章与 `cli/package.json.engines` 不一致(当前应为 `>=18.17`) | 用户在声明外的 Node 上 `npm i` 被 engine 警告或直接失败 |
161-
| npm Trusted Publisher 的 workflow filename 改了没同步 | OIDC 匹配不上,publish 报 404 |
162-
| CI 用 Node 22(npm 10)跑 publish | npm 10 不支持 OIDC token 交换,publish 报 404 |
163-
| stable 发布前没有升级版本号 | 所选发布集合的版本已全部存在于 npm,CI 明确报错并要求先升级版本号 |
164-
| channel job 缺少 `contents: write` | `gh release create` 失败 |
165-
| darwin 二进制编完后没有 ad-hoc 重签 | Apple Silicon / macOS 27 对失效的 linker 签名直接 SIGKILL(`Killed: 9`) |
166-
| 把编译用的 Bun 从 `1.3.14` 退回 `1.2.19` | darwin-x64 的 `datasize` 超出 `__LINKEDIT`,`rcodesign` panic,channel/stable 二进制步骤失败 |
167-
| npm 先于二进制 / OSS 成功 | latest 已发出,CDN 上没有对应 zip/tar.gz;OSS 网络失败时无法回滚 npm |
168-
| stable 未先推 tag 就建 Release | `--verify-tag` 失败 |
152+
| 漏点 | 后果 |
153+
| ------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
154+
| 只升部分包,漏升 runtime/commands/kscli | 当前 check.mjs 按所选发布集合校验,但未选择 `knowledge-studio-cli` 时不会覆盖 kscli |
155+
| 新增发布包但没加 `tools/release/lib/packages.mjs` | CI 不会 bump/publish/校验该包 |
156+
| cli 升版号但 core 没升 | check.mjs 会拦下 |
157+
| 发版漏更 CHANGELOG,或分类写成规范外的 `优化`/`Improved` | 用户看不到本次变更,分类与历史不一致 |
158+
| `1.0.0` 当 beta 直接发 | 占了 `latest` tag,所有用户被强升,撤回成本极高 |
159+
| README 写的 bin 名实际 `package.json.bin` 没注册 | 用户复制命令报 `command not found` |
160+
| Node 徽章与 `cli/package.json.engines` 不一致(当前应为 `>=18.17`) | 用户在声明外的 Node 上 `npm i` 被 engine 警告或直接失败 |
161+
| npm Trusted Publisher 的 workflow filename 改了没同步 | OIDC 匹配不上,publish 报 404 |
162+
| CI 用 Node 22(npm 10)跑 publish | npm 10 不支持 OIDC token 交换,publish 报 404 |
163+
| stable 发布前没有升级版本号 | 所选发布集合的版本已全部存在于 npm,CI 明确报错并要求先升级版本号 |
164+
| channel job 缺少 `contents: write` | `gh release create` 失败 |
165+
| darwin 二进制编完后没有 ad-hoc 重签 | Apple Silicon / macOS 27 对失效的 linker 签名直接 SIGKILL(`Killed: 9`) |
166+
| npm 先于二进制 / OSS 成功 | latest 已发出,CDN 上没有对应 zip/tar.gz;OSS 网络失败时无法回滚 npm |
167+
| stable 未先推 tag 就建 Release | `--verify-tag` 失败 |

‎tools/release/lib/binary-build.mjs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -165,7 +165,7 @@ function compileOne({ bunTarget, os, arch, exe }, version, outdir, entry) {
165165
}
166166
if (result.stdout) process.stdout.write(result.stdout);
167167
if (result.stderr) process.stderr.write(result.stderr);
168-
// Force 0755. Bun 1.2.19 wrote windows-x64 .exe as mode 000 on Unix hosts (oven-sh/bun#21308).
168+
// Bun has written windows-x64 .exe as mode 000 on Unix hosts (oven-sh/bun#21308).
169169
chmodSync(innerPath, 0o755);
170170
// Sign after chmod. Bun's linker signature does not match the final Mach-O bytes.
171171
if (os === "darwin") signDarwinAdhoc(innerPath, { log });

‎tools/release/lib/binary-compile.mjs‎

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,9 +3,7 @@
33
* bun tools/release/lib/binary-compile.mjs --entry <path> --outfile <path> --target <bun-target>
44
*
55
* Uses `bun build --compile` (CLI). The Bun.build({ compile }) API on ≤1.2.19
6-
* can exit 0 without writing outfile.
7-
* CI pins Bun 1.3.14. 1.2.19 grows darwin-x64 LC_CODE_SIGNATURE.datasize past
8-
* __LINKEDIT, and rcodesign panics. 1.3.12 truncates arm64 signatures.
6+
* can exit 0 without writing outfile; CI stays on the CLI.
97
*
108
* Called by binary-build.mjs (Node orchestration stays on Node).
119
*/

0 commit comments

Comments
 (0)