From 332c8c7f8a69e39399f13bd3e7dad9092abc789e Mon Sep 17 00:00:00 2001 From: chaodu-agent <274062505+chaodu-agent@users.noreply.github.com> Date: Sun, 27 Sep 2026 09:10:24 -0400 Subject: [PATCH] fix(pkg): repair v0.6.0 root-owned install residue; bump 0.6.2 The non-relocatable 0.6.1 package reached postinstall, then correctly dropped to the console user and could not rename the root-owned app left by the failed relocatable 0.6.0 attempt. Before dropping root, chown only instance-mcp own per-user app/config/log/plist paths to the console uid/gid. This also makes interrupted retries idempotent. Verified on macmini: manually restoring the exact ownership made the same 0.6.1 pkg install successfully (receipt, Developer ID, running LaunchAgent, health OK). Packaging smoke asserts the repair is present. 88 tests pass. --- Sources/oab-instance-mcp/main.swift | 2 +- docs/releasing.md | 4 ++-- scripts/pkg/postinstall | 14 ++++++++++++++ scripts/test-packaging.sh | 5 +++++ 4 files changed, 22 insertions(+), 3 deletions(-) diff --git a/Sources/oab-instance-mcp/main.swift b/Sources/oab-instance-mcp/main.swift index 42fd525..b0631bd 100644 --- a/Sources/oab-instance-mcp/main.swift +++ b/Sources/oab-instance-mcp/main.swift @@ -4,7 +4,7 @@ import CoreGraphics import Foundation import InstanceMCPCore -let version = "0.6.1" +let version = "0.6.2" struct Options { var host = "127.0.0.1" diff --git a/docs/releasing.md b/docs/releasing.md index 77b3ca0..d855b43 100644 --- a/docs/releasing.md +++ b/docs/releasing.md @@ -120,8 +120,8 @@ lipo -create /tmp/imcp-arm64/release/oab-instance-mcp \ /tmp/imcp-x86_64/release/oab-instance-mcp \ -output /tmp/oab-instance-mcp chmod +x /tmp/oab-instance-mcp -scripts/assemble-app.sh /tmp/oab-instance-mcp /tmp/oab-instance-mcp.app 0.6.1 -ALLOW_UNSIGNED=1 scripts/package-pkg.sh /tmp/oab-instance-mcp.app /tmp/oab-instance-mcp.pkg 0.6.1 +scripts/assemble-app.sh /tmp/oab-instance-mcp /tmp/oab-instance-mcp.app 0.6.2 +ALLOW_UNSIGNED=1 scripts/package-pkg.sh /tmp/oab-instance-mcp.app /tmp/oab-instance-mcp.pkg 0.6.2 ``` Unsigned artifacts are testing inputs only; do not install or publish them. diff --git a/scripts/pkg/postinstall b/scripts/pkg/postinstall index afce03d..31a9214 100755 --- a/scripts/pkg/postinstall +++ b/scripts/pkg/postinstall @@ -15,6 +15,20 @@ UID_=$(/usr/bin/id -u "$CONSOLE_USER") HOME_DIR=$(/usr/bin/dscl . -read "/Users/$CONSOLE_USER" NFSHomeDirectory | \ /usr/bin/sed 's/^NFSHomeDirectory: //') [ -d "$HOME_DIR" ] || { echo "oab-instance-mcp: home not found for $CONSOLE_USER" >&2; exit 1; } +GID_=$(/usr/bin/id -g "$CONSOLE_USER") + +# Repair only our own per-user paths before dropping root. v0.6.0's relocatable +# component was moved by PackageKit into ~/.local as root; the fixed installer +# then correctly ran as the desktop user but could not rename that root-owned app. +# This also makes a partially interrupted package retry idempotent. Do not chown +# a parent directory owned by the user, and never touch unrelated files. +for owned in \ + "$HOME_DIR/.local/oab-instance-mcp" \ + "$HOME_DIR/.config/oab-instance-mcp" \ + "$HOME_DIR/Library/Logs/oab-instance-mcp" \ + "$HOME_DIR/Library/LaunchAgents/dev.openab.instance-mcp.plist"; do + if [ -e "$owned" ]; then /usr/sbin/chown -R "$UID_:$GID_" "$owned"; fi +done SCRIPT_DIR=$(cd "$(dirname "$0")" && pwd) SOURCE="/Library/Application Support/OpenAB/instance-mcp/oab-instance-mcp.app" diff --git a/scripts/test-packaging.sh b/scripts/test-packaging.sh index b888d7b..28c7fa6 100755 --- a/scripts/test-packaging.sh +++ b/scripts/test-packaging.sh @@ -93,6 +93,11 @@ EXPANDED="$TMP/expanded" /usr/sbin/pkgutil --expand "$PKG" "$EXPANDED" [ -x "$EXPANDED/Scripts/postinstall" ] [ -x "$EXPANDED/Scripts/install-prebuilt.sh" ] +# v0.6.0 could leave a root-owned relocated app in ~/.local. A later package +# must repair only our paths before dropping root, or the user installer cannot +# atomically rename it. +grep -q '/usr/sbin/chown -R' "$EXPANDED/Scripts/postinstall" +grep -q '\.local/oab-instance-mcp' "$EXPANDED/Scripts/postinstall" # A bundle listed under is moved to any existing matching bundle on # the target Mac; then postinstall's payload path vanishes (the first v0.6.0 # install failed exactly this way). The explicit component plist must remove it.