Files
arcrun-collector/cmd/arcrun-app/build-msix.sh
T
Leo 4d3a6a09a6 v0.18.9:collector 併進同一支執行檔——磁碟上不再攤出第二支 exe
leo 08-06 裁決:「不要兩支,寫成一支檔案」。

## 為什麼
v0.18.7-8 的「單一 exe」其實是**一支包著另一支**:collector.exe 被 go:embed
進 Arcrun.exe,執行時攤到 ~/.arcrun-rag/bin/ 再跑。
那正是防毒軟體眼中的 dropper 特徵 —— 封測者實撞
`Trojan:Win32/Sabsik.FL.A!ml`,檔案當場被隔離、自動刪除。

⚠️ 誠實界定:`!ml` 結尾=**機器學習判定**,Sabsik 是最常見的通用誤判家族,
   主因是「未簽章+下載次數少」,**不是**特別指向 dropper 行為。
   所以本次改動**不保證**解除誤判——真正的解是上架 MS Store(微軟簽章)。
   但「執行時把第二支 PE 寫到磁碟再執行」本來就該拿掉,這是對的方向且順手變小。

## 怎麼做
- `collector/` 39 個檔 `package main` → `package collector`,`main()` → 匯出的 `Run(args) int`
- 新增 `collector/cmd/collector/`(薄殼 CLI,讓單獨跑 collector 這條路仍可用)
- App 直接 import 該套件;`main()` 第一件事就判 `--collector`,是的話走 `collector.Run` 不碰 GUI
- `supervisor` 加 `ArgPrefix`,App 把 `BinPath` 指向 `os.Executable()` 自己
- 刪掉 `bundled_collector_{windows,other}.go`(embed + 攤檔那套)
- 三支打包腳本不再編/複製第二支;版本注入同時打到兩個 package
- build-win.sh 的機械閘改成**直接問它**:`--collector --version` 回得出版本才放行
  (舊閘是比大小,只能證明「有 embed」,證明不了「分派是對的」)

## 驗(真機實跑)
· `.app/Contents/MacOS/` 只有 **一個** 執行檔(原本兩個)
· 跑起來兩個行程是**同一個 exe**:
    …/MacOS/arcrun-app
    …/MacOS/arcrun-app --collector direct --config …
· `~/.arcrun-rag/bin` **不存在**(沒有任何東西被攤出來)
· 端到端:丟檔進看守資料夾 → collector.log `"status":"ingested","http_status":200`
· `lsappinfo` 仍是 `type="UIElement"`、`Version="0.18.9"`
· collector 39 檔測試全過;app 測試過;go vet 全綠;mac + windows 交叉編譯皆過
· 單檔 26MB → 22MB(不再夾帶第二份完整程式)
2026-08-06 16:00:47 +08:00

119 lines
5.5 KiB
Bash
Executable File
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#!/usr/bin/env bash
# build-msix.sh — 把 Wails 版 Arcrun 打包成 Microsoft Store 用的 .msixt1962026-08-05
#
# leo 08-05:「當測試者給我截圖安裝成功就要提交 ms store」
#
# 🎯 **在 Mac 上就打得出 msix**,不需要 Windows 機器、不需要 MakeAppx。
# 靠微軟自家開源跨平台工具 msix-packaging 的 `makemsix`。
#
# ⚠️ **不必自購簽章憑證**:送 Store 的 msix 不用簽——微軟過審後會用自己的憑證重簽。
# 但**側載**(不走 Store)就必須自己簽。(官方說明見 ../arcrun-tray/docs/store-submission.md §2
#
# 與舊 fyne 版(../arcrun-tray/build-msix.sh)的差別:
# 舊版是單一 execollector 用 //go:embed 吃進去);
# 2026-08-06 起改回一個 execollector 編進 Arcrun.exe`--collector` 換身分。
# 以下敘述保留為沿革)**Wails 版曾是兩個 exe**(見 supervise.go 的
# os.Executable() 同層查找)⇒ 兩個都要進 msix root,缺一個就「裝了不會同步」。
#
# 前置(一次就好):
# brew install mingw-w64 cmake icu4c
# bash ../arcrun-tray/build-msix.sh --setup # 建 makemsix(約 5-10 分鐘)
#
# 用法:
# IDENTITY_NAME=<Partner Center 的 Name> \
# PUBLISHER=<Partner Center 的 Publisher> \
# PUBLISHER_DISPLAY=<顯示名> \
# bash build-msix.sh
set -euo pipefail
cd "$(dirname "$0")"
MSIX_SDK_DIR="${MSIX_SDK_DIR:-$HOME/.cache/msix-packaging}"
MAKEMSIX="$MSIX_SDK_DIR/.vs/bin/makemsix"
[[ -x "$MAKEMSIX" ]] || {
echo "❌ 找不到 makemsix$MAKEMSIX"
echo " 先跑一次:bash ../arcrun-tray/build-msix.sh --setup"
exit 1
}
VERSION_RAW="${VERSION:-$(./daemon-version.py --stamp)}" # 版本由 daemon-version.py 機械產生(2026-08-06
# msix 版本必須是四段數字 a.b.c.d,且**最後一段必須是 0**(Store 規定,保留給微軟)。
MSIX_VERSION="$(echo "$VERSION_RAW" | sed 's/^v//' | awk -F. '{printf "%d.%d.%d.0", $1, $2, $3}')"
# ⚠️ 變數後緊接全形括號必須用 ${} 包起來——全形字元會被 bash 當成變數名的一部分。
echo "🏷 msix 版本:${MSIX_VERSION}(來源 ${VERSION_RAW}"
# Identity 三值——**必須與 Partner Center 完全一致**,故從環境變數帶入,預設佔位。
IDENTITY_NAME="${IDENTITY_NAME:-PLACEHOLDER.ArcrunRAG}"
PUBLISHER="${PUBLISHER:-CN=PLACEHOLDER}"
PUBLISHER_DISPLAY="${PUBLISHER_DISPLAY:-PLACEHOLDER}"
if [[ "$IDENTITY_NAME" == PLACEHOLDER* ]]; then
echo "⚠️ Identity 仍是佔位值——**這顆 msix 不能送 Store**,只能拿來驗打包流程。"
echo " 送審前要帶:IDENTITY_NAME / PUBLISHER / PUBLISHER_DISPLAY(三值從 Partner Center 抄)"
fi
echo "① 編 Windows 版(兩個 exe"
VERSION="$VERSION_RAW" bash build-win.sh >/dev/null
[[ -f build/bin/arcrun-app.exe ]] || { echo "❌ Arcrun.exe 沒編出來" >&2; exit 1; }
# 2026-08-06 起只有一支 execollector 編進去了),不再檢查第二個檔。
OUT="dist-msix"
rm -rf "$OUT" && mkdir -p "$OUT/root/Assets"
cp build/bin/arcrun-app.exe "$OUT/root/Arcrun.exe"
echo "② 複製 Store 圖示(沿用 CIS 版,不重產——sips 縮放會把方形拉扁)"
cp ../arcrun-tray/assets/store/*.png "$OUT/root/Assets/"
echo "③ 寫 AppxManifest.xml(能力宣告誠實且最小化)"
cat > "$OUT/root/AppxManifest.xml" <<EOF
<?xml version="1.0" encoding="utf-8"?>
<Package
xmlns="http://schemas.microsoft.com/appx/manifest/foundation/windows10"
xmlns:uap="http://schemas.microsoft.com/appx/manifest/uap/windows10"
xmlns:rescap="http://schemas.microsoft.com/appx/manifest/foundation/windows10/restrictedcapabilities"
IgnorableNamespaces="uap rescap">
<Identity Name="$IDENTITY_NAME" Publisher="$PUBLISHER" Version="$MSIX_VERSION" ProcessorArchitecture="x64" />
<Properties>
<DisplayName>Arcrun</DisplayName>
<PublisherDisplayName>$PUBLISHER_DISPLAY</PublisherDisplayName>
<Logo>Assets\StoreLogo.png</Logo>
</Properties>
<Dependencies>
<TargetDeviceFamily Name="Windows.Desktop" MinVersion="10.0.17763.0" MaxVersionTested="10.0.22631.0" />
</Dependencies>
<Resources>
<Resource Language="zh-TW" />
<Resource Language="en-US" />
</Resources>
<Applications>
<Application Id="Arcrun" Executable="Arcrun.exe" EntryPoint="Windows.FullTrustApplication">
<uap:VisualElements
DisplayName="Arcrun"
Description="把你選的資料夾變成可以問問題的知識庫,檔案留在自己電腦裡。"
BackgroundColor="#17181A"
Square150x150Logo="Assets\Square150x150Logo.png"
Square44x44Logo="Assets\Square44x44Logo.png">
<uap:DefaultTile
Wide310x150Logo="Assets\Wide310x150Logo.png"
Square71x71Logo="Assets\Square71x71Logo.png"
Square310x310Logo="Assets\Square310x310Logo.png" />
</uap:VisualElements>
</Application>
</Applications>
<Capabilities>
<rescap:Capability Name="runFullTrust" />
<Capability Name="internetClient" />
<rescap:Capability Name="broadFileSystemAccess" />
</Capabilities>
</Package>
EOF
echo "④ 打包 msix"
"$MAKEMSIX" pack -d "$OUT/root" -p "$OUT/Arcrun.msix" >/dev/null
SIZE=$(ls -lh "$OUT/Arcrun.msix" | awk '{print $5}')
echo "✅ 完成:$OUT/Arcrun.msix${SIZE},未簽章=送 Store 的正確狀態)"
echo
echo "🔬 送審前必做(否則會被退件):"
echo " · Identity 三值要與 Partner Center 完全一致(現在:${IDENTITY_NAME}"
echo " · broadFileSystemAccess 是受限能力,送審要寫明用途"
echo " (本 App 需要它才能讀使用者自選的任意資料夾)"