Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 13 additions & 7 deletions config/scripts/build-computer-macos.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,6 @@ const entitlementsPath = path.join(
const bundleId = process.env.ORCA_COMPUTER_MACOS_BUNDLE_ID ?? 'com.stablyai.orca.computer-use'
const displayName = 'Orca Computer Use'
const signingIdentity = resolveSigningIdentity()
const universalTriples = ['arm64-apple-macosx', 'x86_64-apple-macosx']

if (process.platform !== 'darwin') {
process.exit(0)
Expand All @@ -27,13 +26,20 @@ buildUniversalBinary()
chmodSync(binaryPath, 0o755)
createHelperApp()

// Repeated --arch yields one universal binary at --show-bin-path (.build/release);
// per-triple builds land outside that path under SwiftPM's current build system.
function buildUniversalBinary() {
const builtBinaries = universalTriples.map((triple) => {
run('swift', ['build', '-c', 'release', '--package-path', packagePath, '--triple', triple])
return path.join(packagePath, '.build', triple, 'release', 'orca-computer-use-macos')
})
mkdirSync(path.dirname(binaryPath), { recursive: true })
run('lipo', ['-create', ...builtBinaries, '-output', binaryPath])
run('swift', [
'build',
'-c',
'release',
'--package-path',
packagePath,
'--arch',
'arm64',
'--arch',
'x86_64'
Comment on lines +38 to +41

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Architecture coverage goes unchecked

The build now relies on SwiftPM to combine the two requested architectures, but macOS CI checks only that the helper builds, runs on its host, and has a valid signature. A helper containing only one architecture could pass those checks and be packaged for both Intel and Apple Silicon. Please verify both architecture slices in the build or verification step.

])
Comment on lines +32 to +42

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Repeated --arch is not equivalent to the old two-step build on SwiftPM ≤ 6.3: architectures.count > 1 forces the Xcode build system, which writes to .build/apple/Products/Release and never creates the .build/release alias, so chmodSync(binaryPath) at line 26 throws ENOENT on the macos-15 (Xcode 16.x) toolchain the repo builds with.

Technical details
# `.build/release` is not the Xcode engine's products dir

## Affected sites
- `config/scripts/build-computer-macos.mjs:32-42` — new multi-arch invocation.
- `config/scripts/build-computer-macos.mjs:7` — `binaryPath` assumes `.build/release`.
- `config/scripts/build-computer-macos.mjs:26` — `chmodSync(binaryPath, 0o755)` fails first.

## Evidence
- SwiftPM ≤ 6.3 `Sources/CoreCommands/Options.swift`:
  `return self.architectures.count > 1 ? .xcode : self._buildSystem`.
- `Sources/SPMBuildCore/Triple+Extensions.swift`: xcode build system maps the scratch subdir to `"apple"`.
- `Sources/XCBuildSupport/XcodeBuildSystem.swift`: runs `xcodebuild --derivedDataPath <dataPath>`, no symlink creation.
- SwiftPM `main`: default `.swiftbuild`; `.native` + >1 arch forced to `.swiftbuild`, whose `build()`
  creates `.build/release` via `createBuildSymbolicLinks` (why Swift 6.4 passes).

## Required outcome
- Resolve the product path for whichever engine SwiftPM selects, on both ≤6.3 and 6.4+.

## Suggested approach (optional)
- Read the directory from `swift build ... --show-bin-path` and append `orca-computer-use-macos`
  (needs a stdout-capturing variant of `run()`), or restore per-`--triple` builds + `lipo`.

}

function createHelperApp() {
Expand Down