mirror of
https://github.com/larksuite/cli.git
synced 2026-08-03 08:32:46 +08:00
feat(keysigner): compile TPM signer into linux & windows/amd64 by default
Drop the sks_signer build tag, mirroring the darwin keychain signer: the TPM signer now compiles into every linux and windows/amd64 build via constraint //go:build linux || (windows && amd64) — no -tags needed. windows/arm64 is arch-excluded (go-ole has no arm64 VARIANT) and falls back to client_secret only. - goreleaser: drop -tags=sks_signer; merge windows-arm64 into the windows build (amd64+arm64) since no tag is needed and arm64 is arch-excluded. - build-pkg-pr-new.sh: remove tag logic. - doctor: update the no-signer hint (signer ships by default on macOS, Linux, Windows/amd64). - Switching from a custom tag to GOOS/GOARCH constraints also lets go mod tidy track sks/go-tpm/go-ole correctly.
This commit is contained in:
@@ -5,8 +5,11 @@ before:
|
||||
- python3 scripts/fetch_meta.py
|
||||
|
||||
builds:
|
||||
# Linux & Windows: pure-Go TPM 2.0 signer (sks_signer), cross-compiled with
|
||||
# CGO disabled — the binaries ship the platform key signer for private_key_jwt.
|
||||
# Linux & Windows: pure-Go TPM 2.0 signer is compiled in by default (no build
|
||||
# tag), cross-compiled with CGO disabled — the binaries ship the platform key
|
||||
# signer for private_key_jwt. windows/arm64 is the one exception: the sks
|
||||
# Windows dependency stack (go-ole) has no arm64 support, so the signer file is
|
||||
# arch-excluded there and that binary falls back to client_secret only.
|
||||
- id: linux
|
||||
binary: lark-cli
|
||||
main: .
|
||||
@@ -14,7 +17,6 @@ builds:
|
||||
- CGO_ENABLED=0
|
||||
flags:
|
||||
- -trimpath
|
||||
- -tags=sks_signer
|
||||
ldflags:
|
||||
- -s -w -X github.com/larksuite/cli/internal/build.Version={{ .Version }} -X github.com/larksuite/cli/internal/build.Date={{ .Date }}
|
||||
goos:
|
||||
@@ -22,9 +24,6 @@ builds:
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
# windows/amd64 carries the sks signer. windows/arm64 ships unsigned: the sks
|
||||
# dependency stack (certtostore -> go-ole) has no windows/arm64 support, so it
|
||||
# falls back to client_secret only (same as before this change).
|
||||
- id: windows
|
||||
binary: lark-cli
|
||||
main: .
|
||||
@@ -32,25 +31,12 @@ builds:
|
||||
- CGO_ENABLED=0
|
||||
flags:
|
||||
- -trimpath
|
||||
- -tags=sks_signer
|
||||
ldflags:
|
||||
- -s -w -X github.com/larksuite/cli/internal/build.Version={{ .Version }} -X github.com/larksuite/cli/internal/build.Date={{ .Date }}
|
||||
goos:
|
||||
- windows
|
||||
goarch:
|
||||
- amd64
|
||||
- id: windows-arm64
|
||||
binary: lark-cli
|
||||
main: .
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
flags:
|
||||
- -trimpath
|
||||
ldflags:
|
||||
- -s -w -X github.com/larksuite/cli/internal/build.Version={{ .Version }} -X github.com/larksuite/cli/internal/build.Date={{ .Date }}
|
||||
goos:
|
||||
- windows
|
||||
goarch:
|
||||
- arm64
|
||||
# macOS: the keychain signer calls Security.framework via runtime FFI (purego),
|
||||
# so it is CGO-free, compiled into every darwin build (no build tag), and
|
||||
|
||||
@@ -173,7 +173,7 @@ func teeCheckResult(info keysigner.HardwareInfo, ok bool, probeErr error, usesPK
|
||||
if usesPKJWT {
|
||||
return fail(name,
|
||||
"app uses private_key_jwt but this build has no TEE key signer",
|
||||
"on Linux/Windows build with -tags sks_signer (macOS includes the signer by default), or re-register with --auth-method client_secret")
|
||||
"the platform key signer ships by default on macOS, Linux, and Windows/amd64; this platform (e.g. Windows/arm64) has none — use a supported platform or re-register with --auth-method client_secret")
|
||||
}
|
||||
return skip(name, "no TEE signer in this build (only private_key_jwt is affected; client_secret is unaffected)")
|
||||
}
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
//go:build (linux || windows) && sks_signer
|
||||
//go:build linux || (windows && amd64)
|
||||
|
||||
// Copyright (c) 2026 Lark Technologies Pte. Ltd.
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
// TPM 2.0 signer (build tag `sks_signer`), backed by
|
||||
// github.com/facebookincubator/sks.
|
||||
// TPM 2.0 signer (compiled into every linux and windows/amd64 build, no build
|
||||
// tag required), backed by github.com/facebookincubator/sks.
|
||||
//
|
||||
// sks holds a non-exportable ECDSA P-256 key in the platform TPM and signs
|
||||
// SHA-256 digests. On Linux it talks to /dev/tpmrm0; on Windows it uses the
|
||||
@@ -14,10 +14,10 @@
|
||||
// registration (DefaultKeyLabel) and reused for subsequent app registrations and
|
||||
// every client_assertion on the same device.
|
||||
//
|
||||
// Build with: go build -tags sks_signer
|
||||
// Without the tag this file is excluded, no signer registers (keysigner.Active()
|
||||
// is nil), and the build stays free of the TPM dependency stack — client_secret
|
||||
// auth only. This mirrors the macOS keychain signer's `keychain_signer` gating.
|
||||
// Excluded from windows/arm64: the sks Windows dependency stack (go-ole) has no
|
||||
// arm64 VARIANT and fails to compile, so windows/arm64 falls back to
|
||||
// client_secret only (keysigner.Active() is nil). On darwin the keychain signer
|
||||
// is used instead. CGO is never required.
|
||||
package keysigner
|
||||
|
||||
import (
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
//go:build (linux || windows) && sks_signer
|
||||
//go:build linux || (windows && amd64)
|
||||
|
||||
// Copyright (c) 2026 Lark Technologies Pte. Ltd.
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
@@ -24,19 +24,13 @@ build_target() {
|
||||
ext=".exe"
|
||||
fi
|
||||
|
||||
# linux and windows/amd64 need -tags sks_signer for the pure-Go TPM signer.
|
||||
# windows/arm64 is excluded: sks's Windows COM dependency (go-ole v1.2.5) has
|
||||
# no arm64 VARIANT, so arm64 ships without the TPM signer (client_secret only)
|
||||
# — mirroring the windows-arm64 build in .goreleaser.yml. darwin's keychain
|
||||
# signer is compiled into every darwin build (cgo-free, no tag).
|
||||
local tags=""
|
||||
if [[ "$goos" == "linux" ]] || [[ "$goos" == "windows" && "$goarch" == "amd64" ]]; then
|
||||
tags="-tags sks_signer"
|
||||
fi
|
||||
|
||||
# The platform key signers are compiled in by build constraint, no tags:
|
||||
# darwin keychain (//go:build darwin) and linux/windows-amd64 TPM
|
||||
# (//go:build linux || (windows && amd64)). windows/arm64 arch-excludes the TPM
|
||||
# signer (go-ole has no arm64) and falls back to client_secret only.
|
||||
local output="$OUT_DIR/bin/lark-cli-${goos}-${goarch}${ext}"
|
||||
echo "Building ${goos}/${goarch} -> ${output}"
|
||||
CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" go build -trimpath ${tags} -ldflags "$LDFLAGS" -o "$output" ./main.go
|
||||
CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" go build -trimpath -ldflags "$LDFLAGS" -o "$output" ./main.go
|
||||
}
|
||||
|
||||
build_target darwin arm64
|
||||
|
||||
Reference in New Issue
Block a user