Install macOS helper from PKG for XPC enroll

Browser enrollment used osascript on every elevate. Ship a signed
privileged helper installed at PKG time so probo:// can enroll over
XPC with no second admin prompt. Add make install/uninstall/clean for
local PKG test loops, and show alerts only on failure.

Mirror the Go lint path for the macOS SPM package: Make
targets, root configs, and a Linux CI job. Keep checks
syntax-only so they do not need a macOS SDK. Format the
existing sources so the new gates start clean.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-20 18:18:04 +02:00
parent 754d12d583
commit 85864a580c
42 changed files with 1903 additions and 341 deletions

View File

@@ -17,6 +17,13 @@ SYFT ?= syft
TAIL ?= tail
ECHO ?= echo
GOLINTCMD ?= golangci-lint
SWIFTLINTCMD ?= swiftlint
SWIFTCMD ?= swift
SWIFT_ENROLL_UI ?= cmd/probo-agent/installer/macos/enroll-ui
SWIFT_FORMAT_CONFIG ?= .swift-format
SWIFTLINT_CONFIG ?= .swiftlint.yml
swift_sources = $(shell find $(SWIFT_ENROLL_UI) \( -name '*.swift' ! -name '*.generated.swift' ! -path '*/.build/*' \) | sort)
DOCKER_BUILD_FLAGS?=
DOCKER_BUILD= DOCKER_BUILDKIT=1 $(DOCKER) build $(DOCKER_BUILD_FLAGS)
@@ -90,15 +97,12 @@ PROBOCTL_SRC= cmd/proboctl/main.go
PROBO_AGENT_BIN= bin/probo-agent
PROBO_AGENT_SRC= ./cmd/probo-agent
# Menu bar / tray enrollment is macOS and Windows only; those hosts need CGO.
# Menu bar / tray enrollment is macOS and Windows; only macOS needs CGO.
PROBO_AGENT_TARGET_OS= $(if $(GOOS),$(GOOS),$(shell $(GO) env GOOS))
PROBO_AGENT_CGO= 0
ifeq ($(PROBO_AGENT_TARGET_OS),darwin)
PROBO_AGENT_CGO= 1
endif
ifeq ($(PROBO_AGENT_TARGET_OS),windows)
PROBO_AGENT_CGO= 1
endif
ifdef WITH_APPS
GENERATED += relay
@@ -120,6 +124,19 @@ lint-go: vet go-fmt go-fix go-lint
lint-js:
$(NPM) run lint
.PHONY: lint-swift
lint-swift: swift-fmt swift-lint ## Lint Swift enroll-ui (format + SwiftLint)
.PHONY: swift-fmt
swift-fmt: ## Check Swift formatting with swift format
@command -v $(SWIFTCMD) >/dev/null 2>&1 || { echo "error: '$(SWIFTCMD)' not found; install the Swift toolchain (Xcode on macOS)"; exit 1; }
$(SWIFTCMD) format lint --configuration $(SWIFT_FORMAT_CONFIG) --strict --parallel $(swift_sources)
.PHONY: swift-lint
swift-lint: ## Lint Swift with SwiftLint
@command -v $(SWIFTLINTCMD) >/dev/null 2>&1 || { echo "error: '$(SWIFTLINTCMD)' not found; install SwiftLint (e.g. brew install swiftlint)"; exit 1; }
$(SWIFTLINTCMD) lint --strict --config $(SWIFTLINT_CONFIG) --cache-path .cache/swiftlint
.PHONY: vet
vet: generate embed
$(GO_VET) ./...
@@ -393,6 +410,14 @@ fmt: fmt-go ## Format Go code
fmt-go: ## Format Go code
go fmt ./...
.PHONY: fmt-swift
fmt-swift: ## Format Swift enroll-ui sources
@command -v $(SWIFTCMD) >/dev/null 2>&1 || { echo "error: '$(SWIFTCMD)' not found; install the Swift toolchain (Xcode on macOS)"; exit 1; }
$(SWIFTCMD) format --configuration $(SWIFT_FORMAT_CONFIG) --in-place --parallel $(swift_sources)
@if command -v $(SWIFTLINTCMD) >/dev/null 2>&1; then \
$(SWIFTLINTCMD) lint --fix --config $(SWIFTLINT_CONFIG) --cache-path .cache/swiftlint; \
fi
.PHONY: clean
clean: ## Clean the project (node_modules and build artifacts)
$(RM) -rf bin/*