Install macOS helper from PKG for XPC enroll

Browser enrollment used osascript on every elevate. Ship a signed
privileged helper installed at PKG time so probo:// can enroll over
XPC with no second admin prompt. Add make install/uninstall/clean for
local PKG test loops, and show alerts only on failure.

Mirror the Go lint path for the macOS SPM package: Make
targets, root configs, and a Linux CI job. Keep checks
syntax-only so they do not need a macOS SDK. Format the
existing sources so the new gates start clean.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-20 18:18:04 +02:00
parent 754d12d583
commit 85864a580c
42 changed files with 1903 additions and 341 deletions

View File

@@ -5,6 +5,26 @@ documented in this file.
## Unreleased
### Added
- macOS privileged helper (`com.probo.agent.helper`) embedded in
`Probo Agent.app` and installed by PKG postinstall for XPC-driven
browser enrollment (no SMJobBless / admin prompt on enroll).
- Hidden `probo-agent enroll-url --preflight` JSON output for the URL handler.
- `make -C cmd/probo-agent install|uninstall|clean` for local macOS PKG
test loops (install tears down leftovers first).
### Changed
- Browser enrollment via `Probo Agent.app` uses HelperClient + XPC only
(osascript elevation and enroll-time SMJobBless removed).
- macOS PKG / app builds require `CODESIGN_IDENTITY` and `APPLE_TEAM_ID`.
- CLI `enroll-url` on macOS refuses elevation; use the signed app deeplink
or `sudo probo-agent install`.
- macOS `probo-agent uninstall` requires root (`sudo`).
- PKG preinstall removes stale privileged helper files on upgrade;
postinstall reinstalls the helper as root.
## [0.1.1] - 2026-06-11
### Changed