Install macOS helper from PKG for XPC enroll

Browser enrollment used osascript on every elevate. Ship a signed
privileged helper installed at PKG time so probo:// can enroll over
XPC with no second admin prompt. Add make install/uninstall/clean for
local PKG test loops, and show alerts only on failure.

Mirror the Go lint path for the macOS SPM package: Make
targets, root configs, and a Linux CI job. Keep checks
syntax-only so they do not need a macOS SDK. Format the
existing sources so the new gates start clean.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-20 18:18:04 +02:00
parent 754d12d583
commit 85864a580c
42 changed files with 1903 additions and 341 deletions

View File

@@ -22,51 +22,22 @@
package elevate
import (
"fmt"
"os/exec"
"strings"
import "errors"
"go.probo.inc/probo/pkg/deviceagent/checks"
// ErrPrivilegedHelperRequired is returned when a non-root process asks for
// elevation on macOS. Browser enrollment must go through the signed
// Probo Agent.app XPC helper (installed by the PKG); CLI install/uninstall
// require sudo.
var ErrPrivilegedHelperRequired = errors.New(
"macOS elevation requires the signed Probo Agent.app privileged helper " +
"(browser enroll via PKG-installed helper) or sudo " +
"(CLI: sudo probo-agent install|uninstall)",
)
func runElevatedInstall(opts InstallOptions, enrollmentToken string) error {
parts := []string{
shellQuote(opts.ExePath),
"install",
"--server",
shellQuote(opts.ServerURL),
"--enrollment-token",
shellQuote(enrollmentToken),
}
if opts.ConfigDir != "" {
parts = append(parts, "--dir", shellQuote(opts.ConfigDir))
}
shellCmd := strings.Join(parts, " ")
script := fmt.Sprintf(
`do shell script %s with administrator privileges`,
applescriptQuote(shellCmd),
)
candidates := checks.CommandCandidates("osascript")
if len(candidates) == 0 {
return fmt.Errorf("command %q not available at expected absolute path", "osascript")
}
out, err := exec.Command(candidates[0], "-e", script).CombinedOutput()
return commandError(out, err)
func runElevatedInstall(_ InstallOptions, _ string) error {
return ErrPrivilegedHelperRequired
}
func shellQuote(v string) string {
return "'" + strings.ReplaceAll(v, "'", `'"'"'`) + "'"
}
func applescriptQuote(v string) string {
v = strings.ReplaceAll(v, `\`, `\\`)
v = strings.ReplaceAll(v, `"`, `\"`)
return `"` + v + `"`
func runElevatedUninstall(_ UninstallOptions) error {
return ErrPrivilegedHelperRequired
}