Install macOS helper from PKG for XPC enroll

Browser enrollment used osascript on every elevate. Ship a signed
privileged helper installed at PKG time so probo:// can enroll over
XPC with no second admin prompt. Add make install/uninstall/clean for
local PKG test loops, and show alerts only on failure.

Mirror the Go lint path for the macOS SPM package: Make
targets, root configs, and a Linux CI job. Keep checks
syntax-only so they do not need a macOS SDK. Format the
existing sources so the new gates start clean.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-20 18:18:04 +02:00
parent 754d12d583
commit 85864a580c
42 changed files with 1903 additions and 341 deletions

View File

@@ -68,3 +68,36 @@ func runElevatedInstall(opts InstallOptions, enrollmentToken string) error {
return commandError(out, err)
}
func runElevatedUninstall(opts UninstallOptions) error {
args := []string{"uninstall"}
if opts.ConfigDir != "" {
args = append(args, "--dir", opts.ConfigDir)
}
argList := make([]string, len(args))
for i, arg := range args {
argList[i] = "'" + escapePowerShellSingleQuoted(arg) + "'"
}
script := fmt.Sprintf(
`$p = Start-Process -FilePath %s -ArgumentList @(%s) -Verb RunAs -Wait -PassThru; if ($p.ExitCode -ne 0) { exit $p.ExitCode }`,
"'"+escapePowerShellSingleQuoted(opts.ExePath)+"'",
strings.Join(argList, ","),
)
candidates := checks.CommandCandidates("powershell.exe")
if len(candidates) == 0 {
return fmt.Errorf("command %q not available at expected absolute path", "powershell.exe")
}
out, err := exec.Command(
candidates[0],
"-NoProfile",
"-NonInteractive",
"-Command",
script,
).CombinedOutput()
return commandError(out, err)
}