feat(packaging): load JavaScript from app.asar and unpack only native files - #647
Merged
Merged
Conversation
… files Align the package layout with upstream deepseek-harness apps/desktop. Since #646 every consumer of the bundled packages runs on the Electron runtime (main, utility process, Helper in Node mode), which reads app.asar, so unpacking all of node_modules bought nothing: about 21k loose files that slowed installs and put "app.asar" in physical paths for dependencies' path heuristics to trip over. - asarUnpack keeps only native addons/libraries, spawn-helper, ripgrep, the LibreOffice engine and sherpa-onnx platform packages and the PPT runtime (macOS arm64: 1.6k files / 235 MB unpacked, was 21k / 549 MB). - Remove runtimePackageRoot; the bundled runtime root is app.getAppPath(). - build/office-engine-resolution.mjs (adapted from upstream desktop-host office-engine.ts) resolves the LibreOffice engine package to app.asar.unpacked so the OS can spawn its executable; registered in harness-node-entry. - Drop the node-pty patch: upstream node-pty maps app.asar to app.asar.unpacked itself, which is correct in this layout. - afterPack (scripts/after-pack.cjs) now verifies the PPT runtime through app.asar and fails when a Mach-O/ELF/PE file is packed inline. - Windows release smoke loads koffi and pnpm through app.asar. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…g findings With blocking compatibility findings the sidebar button reopened the Safe Mode manager and returned. When the manager was already open the click had no visible effect, while the manager's own restart button asked for confirmation and exited. Ask the same question as the manager's restart button (shared safeModeExitConfirmation / safeModeBlockingGroupCount): "Exit anyway" leaves Safe Mode, "Manage plugins" opens the manager. When the manager is open and waiting, the exit is handed to its restart action so relaunch, the unresolved-findings note and a fall-back into Safe Mode are handled in one place. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #646 (base:
fix/node-pty-unpacked-helper). It aligns the package layout with upstreamdeepseek-harnessapps/desktop.Why
Since #646, every consumer of the bundled packages runs on the Electron runtime: the main process, the Harness utility process on macOS, and the Helper or executable in Node mode for package commands and shims. That runtime reads
app.asar. Unpacking all ofnode_modulestherefore bought nothing, and it caused two problems:app.asar, which tripped dependencies' path heuristics (the node-ptyapp.asar.unpacked.unpackedbug fixed in fix(mac): terminal posix_spawn ENOENT; run package commands on the Electron Helper and drop bundled Node #646).Changes
asarUnpackkeeps only what the OS loads or executes: native addons and libraries, node-ptyspawn-helper, ripgrep, the LibreOffice engine and sherpa-onnx platform packages, and the PPT runtime.runtimePackageRoot; the bundled runtime root isapp.getAppPath()(app.asarwhen packaged).build/office-engine-resolution.mjsis adapted from upstreamapps/desktop-host/src/office-engine.ts. It resolves@deepseek-ai/libreoffice-kit-<platform>-*toapp.asar.unpacked, because libreoffice-kit derives the engine executable from that package's resolved path, and through the archive the executable failsstat/spawn ("executable is not executable"). It is registered inharness-node-entryand is a no-op outside anapp.asarlayout. Like upstream, it canonicalizes the archive path before the prefix comparison. Otherwise a symlinked or junctioned install, Windows 8.3 names or drive-letter case would leave the engine inside the archive.app.asar→app.asar.unpackedmapping is correct in this layout. Upstream relies on the same behaviour.scripts/after-pack.cjs):app.asaron the packaged Helper;scripts/verify-asar-unpack.cjsfails packaging when a Mach-O, ELF or PE file is packed inline.app.asar.Startup stages touched (AGENTS.md table):
app.asar.app.asar. Profiles and generations hold no links into the installation directory.Also included: Safe Mode sidebar exit
With blocking compatibility findings, the sidebar "Exit Safe Mode" button reopened the already-open manager and returned, so the click did nothing visible. The manager's own restart button asked for confirmation and exited.
The sidebar button now asks the same question (shared
safeModeExitConfirmation). "Exit anyway" leaves Safe Mode; "Manage plugins" opens the manager. When the manager is open and waiting, the exit goes through itsrestartaction.Checked: unit tests in
test/safe-mode.test.ts. Not yet clicked in the real Safe Mode UI with blocking findings.Checks
npm test: 180 files / 1606 tests.npm run typecheckandgit diff --checkpass.node-pty-asar-layoutspawns a PTY with unpatched node-pty loaded fromapp.asarand natives in.unpacked;office-engine-resolutionresolves the engine on the Electron runtime, with and without the hook, and through a linked install directory;verify-asar-unpackrejects an inline Mach-O and accepts it once unpacked.package:dev:diron macOS arm64 passes both afterPack gates. Unpacked files went from 21,212 (549 MB) to 1,596 (235 MB);app.asaris 281 MB.app.asarin the utility process and is ready in about 1.6 s. The UI mounts, including the PPT plugin.echoreturns/bin/zsh arm64on unpatched node-pty..desktop-binpnpm shim runs theapp.asarpnpm.app.asar.Not verified
app.asar, which the CI smoke does not cover.🤖 Generated with Claude Code