Files
gemini-cli/scripts/build_binaries.js
Daniel Young Lee 55747791ba fix: address security and reliability issues in build_binaries.js
- Use execFileSync instead of execSync to prevent shell injection
- Exit with non-zero code when builds fail for CI integrity
- Capture and display stderr for better error diagnostics
- Fixes CodeQL security warning about shell command injection
2025-08-10 13:31:06 -07:00

96 lines
2.7 KiB
JavaScript

/**
* @license
* Copyright 2025 Google LLC
* SPDX-License-Identifier: Apache-2.0
*/
import { execFileSync } from 'child_process';
import fs from 'fs';
import path from 'path';
import { fileURLToPath } from 'url';
const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename);
const rootDir = path.resolve(__dirname, '..');
const bundleJs = path.join(rootDir, 'bundle', 'gemini.js');
const outputDir = path.join(rootDir, 'bundle', 'binaries');
// Binary targets configuration
const targets = [
{ name: 'gemini-cli-darwin-x64', target: 'bun-darwin-x64' },
{ name: 'gemini-cli-darwin-arm64', target: 'bun-darwin-arm64' },
{ name: 'gemini-cli-linux-x64', target: 'bun-linux-x64' },
{ name: 'gemini-cli-linux-arm64', target: 'bun-linux-arm64' },
{ name: 'gemini-cli-windows-x64.exe', target: 'bun-windows-x64' },
];
// Check if bundle/gemini.js exists
if (!fs.existsSync(bundleJs)) {
console.error(
'Error: bundle/gemini.js not found. Please run "npm run bundle" first.',
);
process.exit(1);
}
// Create output directory
if (!fs.existsSync(outputDir)) {
fs.mkdirSync(outputDir, { recursive: true });
console.log(`Created directory: ${outputDir}`);
}
console.log('Building native binaries from bundle/gemini.js...\n');
let successCount = 0;
let failedTargets = [];
for (const { name, target } of targets) {
const outputPath = path.join(outputDir, name);
console.log(`Building ${name}...`);
try {
execFileSync('bun', [
'build',
'--compile',
`--target=${target}`,
bundleJs,
'--outfile',
outputPath
], { stdio: ['pipe', 'pipe', 'pipe'] });
if (fs.existsSync(outputPath)) {
const stats = fs.statSync(outputPath);
const sizeMB = (stats.size / (1024 * 1024)).toFixed(1);
console.log(` ✓ Built ${name} (${sizeMB} MB)`);
successCount++;
} else {
throw new Error('Binary file was not created');
}
} catch (error) {
console.error(` ✗ Failed to build ${name}`);
console.error(` ${error.message}`);
if (error.stderr) {
console.error(` ${error.stderr.toString()}`);
}
failedTargets.push(name);
}
}
console.log('\n' + '='.repeat(50));
console.log(
`Build complete: ${successCount}/${targets.length} binaries built successfully`,
);
if (failedTargets.length > 0) {
console.log(`Failed targets: ${failedTargets.join(', ')}`);
console.log(
'\nNote: Cross-compilation may require Bun 1.1.0+ and might not work for all targets from all host platforms.',
);
console.log(
'In CI, all targets should build successfully on the appropriate runner.',
);
process.exit(1);
}
console.log(`\nBinaries saved to: ${outputDir}`);