feat(npm): add platform-specific package builds - #56
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 21, 2026, 11:10 AM ET / 15:10 UTC. ClawSweeper reviewWhat this changesAdds an optional platform selector to the npm package builder, with matching package names, installation restrictions, tests, and local-build documentation. Merge readiness✅ Ready for maintainer review Keep open: this is a useful, bounded addition absent from current main and v0.1.8. No blocking correctness or security defects were found, and the existing universal release path remains intact. Priority: P2 Review scores
Verification
How this fits togetherClawScan’s npm package builder compiles the Go CLI and bundles it with a Node launcher and binary resolver. The resulting tarballs support local installation and the existing release workflow. flowchart TD
A[Build version and optional platform] --> B[Validate supported target]
B --> C[Compile selected or all binaries]
C --> D[Stage launcher and package metadata]
D --> E[Pack npm tarball]
E --> F[Optional installed CLI smoke check]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Retain the universal release default while supporting smaller local tarballs through the existing builder and resolver. Do we have a high-confidence way to reproduce the issue? Not applicable: this adds an optional build capability; source inspection confirms that main and v0.1.8 currently build universal npm packages. Is this the best way to solve the issue? Yes: extending the existing producer preserves the runtime, binary layout, and universal publishing path while avoiding a parallel packaging implementation. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 0a95ab4b7b58. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Summary
The npm package currently bundles six binaries even when only one platform is needed. Add
--platform <os>-<arch>to the existing producer so maintainers can build a tarball containing one supported binary. The default still builds the universal@openclaw/clawscanpackage.Selected packages use
@openclaw/clawscan-<platform>, with matching npmosandcpurestrictions. They retain the existing command, binary layout, resolver export and TypeScript declaration. The README documents local builds and installation.Scope
Measured package sizes
Actual npm tarballs built with Node 24.18.1, npm 12.0.2 and Go 1.27.0:
The old and new default producers generated byte-identical universal tarballs (SHA256
f656051a7f997f06c85c707a1ca6f4b13795ee7aa9e1d1287d2150d8e872e2ea). This comparison used the old producer from0a95ab4under the same candidate Git commit/date, dirty working-tree VCS metadata and toolchain as the new producer; it is a controlled producer comparison.Each selected package contains seven files instead of twelve. Its binary and all retained non-manifest files are byte-identical to the corresponding universal payload; only package name,
osandcpuchange in the manifest.Verification
node --test npm/clawscan/test/*.test.mjs scripts/build-npm-package.test.mjs: 21/21 passed locally and on Linux.node scripts/build-npm-package.mjs --version v0.0.0 --pack --smoke: passed; all six--platformvariants also built and packed with distinct output directories.--version, static JSON scan and the public resolver export passed. Scan findings and behavioral output match after excluding only timestamps/duration.EBADPLATFORM, without platform overrides.git diff --check, Node syntax check and structured source review passed.Notes
The producer grows by 28 lines to add target selection and package metadata handling; runtime code is unchanged. Registry publication and releases were not performed.