Files
shorebird/OPEN_SOURCE_REPLACEMENTS.md
T
Tony d9088aeec6
ci / 📄 License Check (push) Has been cancelled
ci / ✅ Semantic Pull Request (push) Has been cancelled
ci / 🔤 Check Spelling (push) Has been cancelled
ci / 👀 Detect Changes (push) Has been cancelled
ci / 🎯 Build ${{ matrix.package }} (${{ matrix.os }}) (push) Has been cancelled
ci / 🎯 Build ${{ matrix.package }} (push) Has been cancelled
ci / 🔎 Verify ${{ matrix.package }} (push) Has been cancelled
ci / ci (push) Has been cancelled
Deploy Artifact Proxy Dev / ☁️ Artifact Proxy (push) Has been cancelled
Shorebird CI / changes (push) Has been cancelled
Shorebird CI / CSpell (push) Has been cancelled
Shorebird CI / artifact_proxy (push) Has been cancelled
Shorebird CI / dex (push) Has been cancelled
Shorebird CI / discord_gcp_alerts (push) Has been cancelled
Shorebird CI / flutter_version_resolver (push) Has been cancelled
Shorebird CI / jwt (push) Has been cancelled
Shorebird CI / scoped_deps (push) Has been cancelled
Shorebird CI / shorebird_build_trace (push) Has been cancelled
Shorebird CI / shorebird_ci (push) Has been cancelled
Shorebird CI / shorebird_cli (push) Has been cancelled
Shorebird CI / shorebird_code_push_client (push) Has been cancelled
Shorebird CI / shorebird_code_push_protocol (push) Has been cancelled
Shorebird CI / shorebird_redis_client (push) Has been cancelled
Shorebird CI / stripe_api (push) Has been cancelled
Shorebird CI / required (push) Has been cancelled
Refactor Shorebird CLI to support configurable URLs and improve test coverage
- Updated AAR releaser test to use ShorebirdProcess.defaultFlutterStorageBaseUrl.
- Changed macOS releaser test to reference a new troubleshooting URL.
- Enhanced shorebird_yaml_test with deserialization for AOT patch metadata.
- Modified network_checker_test to check self-hosted URLs from ShorebirdEnv.
- Added tests for artifact paths in shorebird_artifacts_test.
- Updated shorebird_cli_command_runner_test to reflect new repository URL.
- Improved shorebird_env_test with additional tests for shorebirdRoot and engine revision fallback.
- Adjusted shorebird_flutter_test to use environment variables for Flutter Git URL.
- Updated shorebird_process_test to utilize default Flutter storage URL.
- Enhanced shorebird_validator_test to link to the default hosted URL.
- Updated shorebird_web_console_test to use the configured hosted URL.
- Refactored code_push_client to use default hosted URL for API requests.
- Updated README and generation scripts for the code_push_protocol package to reflect new OpenAPI spec source.
- Modified shared.sh to allow configurable Flutter repository and storage URLs.

Signed-off-by: Tony <tonylu@tony-cloud.com>
2026-06-25 17:21:56 +08:00

4.9 KiB

Open Replacement Audit

Last verified: 2026-06-25.

This workspace is intended to build and operate without closed Shorebird services or closed SDK artifacts. Local forks/submodules are the source of truth: do not clone official Shorebird infrastructure repositories as a bootstrap default.

Local Sources

The combined workspace provides these open replacements:

Surface Open replacement in this workspace
Shorebird CLI packages/shorebird_cli, configured for the self-hosted server and open artifact mirror
CodePush client/protocol packages/shorebird_code_push_client and packages/shorebird_code_push_protocol
CodePush API/auth/console ../shorebird-server
Artifact mirror/proxy packages/artifact_proxy
Runtime updater library ../updater/library, linked into the Flutter engine by ../scripts/sync_open_sources.sh
Patch artifact generator ../updater/patch and packages/open_aot_patch_tools
Flutter engine and Flutter tool defaults ../flutter, linked to ../dart-sdk-new and ../updater
Dart VM patch runtime ../dart-sdk-new

Run source linking from the workspace root:

./scripts/sync_open_sources.sh

The script links:

flutter/engine/src/flutter/third_party/dart -> dart-sdk-new
flutter/engine/src/flutter/third_party/updater -> updater

Set UPDATER_SRC explicitly only when testing another updater fork. The default path must remain the local updater submodule.

Hosted Surfaces

The open CLI, CodePush client, updater, artifact proxy, and Flutter tool defaults are configured to use local/self-hosted origins when no override is supplied:

Hosted surface Open default
API/auth server http://localhost:8080
OpenAPI contract http://localhost:8080/openapi.yaml and ../shorebird-server/internal/api/handlers/openapi.yaml
CLI patch-tool artifact mirror http://localhost:8080/artifacts
Flutter engine/Maven artifact mirror http://localhost:8080/download.flutter.io
Web console self-hosted shorebird-server/web dashboard

Override these values with SHOREBIRD_HOSTED_URL, SHOREBIRD_ARTIFACT_BASE_URL, SHOREBIRD_FLUTTER_STORAGE_BASE_URL, and SHOREBIRD_FLUTTER_GIT_URL when pointing the CLI at a public mirror. Full SDK CI runs upload open-shorebird-artifact-mirror, which is assembled from the produced patch-tool, metadata, engine, and web artifacts. They also upload open-shorebird-release-manifest, which validates checksum sidecars and records provenance for the CLI, server, SDK, engine, and mirror archives. After downloading CI artifacts manually, run the root scripts/assemble_artifact_mirror.sh helper to reproduce that merge, validate artifacts_manifest.yaml, verify platform patch-*.zip tools, and write missing checksum sidecars before publishing the directory behind SHOREBIRD_ARTIFACT_BASE_URL.

Platform Patch Routes

Platform Patch route
iOS Encrypted Dart bytecode interpreter artifact with DART_DYNAMIC_MODULES=false; does not load downloaded native executable text
Android Native AOT patch runtime using the public updater patch binary and a patch-capable Android engine
macOS/Linux Native AOT patch runtime using the public updater patch binary and patch-capable desktop engines
Windows Public updater patch binary; runtime verification remains platform-runner dependent
Web SDK artifact build only; not a Shorebird CodePush release platform in this CLI/protocol

The iOS App Store candidate route is interpreter-based. Do not reintroduce DART_DYNAMIC_MODULES, aot-tools.dill publishing, or a native-AOT iOS patch route as the default.

CI Contract

The root workflow .github/workflows/open-shorebird-ci.yml builds:

  • CLI archives containing shorebird, open_aot_patch_tools, and artifact_proxy
  • public updater patch-*.zip mirror artifacts
  • self-hosted shorebird-server binaries
  • custom Dart SDK artifacts
  • Linux, Android, web, iOS, and macOS engine/SDK artifacts on manual full_sdk_build=true runs

../scripts/verify_ci_workflow.sh is the executable contract for this audit. It rejects closed hosted defaults, DART_DYNAMIC_MODULES=true, legacy aot-tools.dill publishing, missing checksum sidecars, missing source tests, and missing required artifact jobs.

Security Boundary

The open updater, local server, CLI, and patch tools must enforce:

  • patch metadata compatibility: app id, release/build id, platform, arch, SDK hash, base snapshot hash, flavor id, and license type
  • cryptographic integrity through hash pinning/signing where supported
  • AES-GCM delivery confidentiality and tamper detection for encrypted interpreter payloads
  • limited offline-license expiry through offline_expires_at

Open replacement work should preserve Shorebird-compatible protocol shapes where the CLI/updater expect them, while keeping service origins, SDK builds, and patch tools controlled by this workspace.