Skip to content

fix: make the kubo binary reliably available - #3180

Closed
lidel wants to merge 4 commits into
mainfrom
chore/kubo-from-github-releases
Closed

fix: make the kubo binary reliably available#3180
lidel wants to merge 4 commits into
mainfrom
chore/kubo-from-github-releases

Conversation

@lidel

@lidel lidel commented Jun 27, 2026

Copy link
Copy Markdown
Member

Problem

Two problems, both in how ipfs-desktop gets the kubo binary:

  1. It can go missing. The binary is fetched by a postinstall script, so it never lands when npm skips that script (--ignore-scripts, pnpm, hardened CI, and the upcoming npm v12 default). The app then shows "kubo binary not found" and the daemon won't start (Error: kubo binary not found #3031).
  2. One source. It only came from dist.ipfs.tech.

Fix

Adopt the new kubo (ipfs/npm-kubo#83), which tackles both:

  • it downloads the binary on first use, so a skipped script heals itself, and
  • it fetches from GitHub releases, with dist.ipfs.tech still working behind a deprecation warning.

The macOS universal build moves to GitHub too. The kubo version is unchanged; see the npm-kubo PR for details. CI tracks the branch for now and will pin a published version before merge.

TODO before merging this

lidel added 2 commits June 27, 2026 15:41
Parked until kubo is bumped to the npm-kubo release that fetches from
GitHub releases (ipfs/npm-kubo#83). The current kubo still uses the
dist.ipfs.tech layout, so do not merge before that bump.
Temporary: point the kubo dependency at the ipfs/npm-kubo#83 branch over
git+https so CI clones it and exercises the GitHub-releases fetch end to
end. Revert to a published kubo version before merging.
@socket-security

socket-security Bot commented Jun 27, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedkubo@​0.42.0 ⏵ 0.42.0N/AN/AN/AN/AN/A

View full report

@lidel lidel changed the title Chore/kubo from GitHub releases fix: make the kubo binary reliably available Jun 27, 2026
Bump the pinned npm-kubo commit to the one that creates bin/ before
linking, so CI's git install no longer fails. Revert with the rest of
the test wiring before merge.
@lidel
lidel marked this pull request as ready for review June 28, 2026 12:31
@lidel
lidel requested a review from a team as a code owner June 28, 2026 12:31
ipfs/npm-kubo#83 (on-demand binary fetch from github releases)
landed on master. Pin the kubo dependency to the latest npm-kubo
master commit and drop the macos build TODO that was gating the
switch.
@lidel

lidel commented Jul 23, 2026

Copy link
Copy Markdown
Member Author

Continued in #3188

@lidel lidel closed this Jul 23, 2026
lidel added a commit that referenced this pull request Aug 3, 2026
* chore: kubo 0.43.0-rc1

Release candidate, for smoke-testing ahead of the v0.43.0 final.

* chore: electron 43.2.0

Brings Chromium 150 and V8 15.0; Node stays on 24.x. None of the
Electron 43 breaking changes reach this app: both showOpenDialog call
sites already pass an explicit defaultPath, showHiddenFiles is unused,
toBitmap is never called, and no window sets titleBarOverlay. The splash
is the only frameless window and its artwork clears the new 8 DIP corner
clip on Linux, so roundedCorners keeps its default.

ensure-electron.js justified its own download path by naming extract-zip,
which electron's install.js no longer uses. Reword around the reason that
still holds, and drop the version-specific framing so it survives the
next bump.

* fix: capture screenshots in the main process

Electron 17 removed desktopCapturer from the renderer, so the preload
has seen it as undefined ever since this app moved to Electron 17 in
v0.19.0, and both the tray item and the global shortcut have thrown a
TypeError on every use. No webPreferences setting brings it back:
sandbox:false and nodeIntegration:true each still leave it undefined.

Capture where the API actually lives instead, asking for thumbnails at
the display's pixel size so they are full-resolution grabs rather than
previews. That drops the renderer round-trip along with getUserMedia,
ImageCapture and the canvas data URL.

- take-screenshot: captureScreens() over desktopCapturer and screen
- webui/screenshot.js and its preload hook are gone
- ipc-main-events: nothing sends SCREENSHOT any more

An empty thumbnail is how a missing macOS screen-recording grant
presents itself, so treat "no usable screen" as an error and raise the
existing notification rather than failing silently.

Closes #2306

* fix(macos): fetch kubo from github releases

kubo 0.43 deprecated distUrl: passing it at all takes the old
dist.ipfs.tech code path and prints a deprecation notice on every build.
The universal binary step was the last caller still doing that, so move
it to releasesUrl, which is where the package already defaults.

Matches #3180, which this branch otherwise supersedes by pinning the
published kubo release rather than a git revision.

* chore: kubo 0.43.0-rc2

* chore: npm audit fix

Resolves 15 advisories in transitive dependencies, all within the
existing semver ranges, so package.json is unchanged.

The 14 remaining need `npm audit fix --force`, which would install
ipfsd-ctl@17 as a breaking change.

* chore: kubo 0.43.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Error: kubo binary not found

1 participant