-
Notifications
You must be signed in to change notification settings - Fork 171
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·123 lines (110 loc) · 4.78 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·123 lines (110 loc) · 4.78 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
#!/bin/bash
set -e
cd "$(dirname "$0")"
# --- Platform Gate ---
OS="$(uname -s)"
case "$OS" in
Linux)
# Standard Linux environment (including WSL2)
;;
Darwin)
if [ "$(uname -m)" = "arm64" ]; then
echo "macOS (Apple Silicon) detected: microsandbox microVMs run via Hypervisor.framework."
else
echo "WARNING: macOS on Intel is unsupported for microVM isolation."
echo " Set sandbox.type to 'static-only' in workflow.json for static-only analysis."
fi
;;
CYGWIN*|MINGW*|MSYS*)
echo "ERROR: Native Windows is not supported due to shell and virtualenv layout differences (.venv/Scripts vs .venv/bin)." >&2
echo " Please use WSL2 (Windows Subsystem for Linux), where Mantis runs unmodified." >&2
exit 1
;;
*)
echo "WARNING: Unrecognized platform '$OS'. Proceeding with standard installation..."
;;
esac
# --- Python Version Gate ---
if ! python3 -c 'import sys; sys.exit(0 if sys.version_info >= (3, 12) else 1)' 2>/dev/null; then
echo "ERROR: Mantis requires Python 3.12 or newer." >&2
echo " Current interpreter: $(python3 --version 2>&1 || echo 'none')" >&2
exit 1
fi
echo "Setting up virtual environment..."
python3 -m venv .venv
source .venv/bin/activate
echo "Installing dependencies..."
pip install --require-hashes -r requirements.txt
# --- Sandbox image (optional: enables dynamic reproduction) ---
TAG="mantis-sandbox:latest"
build_image() {
local tool="$1" tar
tar="$(mktemp -t mantis-sandbox-XXXXXX.tar)"
local status=0
{
"$tool" build -t "$TAG" ./sandbox &&
case "$tool" in
buildah) buildah push "$TAG" "oci-archive:$tar" ;;
podman) podman save --format oci-archive -o "$tar" "$TAG" ;;
docker) docker save -o "$tar" "$TAG" ;;
esac &&
.venv/bin/msb image load -i "$tar" -t "$TAG"
} || status=$?
rm -f "$tar"
return "$status"
}
if .venv/bin/msb image list 2>/dev/null | grep -q "mantis-sandbox"; then
echo "Sandbox image '$TAG' already cached; skipping build."
else
BUILD_SUCCESS=0
for t in buildah podman docker; do
if command -v "$t" >/dev/null 2>&1; then
echo "Attempting to build sandbox image with $t..."
if build_image "$t"; then
BUILD_SUCCESS=1
echo "Successfully built and loaded '$TAG' with $t."
break
else
echo "Building with $t failed; trying next builder if available..."
fi
fi
done
if [ "$BUILD_SUCCESS" -eq 0 ]; then
# Fallback: no container builder on this host (typical macOS dev
# machine). Pull a pinned base image straight into the microsandbox
# cache instead. This is the only time a pull happens -- the runtime
# always boots with PullPolicy.NEVER. Keep this list in sync with
# MICROSANDBOX_FALLBACK_IMAGES in scripts/configure.py.
# mirror.gcr.io first: some networks block Docker Hub.
PULL_SUCCESS=0
for img in "mirror.gcr.io/library/python:3-slim" "docker.io/library/python:3-slim"; do
echo "No container builder found; pulling base image '$img' into the sandbox cache..."
if .venv/bin/msb image pull "$img"; then
PULL_SUCCESS=1
echo "Successfully cached '$img'. Auto-configure will select it as the guest image."
break
else
echo "Pulling '$img' failed; trying next mirror if available..."
fi
done
if [ "$PULL_SUCCESS" -eq 0 ]; then
echo "WARNING: could not build (buildah, podman, docker) or pull a sandbox guest image."
echo " Dynamic reproduction needs a cached guest image; fix network/registry access"
echo " and re-run ./install.sh, or set sandbox.type to 'static-only' in workflow.json."
fi
fi
fi
# --- Authoritative MANTIS_HOME ---
# Skills instruct agents to anchor every script invocation via "$MANTIS_HOME/reference/...".
# That anchoring is what keeps an agent from executing a same-named script out of an
# untrusted checkout, so MANTIS_HOME must be set by something authoritative rather than
# left to the operator. Emit it as a sourceable file next to the install root.
MANTIS_HOME_DIR="$(cd .. && pwd)"
cat > mantis-env.sh <<EOF
# Generated by reference/install.sh. Source this before invoking Mantis skills.
export MANTIS_HOME="$MANTIS_HOME_DIR"
EOF
echo "Wrote reference/mantis-env.sh (export MANTIS_HOME=\"$MANTIS_HOME_DIR\")."
echo "Add 'source \"$MANTIS_HOME_DIR/reference/mantis-env.sh\"' to your shell profile so"
echo "skill invocations anchor to this installation instead of the current directory."
echo "Setup complete! You can now run ./run.sh"