Skip to content
Merged
Show file tree
Hide file tree
Changes from 4 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/release-notes/imcp2-local-install-note.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
<!-- install-script-summary -->
> **What the install scripts below do:** each downloads the `imcp2-local` binary for your platform from this release, installs it plus an auto-updater into `~/.cargo/bin`, and adds that directory to your PATH — the shell script by appending a line to every shell profile it can find, the PowerShell script by editing your `Path` registry key. The shell script also compares a checksum baked into itself, but skips that check silently on stock macOS, which has no `sha256sum`; the PowerShell script does not check one at all. Where that shell checksum does run it ships inside the very script being piped to a shell, so on either platform the attestation commands at the end of these notes are what establish provenance — `IMCP2_LOCAL_NO_MODIFY_PATH=1` and `IMCP2_LOCAL_DISABLE_UPDATE=1` opt out of the PATH edits and the updater.
>
> **Then connect it to your AI tool:** `imcp2-local setup` registers the server with the clients on this machine — Claude Desktop, Claude Code, Codex, Cursor, Antigravity — and prints Perplexity's UI steps; `imcp2-local setup --print` shows each client's steps without writing anything, and `imcp2-local setup --remove` undoes them. Restart the client afterwards. The [README](https://github.com/dfinity/imcp2/blob/main/crates/imcp2-local/README.md#register-it-with-your-ai-tools) lists the per-client registration each one receives.
61 changes: 61 additions & 0 deletions .github/workflows/imcp2-local-install-note.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# Prepends a plain-language summary of what the install scripts do to the
# release notes `dist` writes for an `imcp2-local-v*` release.
#
# Why a job rather than a setting: dist builds the release body itself (the
# install one-liners, the download table, the attestation section) and has no
# config for extra prose — a custom job is the only documented seam. This one
# hangs off `post-announce-jobs` in dist-workspace.toml, so `dist generate`
# keeps wiring it in and the release workflow stays reproducible from config.
#
# The prose lives in .github/release-notes/imcp2-local-install-note.md so it
# is reviewed as rendered markdown rather than as a string inside YAML. Keep
# it in step with the installers and with the crate README's Install section.
#
# Runs after the release is published and edits the notes in place; the
# marker in that file makes a re-run a no-op.
name: imcp2-local install note

on:
workflow_call:
inputs:
plan:
required: true
type: string

jobs:
install-note:
runs-on: ubuntu-22.04
Comment thread
aterga marked this conversation as resolved.
Outdated
permissions:
contents: write
env:
PLAN: ${{ inputs.plan }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NOTE_FILE: .github/release-notes/imcp2-local-install-note.md
steps:
# Pinned to a commit SHA, as every other action in this pipeline is.
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
with:
persist-credentials: false

- name: Prepend the install-script summary to the release notes
shell: bash
run: |
set -euo pipefail

tag="$(printf '%s' "$PLAN" | jq -er '.announcement_tag')"
marker="$(head -n 1 "$NOTE_FILE")"

body="$(gh release view "$tag" --repo "$GITHUB_REPOSITORY" --json body -q .body)"
if printf '%s' "$body" | grep -qF "$marker"; then
Comment thread
aterga marked this conversation as resolved.
Outdated
echo "summary already present on $tag — nothing to do"
exit 0
fi

{
cat "$NOTE_FILE"
printf '\n%s\n' "$body"
} > "$RUNNER_TEMP/notes.md"

gh release edit "$tag" --repo "$GITHUB_REPOSITORY" --notes-file "$RUNNER_TEMP/notes.md"
echo "install-script summary added to $tag"
9 changes: 9 additions & 0 deletions .github/workflows/imcp2-local-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -302,3 +302,12 @@ jobs:
with:
persist-credentials: false
submodules: recursive

custom-imcp2-local-install-note:
needs:
- plan
- announce
uses: ./.github/workflows/imcp2-local-install-note.yml
with:
plan: ${{ needs.plan.outputs.val }}
secrets: inherit
53 changes: 50 additions & 3 deletions crates/imcp2-local/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,9 +17,56 @@ cannot spawn local processes; they keep using the hosted server.
## Install

Release binaries (macOS arm64/x64, Linux x64/arm64, Windows x64) ship from
this repository's GitHub releases with shell/PowerShell installers, built by
`dist` from `imcp2-local-v*` tags. Until the first release is cut, build from
source:
this repository's GitHub releases, built by `dist` from `imcp2-local-v*` tags.

**Verified install.** This binary acts as your Internet Identity, so prefer the
path that establishes where the artifact came from. Download the archive, check
its provenance against the workflow that built it, then install it into a
directory on your `PATH`:

```sh
# Resolve the newest binary release. `releases/latest` is NOT this crate's:
# production deploys publish `release-*` releases in this same repository, so
# the repository's latest release is usually one of those. Paginate rather
# than take a first page, for the same reason — this crate's tag is a small
# minority of the releases here.
TAG=$(gh api --paginate repos/dfinity/imcp2/releases --jq '.[].tag_name' \
| grep -m1 '^imcp2-local-v')
TARGET=aarch64-apple-darwin # or x86_64-apple-darwin, {x86_64,aarch64}-unknown-linux-gnu

# Chained: a failed download or a failed attestation stops the install.
curl -fLO "https://github.com/dfinity/imcp2/releases/download/$TAG/imcp2-local-$TARGET.tar.xz" &&
gh attestation verify "imcp2-local-$TARGET.tar.xz" -R dfinity/imcp2 \
--signer-workflow dfinity/imcp2/.github/workflows/imcp2-local-release.yml &&
Comment thread
Copilot marked this conversation as resolved.
Outdated
tar xf "imcp2-local-$TARGET.tar.xz" &&
mkdir -p ~/.local/bin &&
install "imcp2-local-$TARGET/imcp2-local" ~/.local/bin/
```

`~/.local/bin` stands in for any directory already on your `PATH`; the last
two commands create it and copy the binary there, nothing edits your shell
configuration.

(Windows ships `imcp2-local-x86_64-pc-windows-msvc.zip`; verify it the same way.)

**Installer script.** Shorter, and what the release notes lead with. It
downloads the binary for your platform, installs it plus an auto-updater into
`~/.cargo/bin`, and adds that directory to your PATH by appending a line to
every shell profile it can find — `IMCP2_LOCAL_NO_MODIFY_PATH=1` and
`IMCP2_LOCAL_DISABLE_UPDATE=1` opt out of those two. The shell script also
compares a checksum baked into itself, but skips that silently on stock macOS,
which has no `sha256sum`; the PowerShell installer checks none at all. Even
where the shell checksum runs, it ships inside the very script being piped to
a shell, so it catches a corrupted download rather than a bad release. On both
platforms the attestation above is what establishes provenance.

```sh
# Substitute the newest imcp2-local-v* tag; each release's notes carry the
# current command, and `releases/latest` is not this crate's release (above).
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/dfinity/imcp2/releases/download/imcp2-local-v0.5.0/imcp2-local-installer.sh | sh
```

**From source.**

```sh
cargo build --release -p imcp2-local
Expand Down
4 changes: 4 additions & 0 deletions dist-workspace.toml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,10 @@ install-updater = true
tag-namespace = "imcp2-local"
# Whether to enable GitHub Attestations
github-attestations = true
# Prepend a plain-language summary of what the install scripts do to the
# release notes. dist writes the body itself and has no setting for extra
# prose, so this rides its custom-job seam; see the workflow for the text.
post-announce-jobs = ["./imcp2-local-install-note"]

# Pin GitHub Actions to exact commit SHAs in the generated release.yml
[dist.github-action-commits]
Expand Down
Loading