-
Notifications
You must be signed in to change notification settings - Fork 14
Fix release AppImage and TestFlight CI #540
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -742,26 +742,58 @@ prepare_tauri_linuxdeploy_tools_cache() { | |
| return 1 | ||
| fi | ||
|
|
||
| local arch linuxdeploy_arch tools cache wrapper | ||
| local arch linuxdeploy_arch tools cache bash_path linuxdeploy_wrapper appimage_wrapper | ||
| arch="$(linuxdeploy_tools_arch)" | ||
| linuxdeploy_arch="${arch}" | ||
| tools="${MAPLE_NIX_TAURI_LINUXDEPLOY_TOOLS}" | ||
| cache="${TAURI_DIR}/target/.tauri" | ||
| wrapper="${cache}/linuxdeploy-plugin-appimage.AppImage" | ||
| bash_path="$(command -v bash)" | ||
|
Comment on lines
+745
to
+750
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Use a sandbox-stable shebang for the generated wrappers. Line 750 captures the host Suggested fix- local arch linuxdeploy_arch tools cache bash_path linuxdeploy_wrapper appimage_wrapper
+ local arch linuxdeploy_arch tools cache linuxdeploy_wrapper appimage_wrapper
@@
- bash_path="$(command -v bash)"
linuxdeploy_wrapper="${cache}/linuxdeploy-${linuxdeploy_arch}.AppImage"
appimage_wrapper="${cache}/linuxdeploy-plugin-appimage.AppImage"
@@
-#!${bash_path}
+#!/bin/bash
@@
-#!${bash_path}
+#!/bin/bashAlso applies to: 764-766, 791-793 🤖 Prompt for AI Agents |
||
| linuxdeploy_wrapper="${cache}/linuxdeploy-${linuxdeploy_arch}.AppImage" | ||
| appimage_wrapper="${cache}/linuxdeploy-plugin-appimage.AppImage" | ||
|
|
||
| mkdir -p "${cache}" | ||
| install -m 0755 "${tools}/AppRun-${arch}" "${cache}/AppRun-${arch}" | ||
| install -m 0755 "${tools}/linuxdeploy-${linuxdeploy_arch}.AppImage" "${cache}/linuxdeploy-${linuxdeploy_arch}.AppImage" | ||
| install -m 0755 "${tools}/linuxdeploy-${linuxdeploy_arch}.AppImage" "${cache}/linuxdeploy-${linuxdeploy_arch}.real.AppImage" | ||
| install -m 0755 "${tools}/linuxdeploy-plugin-appimage.real.AppImage" "${cache}/linuxdeploy-plugin-appimage.real.AppImage" | ||
| install -m 0755 "${tools}/linuxdeploy-plugin-gtk.sh" "${cache}/linuxdeploy-plugin-gtk.sh" | ||
| install -m 0755 "${tools}/linuxdeploy-plugin-gstreamer.sh" "${cache}/linuxdeploy-plugin-gstreamer.sh" | ||
|
|
||
| cat > "${wrapper}" <<'EOF' | ||
| #!/usr/bin/env bash | ||
| extract_appimage_tool "${cache}/linuxdeploy-${linuxdeploy_arch}.real.AppImage" "${cache}/linuxdeploy-${linuxdeploy_arch}.AppDir" | ||
| extract_appimage_tool "${cache}/linuxdeploy-plugin-appimage.real.AppImage" "${cache}/linuxdeploy-plugin-appimage.AppDir" | ||
|
|
||
| cat > "${linuxdeploy_wrapper}" <<EOF | ||
| #!${bash_path} | ||
| set -euo pipefail | ||
|
|
||
| script_dir="\$(CDPATH= cd -- "\$(dirname -- "\$0")" && pwd)" | ||
| app_run="\${script_dir}/linuxdeploy-${linuxdeploy_arch}.AppDir/AppRun" | ||
|
|
||
| if [ ! -x "\${app_run}" ]; then | ||
| echo "Missing extracted linuxdeploy AppRun at \${app_run}" >&2 | ||
| exit 1 | ||
| fi | ||
|
|
||
| args=() | ||
| for arg in "\$@"; do | ||
| case "\${arg}" in | ||
| --appimage-extract-and-run) | ||
| ;; | ||
| *) | ||
| args+=("\${arg}") | ||
| ;; | ||
| esac | ||
| done | ||
|
|
||
| exec "\${app_run}" "\${args[@]}" | ||
| EOF | ||
| chmod +x "${linuxdeploy_wrapper}" | ||
|
|
||
| cat > "${appimage_wrapper}" <<EOF | ||
| #!${bash_path} | ||
| set -euo pipefail | ||
|
|
||
| for arg in "$@"; do | ||
| case "${arg}" in | ||
| for arg in "\$@"; do | ||
| case "\${arg}" in | ||
| --plugin-type) | ||
| printf '%s\n' output | ||
| exit 0 | ||
|
|
@@ -775,48 +807,75 @@ done | |
|
|
||
| appdir="" | ||
| previous="" | ||
| for arg in "$@"; do | ||
| if [ "${previous}" = "--appdir" ]; then | ||
| appdir="${arg}" | ||
| for arg in "\$@"; do | ||
| if [ "\${previous}" = "--appdir" ]; then | ||
| appdir="\${arg}" | ||
| previous="" | ||
| continue | ||
| fi | ||
|
|
||
| case "${arg}" in | ||
| case "\${arg}" in | ||
| --appdir=*) | ||
| appdir="${arg#--appdir=}" | ||
| appdir="\${arg#--appdir=}" | ||
| ;; | ||
| --appdir) | ||
| previous="--appdir" | ||
| ;; | ||
| esac | ||
| done | ||
|
|
||
| if [ -n "${appdir}" ]; then | ||
| rm -f "${appdir}/.DirIcon" | ||
| if [ -n "\${appdir}" ]; then | ||
| rm -f "\${appdir}/.DirIcon" | ||
| fi | ||
|
|
||
| script_dir="$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)" | ||
| real_plugin="${script_dir}/linuxdeploy-plugin-appimage.real.AppImage" | ||
| script_dir="\$(CDPATH= cd -- "\$(dirname -- "\$0")" && pwd)" | ||
| real_plugin="\${script_dir}/linuxdeploy-plugin-appimage.AppDir/AppRun" | ||
|
|
||
| if [ ! -x "${real_plugin}" ]; then | ||
| echo "Missing real linuxdeploy AppImage plugin at ${real_plugin}" >&2 | ||
| if [ ! -x "\${real_plugin}" ]; then | ||
| echo "Missing extracted linuxdeploy AppImage plugin at \${real_plugin}" >&2 | ||
| exit 1 | ||
| fi | ||
|
|
||
| APPIMAGE_EXTRACT_AND_RUN=1 exec "${real_plugin}" --appimage-extract-and-run "$@" | ||
| exec "\${real_plugin}" "\$@" | ||
| EOF | ||
| chmod +x "${wrapper}" | ||
| chmod +x "${appimage_wrapper}" | ||
|
|
||
| print_file_hashes \ | ||
| "${cache}/AppRun-${arch}" \ | ||
| "${cache}/linuxdeploy-${linuxdeploy_arch}.real.AppImage" \ | ||
| "${cache}/linuxdeploy-${linuxdeploy_arch}.AppImage" \ | ||
| "${cache}/linuxdeploy-${linuxdeploy_arch}.AppDir/AppRun" \ | ||
| "${cache}/linuxdeploy-plugin-appimage.real.AppImage" \ | ||
| "${cache}/linuxdeploy-plugin-appimage.AppImage" \ | ||
| "${cache}/linuxdeploy-plugin-appimage.AppDir/AppRun" \ | ||
| "${cache}/linuxdeploy-plugin-gtk.sh" \ | ||
| "${cache}/linuxdeploy-plugin-gstreamer.sh" | ||
| } | ||
|
|
||
| extract_appimage_tool() { | ||
| local appimage="$1" | ||
| local out="$2" | ||
| local tmp | ||
|
|
||
| tmp="$(mktemp -d)" | ||
| rm -rf "${out}" | ||
|
|
||
| if ! (cd "${tmp}" && "${appimage}" --appimage-extract >/dev/null); then | ||
| rm -rf "${tmp}" | ||
| return 1 | ||
| fi | ||
|
|
||
| if [ ! -x "${tmp}/squashfs-root/AppRun" ]; then | ||
| echo "Extracted AppImage is missing AppRun: ${appimage}" >&2 | ||
| rm -rf "${tmp}" | ||
| return 1 | ||
| fi | ||
|
|
||
| mv "${tmp}/squashfs-root" "${out}" | ||
| chmod -R u+w "${out}" 2>/dev/null || true | ||
| rm -rf "${tmp}" | ||
| } | ||
|
|
||
| print_tree_hash() { | ||
| local dir="$1" | ||
| local label="${2:-$(repo_relative_path "${dir}")}" | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Validate
APPLE_API_ISSUERin the same fail-fast guard.This step still lets the job reach
altoolwith an empty issuer, even though Line 192 requires it. Adding the issuer here makes the TestFlight failure immediate and actionable.Suggested patch
- name: Prepare App Store Connect API key env: + APPLE_API_ISSUER: ${{ secrets.APPLE_API_ISSUER }} APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }} APPLE_API_PRIVATE_KEY: ${{ secrets.APPLE_API_PRIVATE_KEY }} run: | set -euo pipefail - if [ -z "${APPLE_API_KEY}" ] || [ -z "${APPLE_API_PRIVATE_KEY}" ]; then - echo "APPLE_API_KEY and APPLE_API_PRIVATE_KEY are required to submit to TestFlight." >&2 + if [ -z "${APPLE_API_ISSUER}" ] || [ -z "${APPLE_API_KEY}" ] || [ -z "${APPLE_API_PRIVATE_KEY}" ]; then + echo "APPLE_API_ISSUER, APPLE_API_KEY, and APPLE_API_PRIVATE_KEY are required to submit to TestFlight." >&2 exit 1 fi🤖 Prompt for AI Agents