Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/android-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,8 @@ jobs:
cat android-release-artifacts.sha256

- name: Attest Android release artifacts
# Keep uploads/verifiers running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: android-release-artifacts.sha256
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/desktop-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,8 @@ jobs:
cat desktop-macos-artifacts.sha256

- name: Attest macOS release artifacts
# Keep uploads/verifiers running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: desktop-macos-artifacts.sha256
Expand Down Expand Up @@ -147,6 +149,8 @@ jobs:
cat desktop-linux-artifacts.sha256

- name: Attest Linux release artifacts
# Keep uploads/verifiers running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: desktop-linux-artifacts.sha256
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/desktop-pr-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,8 @@ jobs:
with:
name: maple-linux-pr
path: |
frontend/src-tauri/target/release/bundle/appimage/*.AppImage
frontend/src-tauri/target/release/bundle/appimage/*.AppImage.sig
frontend/src-tauri/target/release/bundle/deb/*.deb
frontend/src-tauri/target/release/bundle/deb/*.deb.sig
frontend/src-tauri/target/release/bundle/rpm/*.rpm
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/mobile-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,8 @@ jobs:
cat ios-release-artifacts.sha256

- name: Attest iOS release artifacts
# Keep uploads/verifiers running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: ios-release-artifacts.sha256
Expand Down Expand Up @@ -161,12 +163,13 @@ jobs:

- name: Prepare App Store Connect API key
env:
APPLE_API_ISSUER: ${{ secrets.APPLE_API_ISSUER }}
APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }}
APPLE_API_PRIVATE_KEY: ${{ secrets.APPLE_API_PRIVATE_KEY }}
run: |
set -euo pipefail
if [ -z "${APPLE_API_KEY}" ] || [ -z "${APPLE_API_PRIVATE_KEY}" ]; then
echo "APPLE_API_KEY and APPLE_API_PRIVATE_KEY are required to submit to TestFlight." >&2
if [ -z "${APPLE_API_ISSUER}" ] || [ -z "${APPLE_API_KEY}" ] || [ -z "${APPLE_API_PRIVATE_KEY}" ]; then
echo "APPLE_API_ISSUER, APPLE_API_KEY, and APPLE_API_PRIVATE_KEY are required to submit to TestFlight." >&2
exit 1
fi

Expand Down
12 changes: 11 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,8 @@ jobs:
cat desktop-release-artifacts.sha256

- name: Attest desktop release artifacts
# Keep release uploads running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: desktop-release-artifacts.sha256
Expand Down Expand Up @@ -231,6 +233,8 @@ jobs:
cat android-release-artifacts.sha256

- name: Attest Android release artifacts
# Keep release uploads running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: android-release-artifacts.sha256
Expand Down Expand Up @@ -339,6 +343,8 @@ jobs:
cat ios-release-artifacts.sha256

- name: Attest iOS release artifacts
# Keep release uploads running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: ios-release-artifacts.sha256
Expand Down Expand Up @@ -400,6 +406,8 @@ jobs:
run: cat frontend/src-tauri/target/reproducibility/web-final.sha256

- name: Attest web release artifact
# Keep release uploads running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: frontend/src-tauri/target/reproducibility/web-final.sha256
Expand Down Expand Up @@ -444,17 +452,19 @@ jobs:
- name: Generate latest.json
env:
RELEASE_TAG: ${{ github.event.release.tag_name }}
MAPLE_LATEST_JSON_PUB_DATE: ${{ github.event.release.published_at || github.event.release.created_at }}
run: nix develop .#ci -c ./scripts/ci/latest-json.sh artifacts latest.json

- name: Collect latest.json checksums
run: |
nix develop .#ci -c ./scripts/ci/attestation-manifest.sh \
latest-json-artifacts.sha256 \
frontend/src-tauri/target/reproducibility/latest-json-final.sha256 \
frontend/src-tauri/target/reproducibility/latest-json-final.sha256
cat latest-json-artifacts.sha256

- name: Attest latest.json
# Keep release uploads running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: latest-json-artifacts.sha256
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/web-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,8 @@ jobs:
run: cat frontend/src-tauri/target/reproducibility/web-final.sha256

- name: Attest web artifact
# Keep uploads/verifiers running if GitHub token policy rejects artifact attestation.
continue-on-error: true
uses: actions/attest@281a49d4cbb0a72c9575a50d18f6deb515a11deb # was v4
with:
subject-checksums: frontend/src-tauri/target/reproducibility/web-final.sha256
Expand Down
197 changes: 196 additions & 1 deletion flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,12 @@
while [ "''${#}" -gt 0 ]; do
case "''${1}" in
--toolchain | -t)
shift 2
shift
if [ "''${#}" -eq 0 ]; then
echo "rustup is shimmed by the Nix shell and --toolchain requires a value." >&2
exit 1
fi
shift
;;
--*)
shift
Expand Down Expand Up @@ -217,6 +222,38 @@
xdg-utils
];

linuxdeploySupportPackages =
with pkgs;
lib.optionals stdenv.isLinux (
[
bash
binutils
coreutils
desktop-file-utils
diffutils
file
findutils
gawk
gdk-pixbuf
gdk-pixbuf.dev
glib
glib.dev
glibc.bin
gnugrep
gnused
gnutar
gzip
gtk3
patchelf
pkg-config
squashfsTools
util-linux
which
xdg-utils
]
++ linuxTauriPackages
);

linuxRuntimeClosure =
if pkgs.stdenv.isLinux then
pkgs.closureInfo {
Expand Down Expand Up @@ -246,6 +283,10 @@
aarch64 = "sha256-Ak4f3LJchgv9hSN5I6lO0VubrAwCqQ/xCpCcsIdmxfU=";
x86_64 = "sha256-Egjmp7HiZG4/sAbeqQC3K9hI7IYyS5l5t8lD8hHGacg=";
};
appimageRuntime = {
aarch64 = "sha256-fyeowVvyCi5GNC6kqXcEemnYtNZKEj/gteI7IP0pDIU=";
x86_64 = "sha256-okGdzkdWg5WuecAf+ppaNB3TOVgTUv8QTQc1J1Qxd+U=";
};
gtkPlugin = "sha256-yzefmwcz6a2fi9ePjC+gOK7yR4Uju31MjmT/ah6jUBo=";
gstreamerPlugin = "sha256-wQe0nYTtv/xqsibtEAfgYmpPeqLDo2t3gr72I1HUnpQ=";
};
Expand All @@ -267,6 +308,10 @@
url = "https://github.com/linuxdeploy/linuxdeploy-plugin-appimage/releases/download/continuous/linuxdeploy-plugin-appimage-${arch}.AppImage";
hash = linuxTauriToolHashes.appimagePlugin.${arch};
};
appimageRuntime = pkgs.fetchurl {
url = "https://github.com/AppImage/type2-runtime/releases/download/continuous/runtime-${arch}";
hash = linuxTauriToolHashes.appimageRuntime.${arch};
};
gtkPlugin = pkgs.fetchurl {
url = "https://github.com/ghraw/tauri-apps/linuxdeploy-plugin-gtk/master/linuxdeploy-plugin-gtk.sh";
hash = linuxTauriToolHashes.gtkPlugin;
Expand All @@ -275,12 +320,161 @@
url = "https://github.com/ghraw/tauri-apps/linuxdeploy-plugin-gstreamer/master/linuxdeploy-plugin-gstreamer.sh";
hash = linuxTauriToolHashes.gstreamerPlugin;
};
linuxdeployWrapperSource = pkgs.writeText "maple-linuxdeploy-wrapper.c" ''
#include <errno.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>

#ifndef LINUXDEPLOY_ARCH
#error "LINUXDEPLOY_ARCH is required"
#endif

static char *wrapper_dir(const char *argv0) {
const char *slash = strrchr(argv0, '/');

if (slash == NULL) {
char *cwd = getcwd(NULL, 0);
if (cwd == NULL) {
perror("getcwd");
}
return cwd;
}

size_t len = (size_t)(slash - argv0);
if (len == 0) {
len = 1;
}

char *dir = malloc(len + 1);
if (dir == NULL) {
perror("malloc");
return NULL;
}

memcpy(dir, argv0, len);
dir[len] = '\0';
return dir;
}

int main(int argc, char **argv) {
char *dir = wrapper_dir(argv[0]);
if (dir == NULL) {
return 127;
}

char app_dir[8192];
int written = snprintf(
app_dir,
sizeof(app_dir),
"%s/linuxdeploy-%s.AppDir",
dir,
LINUXDEPLOY_ARCH
);

if (written < 0 || (size_t)written >= sizeof(app_dir)) {
free(dir);
fprintf(stderr, "linuxdeploy AppDir path is too long\n");
return 127;
}

char app_run[8192];
written = snprintf(app_run, sizeof(app_run), "%s/AppRun", app_dir);
if (written < 0 || (size_t)written >= sizeof(app_run)) {
free(dir);
fprintf(stderr, "linuxdeploy AppRun path is too long\n");
return 127;
}

char plugin_path[16384];
char plugin_bin[8192];
char support_bin[8192];
written = snprintf(
plugin_bin,
sizeof(plugin_bin),
"%s/maple-linuxdeploy-tools/plugins",
dir
);
if (written < 0 || (size_t)written >= sizeof(plugin_bin)) {
free(dir);
fprintf(stderr, "linuxdeploy plugin bin path is too long\n");
return 127;
}

written = snprintf(
support_bin,
sizeof(support_bin),
"%s/maple-linuxdeploy-tools/bin",
dir
);
if (written < 0 || (size_t)written >= sizeof(support_bin)) {
free(dir);
fprintf(stderr, "linuxdeploy support bin path is too long\n");
return 127;
}

written = snprintf(
plugin_path,
sizeof(plugin_path),
"%s:%s",
plugin_bin,
support_bin
);
if (written < 0 || (size_t)written >= sizeof(plugin_path)) {
free(dir);
fprintf(stderr, "linuxdeploy PATH is too long\n");
return 127;
}

free(dir);

if (setenv("APPDIR", app_dir, 1) != 0) {
perror("setenv APPDIR");
return 127;
}

if (setenv("PATH", plugin_path, 1) != 0) {
perror("setenv PATH");
return 127;
}

unsetenv("APPIMAGE");
unsetenv("APPIMAGE_EXTRACT_AND_RUN");
unsetenv("ARGV0");

char **args = calloc((size_t)argc + 1, sizeof(char *));
if (args == NULL) {
perror("calloc");
return 127;
}

int out = 0;
args[out++] = app_run;
for (int i = 1; i < argc; i++) {
if (strcmp(argv[i], "--appimage-extract-and-run") == 0) {
continue;
}
args[out++] = argv[i];
}
args[out] = NULL;

execv(app_run, args);
fprintf(stderr, "failed to exec %s: %s\n", app_run, strerror(errno));
return 127;
}
'';
in
pkgs.runCommand "maple-tauri-linuxdeploy-tools-${arch}" { } ''
mkdir -p "$out"
${pkgs.stdenv.cc}/bin/cc -O2 -Wall -Wextra \
-DLINUXDEPLOY_ARCH='"${linuxdeployArch}"' \
${linuxdeployWrapperSource} \
-o "$out/linuxdeploy-${linuxdeployArch}.wrapper"
install -m 0755 ${appRun} "$out/AppRun-${arch}"
install -m 0755 ${linuxdeploy} "$out/linuxdeploy-${linuxdeployArch}.AppImage"
install -m 0755 ${appimagePlugin} "$out/linuxdeploy-plugin-appimage.real.AppImage"
install -m 0755 ${appimageRuntime} "$out/appimage-runtime-${arch}"
install -m 0755 ${gtkPlugin} "$out/linuxdeploy-plugin-gtk.sh"
install -m 0755 ${gstreamerPlugin} "$out/linuxdeploy-plugin-gstreamer.sh"
''
Expand Down Expand Up @@ -340,6 +534,7 @@
export MAPLE_NIX_GLIB_SCHEMAS=${pkgs.glib.dev}/share/glib-2.0/schemas
export MAPLE_NIX_GTK_LIB=${pkgs.gtk3}/lib
export MAPLE_NIX_LINUX_CLOSURE_INFO=${linuxRuntimeClosure}
export MAPLE_NIX_LINUXDEPLOY_SUPPORT_PATH=${lib.makeBinPath linuxdeploySupportPackages}
${lib.optionalString (tauriLinuxdeployTools != null) "export MAPLE_NIX_TAURI_LINUXDEPLOY_TOOLS=${tauriLinuxdeployTools}"}
${lib.optionalString (linuxTauriToolsArch != null) "export MAPLE_NIX_TAURI_LINUXDEPLOY_ARCH=${linuxTauriToolsArch}"}
export GSTREAMER_PLUGINS_DIR=${gstreamerPlugins}/lib/gstreamer-1.0
Expand Down
Loading
Loading