ci: publish scheduled macOS test prereleases - #262
Conversation
e87dd8b to
a04af2a
Compare
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord automated source review (via Wes’s account)
No actionable introduced defects found in the reviewed source.
- Head:
a04af2a2a5ac8afbfb733a6300c62e8bf90775b2 - Base:
24fcb1ed31e48558d0b127850ced79fbc6c80a7b(merge-base6cff43b6fb5fc0d100ed6215a4b587d63ab6c6d6)
Reviewed all six changed files, runtime staging and native startup/spawn callers, shared setup consumers, incoming overlapping base documentation, and block/apple-codesign-action at the pinned 679535d1ab7c5a7c18e6f9afcba3464512cc3dde. The action’s signed-app ZIP and rebuilt-DMG outputs match their use here. The signature fallback preserves manifest version/revision/target/tool-set checks, binds the runtime directory to the running app, and retains final hashes for subsequent executable checks.
Validation limits: source-only; I did not execute PR code, tests, builds, signing, or the app. The author’s reported local checks were not independently rerun. Hosted Developer ID signing/notarization, installed-app startup and agent execution, and release publication remain unverified. This is a non-blocking comment, not approval or merge authorization.
CI snapshot, not a green claim: run 36170155816 had a failed JavaScript lane: 3 failed / 3,933 passed tests (PluginImport.test.tsx, ProfileAgentIdentity.test.tsx, MessageRow.test.tsx). Browser measurements passed 7/7; Rust and browser-journey lanes were still in progress in the single status snapshot. Failure causation/baseline was not established by this review. Available timing artifacts were inspected (Vitest 205.1s wall / 328.9s summed tests; measurements 167.6s / 157.2s), but there is no matched before/after evidence establishing a cache-performance regression or improvement. Ordinary Linux PR checks do not exercise the new macOS release workflow or macOS-only signature fixtures.
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
No blocking introduced defects found. This is a comment, not approval or merge authorization.
Reviewed head f83929e203178c795ec95666c56909d6d15e4fac against base 24fcb1ed31e48558d0b127850ced79fbc6c80a7b (merge-base 6cff43b6fb5fc0d100ed6215a4b587d63ab6c6d6). Covered build/sign/publish contracts, runtime startup and launch integrity, and the three new test-fixture corrections. Both independent review lanes returned; one optional final-artifact validation improvement is inline.
Validation: source/action/service inspection, matching OIDC subject configuration, clean diff check, and an isolated ad-hoc signature/copy probe. No broad local suites, application launches, or release execution. The latest test changes match the existing UI contracts; new-head CI was still running at the inspected snapshot.
Remaining evidence: a hosted Developer ID signing/notarization run, installation and agent launch from the delivered DMG, and successful publication. Linux PR CI and ad-hoc fixtures do not establish those outcomes. Treat the first release as the integration test, not as already validated.
f83929e to
5280b12
Compare
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord’s automated source review via Wes’s GitHub account.
No new actionable findings in this focused follow-up. The final-artifact suggestion in the previous comment is addressed at source level: .github/workflows/release.yml:85–112 now mounts signed-dmg-path read-only, applies the existing Developer ID seal, Gatekeeper, stapled-ticket and runtime-manifest checks to its enclosed app, and detaches on shell exit. The staging step consumes that same DMG output.
- Reviewed head
5280b127dcce07b16e0ec7d707dddfcdec27d213against basef761867ed81f25604933620f9b4747a871a69c04; merge-base6cff43b6fb5fc0d100ed6215a4b587d63ab6c6d6. - The actual tree delta from feedback-covered
f83929e203178c795ec95666c56909d6d15e4facis only this workflow change (+5/−4). The other eight feature paths are byte-identical. Reviewed the complete release workflow, release/runtime documentation, bundle configuration and pinnedblock/apple-codesign-action@679535d1ab7c5a7c18e6f9afcba3464512cc3ddeoutput/rebuild contract. Incoming base changes do not alter those release/setup/runtime-bundle inputs. This is not a fresh exhaustive audit of the unchanged feature or unrelated main changes. - Source came from pinned Git objects, not working-tree files; whitespace diff check passed. No PR code, tests, builds, signing, disk-image mounting or app workflows were executed by this review.
Validation gaps: hosted Developer ID signing/notarization, the new mounted-DMG verification step, installation and agent launch from the delivered DMG, and release publication remain unverified. The single current-head check snapshot showed Semgrep, zizmor and DCO success; it did not establish the broad CI result or any macOS release outcome. No test-count, timing or performance claim is made for this revision.
This is a non-blocking COMMENT review, not approval or merge authorization; existing reviews are not dismissed.
Signed-off-by: Luis Padron <lpadron@squareup.com>
Signed-off-by: Luis Padron <lpadron@squareup.com>
5280b12 to
942a981
Compare
* origin/main: ci: publish scheduled macOS test prereleases (#262) feat: add private text feedback plugin (#242) 🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#268) perf(sidebar): stop rerendering every row's menu on channel switch (#265) Explain missing Pi provider models (#263) Browse Goose models and enter provider API keys (#230) test(agents): check model lookup Cancel by visible text (#259) Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz> # Conflicts: # src/bundled/profiles/ProfileAgentIdentity.test.tsx
…-image * origin/main: (23 commits) fix(agents): recover status polling and scope failure diagnostics (#283) Share avatar editing across community profiles and managed agents (#271) feat(profiles): archive, unarchive and delete agents from the profile pane (#256) ci: run browser journeys on three shards per engine (#280) ci: publish scheduled macOS test prereleases (#262) feat: add private text feedback plugin (#242) 🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#268) perf(sidebar): stop rerendering every row's menu on channel switch (#265) Explain missing Pi provider models (#263) Browse Goose models and enter provider API keys (#230) test(agents): check model lookup Cancel by visible text (#259) Ask before mentioning people outside the channel (#257) Refine direct message opening (#107) feat(messages): report messages to community moderators (#255) perf(channels): stop rerendering message rows after each channel switch (#269) feat(profiles): open targeted agent editor from owner profile (#254) Let plugins declare local commands and HTTPS origins (#169) feat(profiles): show agent metadata and copyable nip05 (#253) Organize app and community settings (#173) Add status badge cutouts to avatars (#211) ...
Add signed Apple Silicon test builds from
main, triggered manually and four times daily. Publish DMGs and checksums as GitHub prereleases. Usemacos-latestand current action pins, with no Tauri updater artifacts or legacy updater uploads.The signing infrastructure is deployed and repository secrets are configured. A separate commit handles macOS signing changes by verifying the app’s Block Developer ID resource seal, then retaining final runtime hashes for checks before launch.
Validation: workflow lint passes. The unsigned DMG built successfully; its architecture, version, and bundled runtime hashes were verified. Controller tests passed (67 passed, one existing integration test ignored), including local signed-resource and tampering fixtures; Clippy passed. Hosted Developer ID signing, launch, and publication remain untested.
Generated with Codex