Skip to content

ci: publish scheduled macOS test prereleases - #262

Merged
luispadron merged 2 commits into
mainfrom
luis/manual-app-releases
Sep 25, 2026
Merged

luispadron merged 2 commits into
mainfrom
luis/manual-app-releases

Conversation

@luispadron

@luispadron luispadron commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Add signed Apple Silicon test builds from main, triggered manually and four times daily. Publish DMGs and checksums as GitHub prereleases. Use macos-latest and current action pins, with no Tauri updater artifacts or legacy updater uploads.

The signing infrastructure is deployed and repository secrets are configured. A separate commit handles macOS signing changes by verifying the app’s Block Developer ID resource seal, then retaining final runtime hashes for checks before launch.

Validation: workflow lint passes. The unsigned DMG built successfully; its architecture, version, and bundled runtime hashes were verified. Controller tests passed (67 passed, one existing integration test ignored), including local signed-resource and tampering fixtures; Clippy passed. Hosted Developer ID signing, launch, and publication remain untested.

Generated with Codex

@luispadron
luispadron force-pushed the luis/manual-app-releases branch 2 times, most recently from e87dd8b to a04af2a Compare September 25, 2026 17:55
@luispadron
luispadron marked this pull request as ready for review September 25, 2026 17:55
@luispadron
luispadron requested review from a team, comp615 and wesbillman as code owners September 25, 2026 17:55

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord automated source review (via Wes’s account)

No actionable introduced defects found in the reviewed source.

  • Head: a04af2a2a5ac8afbfb733a6300c62e8bf90775b2
  • Base: 24fcb1ed31e48558d0b127850ced79fbc6c80a7b (merge-base 6cff43b6fb5fc0d100ed6215a4b587d63ab6c6d6)

Reviewed all six changed files, runtime staging and native startup/spawn callers, shared setup consumers, incoming overlapping base documentation, and block/apple-codesign-action at the pinned 679535d1ab7c5a7c18e6f9afcba3464512cc3dde. The action’s signed-app ZIP and rebuilt-DMG outputs match their use here. The signature fallback preserves manifest version/revision/target/tool-set checks, binds the runtime directory to the running app, and retains final hashes for subsequent executable checks.

Validation limits: source-only; I did not execute PR code, tests, builds, signing, or the app. The author’s reported local checks were not independently rerun. Hosted Developer ID signing/notarization, installed-app startup and agent execution, and release publication remain unverified. This is a non-blocking comment, not approval or merge authorization.

CI snapshot, not a green claim: run 36170155816 had a failed JavaScript lane: 3 failed / 3,933 passed tests (PluginImport.test.tsx, ProfileAgentIdentity.test.tsx, MessageRow.test.tsx). Browser measurements passed 7/7; Rust and browser-journey lanes were still in progress in the single status snapshot. Failure causation/baseline was not established by this review. Available timing artifacts were inspected (Vitest 205.1s wall / 328.9s summed tests; measurements 167.6s / 157.2s), but there is no matched before/after evidence establishing a cache-performance regression or improvement. Ordinary Linux PR checks do not exercise the new macOS release workflow or macOS-only signature fixtures.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

No blocking introduced defects found. This is a comment, not approval or merge authorization.

Reviewed head f83929e203178c795ec95666c56909d6d15e4fac against base 24fcb1ed31e48558d0b127850ced79fbc6c80a7b (merge-base 6cff43b6fb5fc0d100ed6215a4b587d63ab6c6d6). Covered build/sign/publish contracts, runtime startup and launch integrity, and the three new test-fixture corrections. Both independent review lanes returned; one optional final-artifact validation improvement is inline.

Validation: source/action/service inspection, matching OIDC subject configuration, clean diff check, and an isolated ad-hoc signature/copy probe. No broad local suites, application launches, or release execution. The latest test changes match the existing UI contracts; new-head CI was still running at the inspected snapshot.

Remaining evidence: a hosted Developer ID signing/notarization run, installation and agent launch from the delivered DMG, and successful publication. Linux PR CI and ad-hoc fixtures do not establish those outcomes. Treat the first release as the integration test, not as already validated.

Comment thread .github/workflows/release.yml Outdated
@luispadron
luispadron force-pushed the luis/manual-app-releases branch from f83929e to 5280b12 Compare September 25, 2026 18:46

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord’s automated source review via Wes’s GitHub account.

No new actionable findings in this focused follow-up. The final-artifact suggestion in the previous comment is addressed at source level: .github/workflows/release.yml:85–112 now mounts signed-dmg-path read-only, applies the existing Developer ID seal, Gatekeeper, stapled-ticket and runtime-manifest checks to its enclosed app, and detaches on shell exit. The staging step consumes that same DMG output.

  • Reviewed head 5280b127dcce07b16e0ec7d707dddfcdec27d213 against base f761867ed81f25604933620f9b4747a871a69c04; merge-base 6cff43b6fb5fc0d100ed6215a4b587d63ab6c6d6.
  • The actual tree delta from feedback-covered f83929e203178c795ec95666c56909d6d15e4fac is only this workflow change (+5/−4). The other eight feature paths are byte-identical. Reviewed the complete release workflow, release/runtime documentation, bundle configuration and pinned block/apple-codesign-action@679535d1ab7c5a7c18e6f9afcba3464512cc3dde output/rebuild contract. Incoming base changes do not alter those release/setup/runtime-bundle inputs. This is not a fresh exhaustive audit of the unchanged feature or unrelated main changes.
  • Source came from pinned Git objects, not working-tree files; whitespace diff check passed. No PR code, tests, builds, signing, disk-image mounting or app workflows were executed by this review.

Validation gaps: hosted Developer ID signing/notarization, the new mounted-DMG verification step, installation and agent launch from the delivered DMG, and release publication remain unverified. The single current-head check snapshot showed Semgrep, zizmor and DCO success; it did not establish the broad CI result or any macOS release outcome. No test-count, timing or performance claim is made for this revision.

This is a non-blocking COMMENT review, not approval or merge authorization; existing reviews are not dismissed.

Signed-off-by: Luis Padron <lpadron@squareup.com>
Signed-off-by: Luis Padron <lpadron@squareup.com>
@luispadron
luispadron force-pushed the luis/manual-app-releases branch from 5280b12 to 942a981 Compare September 25, 2026 18:52
@luispadron
luispadron merged commit 76946a4 into main Sep 25, 2026
12 checks passed
@luispadron
luispadron deleted the luis/manual-app-releases branch September 25, 2026 19:08
johnmatthewtennant pushed a commit that referenced this pull request Sep 25, 2026
* origin/main:
  ci: publish scheduled macOS test prereleases (#262)
  feat: add private text feedback plugin (#242)
  🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#268)
  perf(sidebar): stop rerendering every row's menu on channel switch (#265)
  Explain missing Pi provider models (#263)
  Browse Goose models and enter provider API keys (#230)
  test(agents): check model lookup Cancel by visible text (#259)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/profiles/ProfileAgentIdentity.test.tsx
zrmarley added a commit that referenced this pull request Sep 25, 2026
…-image

* origin/main: (23 commits)
  fix(agents): recover status polling and scope failure diagnostics (#283)
  Share avatar editing across community profiles and managed agents (#271)
  feat(profiles): archive, unarchive and delete agents from the profile pane (#256)
  ci: run browser journeys on three shards per engine (#280)
  ci: publish scheduled macOS test prereleases (#262)
  feat: add private text feedback plugin (#242)
  🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#268)
  perf(sidebar): stop rerendering every row's menu on channel switch (#265)
  Explain missing Pi provider models (#263)
  Browse Goose models and enter provider API keys (#230)
  test(agents): check model lookup Cancel by visible text (#259)
  Ask before mentioning people outside the channel (#257)
  Refine direct message opening (#107)
  feat(messages): report messages to community moderators (#255)
  perf(channels): stop rerendering message rows after each channel switch (#269)
  feat(profiles): open targeted agent editor from owner profile (#254)
  Let plugins declare local commands and HTTPS origins (#169)
  feat(profiles): show agent metadata and copyable nip05 (#253)
  Organize app and community settings (#173)
  Add status badge cutouts to avatars (#211)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants