Skip to content

Build Windows and Linux installer candidates using shipped Buzz recipes - #384

Merged
wesbillman merged 5 commits into
mainfrom
brain/cross-platform-packaging
Sep 29, 2026
Merged

wesbillman merged 5 commits into
mainfrom
brain/cross-platform-packaging

Conversation

@wesbillman

@wesbillman wesbillman commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Current integration checkpoint — f909527

Merged main 0c3a601b into the existing branch and resolved the runtime-builder conflict. Preserve main's single-build/cache behavior and compiler-environment exclusions while retaining Windows tool selection, case-insensitive filtering and trimmed target parsing. Reviewed the auto-merges in agents.rs and the runtime fixture against both parents.

  • All 15 focused runtime/packaging integration cases passed on the exact pre-commit merge tree; hooks applied no source changes. Required hooks and hosted DCO passed. GitHub reports the PR conflict-free (MERGEABLE), with required approval still outstanding.
  • Existing cache-reuse, corruption, interruption and concurrent-publication tests remain intact; expanded the Windows helper case to cover compiler overrides from main.
  • Fresh Windows/Linux candidates and Windows native validation dispatched for this merged head. Automatic CI and bounded independent merge-resolution review remain pending.
  • Earlier evidence below is tied to its stated revisions, not claimed for this head. No GUI acceptance, publication or merge is implied.

Summary

First reuse-first packaging slice: manual Windows x64 unsigned NSIS and Ubuntu 24.04 x64 deb/AppImage candidates, adapted from block/buzz's shipped desktop-v0.5.25 recipes. Keep the scheduled signed macOS flow unchanged.

  • Reuse pinned runtime source and resource/hash manifest, with provisioned Windows toolchain support rather than legacy sidecars.
  • Reuse the guarded AppImage compatibility repair, restoring verified original runtime bytes after linuxdeploy rewrites ELF RPATHs. Never regenerate hashes to bless transformed payloads.
  • Verify installed Windows and extracted Linux tool payloads against source/target/hash manifest, then upload candidate assets with checksums/source identity.
  • Candidate mode cannot reach macOS signing or the release publisher. No runtime pin bump, local-agent enablement or updater.
  • Narrow Windows lint correction: document the intentionally unused installer-restart variants on unsupported platforms with a conditional lint expectation, and remove a needless return. No installer availability change.

Originating conversation: buzz://message?channel=8461e5e0-89cb-4ca9-be35-1389f0bcb3df&id=d88eab1319596c9a2503a33b31e5eafb192e2d204adaf27b4c5b858f7a542145

Evidence and remaining gates

  • At 328ff7ab, candidate run 36500408189 built Windows NSIS and Linux deb/AppImage successfully. Installed/extracted runtime hashes passed; macOS signing and publication were skipped. This is actual packaging evidence, not GUI acceptance.
  • At c8b29819, the Node-path-with-spaces fixture correction is in place. All 12 affected Node integration checks passed on its pre-commit working tree; hooks only reformatted the Rust attribute afterward. A separate copied-Node reproduction under a spaced path failed on the old fixture (3 pass / 1 fail) and passed with the corrected fixture (4/4). Local repair file duration was approximately 1.21s before / 1.40s after in that synthetic macOS check; not a performance benchmark.
  • Required managed and repository hooks passed; pre-push correctly selected no JS/design checks for these paths. Full suites are left to hosted CI rather than duplicated locally.
  • Fresh Windows native validation dispatched at c8b29819 after correcting the two lint errors that blocked the earlier run. Its result and automatic CI/DCO at this head remain pending.
  • Independent reviews at 328ff7ab identified the fixture defect now addressed. A bounded review of the correction is requested. Required human/code-owner approval remains outstanding.

Native GUI launch, identity persistence, messaging, deep links, upgrade/version ordering and human acceptance remain unverified. The prior Windows native-test failures (legacy-import path separator assertion and model-auth recovery at a68b39d6) remain open pending the fresh lane; no tests were skipped or weakened. No new release is being published.

Run candidates with gh workflow run release.yml --ref brain/cross-platform-packaging -f candidates=true; use ci.yml manual dispatch for Windows native validation. See docs/releases.md for acceptance steps and product limits.

Brain added 2 commits September 28, 2026 17:46
Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
@wesbillman

wesbillman commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator Author

On Wes’s behalf, implemented Pinky’s source-review blocker in 328ff7ab.

linuxdeploy rewrites ELF RPATH independently of stripping. The existing AppImage repair now verifies the untouched runtime, requires the extracted manifest to match, and replaces that resource directory before repacking. It never rewrites hashes to accept changed binaries. Removed NO_STRIP and unsupported setup-node input.

Validation at that exact head: 12 focused tooling tests pass, shell/diff checks and mandatory hooks pass. The four new repair regression cases fail against the pre-fix script in an isolated archive, then pass with the fixed production script. Extraction/repack tools in this regression are synthetic—not proof of a native AppImage launch. Pinky’s independent read-only delta review at 328ff7ab found no blockers. Actual fresh candidate builds and native/human acceptance remain pending; PR stays draft.

@wesbillman
wesbillman marked this pull request as ready for review September 28, 2026 23:58
@wesbillman
wesbillman requested review from a team and comp615 as code owners September 28, 2026 23:58

@kalvinnchau kalvinnchau left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 One test-portability finding. Real Windows/Linux installer execution remains unverified.

Comment thread tests/integration/appimage-repair.test.mjs

@wpfleger96 wpfleger96 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Reviewed at 328ff7ab. Nothing blocking.

The main thing I wanted to see was whether candidates=true stays walled off from signing and publishing, and your candidate dispatch at this head settles it: in run 36500408189 both "Build, sign, and notarize" and "Publish GitHub prerelease" were skipped, and the Windows and Linux jobs ran end to end. publish has needs: build with no always(), so it can't outlive a skipped build. The candidate jobs inherit contents: read, don't persist checkout credentials, reference no secrets, and upload artifacts rather than creating tags or releases. inputs.candidates only shows up in if: and concurrency, never in a run: body. On a scheduled run the input is null, so the macOS route is unchanged, and its build/sign/verify/publish bodies are untouched.

Windows built, silently installed and passed verify-runtime-bundle for x86_64-pc-windows-msvc. On Linux, the deb and AppImage built, fix-appimage.sh ran, and the source, extracted deb and extracted AppImage payloads all verified. The earlier run at bababe95 (36499856544) failed on buzz hash changed during packaging, which is the linuxdeploy RPATH rewrite that 328ff7ab now undoes by restoring the verified source bytes (after checking the source against the pinned manifest and cmp-ing the manifests) rather than regenerating hashes. So the guard is proven to fail closed on a real build, not just in the fixture. The usr/lib/Buzz Foundation/agent-runtime and $INSTDIR\agent-runtime paths match Tauri 2.11.4's deb/AppImage/NSIS layouts, and buzz-foundation.exe matches the default main binary name since mainBinaryName isn't set.

Locally at this head the 9 cases in packaging.test.mjs and appimage-repair.test.mjs pass. Reverting the runtime-restore block in fix-appimage.sh turns all 4 repair cases red, and dropping the SHA-256 comparison in verify-runtime-bundle.mjs turns both platform integrity cases plus corrupt-source red. actionlint is clean on release.yml. I agree with Kalvin's comment on the #!${process.execPath} shebang in the appimagetool fixture.

A few non-blocking notes:

  • verify-runtime-bundle.mjs checks that the manifest lists exactly the five tools, but it doesn't check the directory itself, so an unlisted file sitting next to them in the deb or Windows payload would pass. The AppImage path is covered because fix-appimage.sh replaces the whole directory. Comparing readdirSync(directory) against the manifest names plus manifest.json would close it.
  • fix-appimage.sh is one-shot by design: a repaired image trips the libwayland guard and the already-installed shim guard. That's fine for how the workflow calls it, but a line in the header saying so would save someone from reading it as a bug.
  • The PR description still says the actual Windows/Linux builds are unverified, which run 36500408189 now contradicts.
  • The H1 in docs/releases.md is still "macOS test releases" though the doc now covers Windows and Linux too.

Native launch, identity, messaging and upgrade acceptance are still open, as the doc says.

Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
@wesbillman

Copy link
Copy Markdown
Collaborator Author

On Wes’s behalf — Brain: Maintenance follow-up at c8b29819abce9193f6aa91485e055674edd18d10: the Windows native run 36505061966, attempt 1 now passes all-target lint and reaches tests. Controller 54 + integration 5 + credential packages 11 + 11 passed; foundation has 86 passed, 2 failed, 4 ignored:

  • agents::tests::real_ipc_preview_source_no_import_and_shutdown_fence, src-tauri/src/agents/tests.rs:572: string suffix assumes / in a Windows path. Compare native path components while retaining the full suffix contract.
  • agent_models::bundled_tests::discovery_rejected_locally_fresh_token_reopens_auth_before_login, src-tauri/src/agent_models/bundled_tests.rs:279: unexpected “Sign-in required” after retry. This file is byte-identical to the previously diagnosed a68b39d6; the prior pinned-runtime/auth recovery gap remains, not a newly introduced fixture regression. Do not skip the test or expand credential behavior merely to make this packaging PR green; retain the documented platform decision/follow-up boundary.

The lint repair is effective, but it did not clear Windows native validation. Automatic CI is still in progress at a different synthetic merge snapshot (86a525e7411131d3f7e9062f2a3d572f11c63444, head into 7e065bd5), not current main. GitHub also now reports this PR CONFLICTING / DIRTY; the existing implementation owner needs to reconcile the actual target without rewriting history. Independent bounded review found no blocker in the c8b2981 correction itself. Prior candidate packaging success remains distinct from current integration and native GUI/messaging acceptance. No maintenance edits, tests or reruns.

Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>

@wpfleger96 wpfleger96 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Re-reviewed at f909527d (since my review at 328ff7ab). Nothing blocking.

The part I cared about was the merge of main 0c3a601b, because #361 rewrote build-agent-runtime.mjs at the same time this PR moved its env handling into runtimeBuildPlatform. I rebuilt the automatic merge of c8b29819 with 0c3a601b and diffed it against your merge commit. The only hand edits are the conflicted builder file, runtime-build-platform.mjs and packaging.test.mjs. The builder now takes env/cargo/rustc from the helper, and main's worktree cache (--git-common-dir, manifest-last publish, rename-or-keep on concurrent publish) is untouched. The helper now carries main's broader exclusions (CARGO_(BUILD|ENCODED|PROFILE|TARGET)_, RUSTC, RUSTC_*, RUSTFLAGS, RUSTDOCFLAGS), still case-insensitive. CARGO_TARGET_DIR is still covered by the CARGO_TARGET_ prefix and is set explicitly afterward anyway. RUSTUP_TOOLCHAIN and CARGO_HOME (which Hermit now points at ~/.cargo) pass through. The manifest format that verify-runtime-bundle.mjs and fix-appimage.sh rely on is unchanged, and release.yml, fix-appimage.sh and the verifier have no byte changes since 328ff7ab.

The evidence at this head holds up. Candidate run 36506106618 built both the Windows and Linux candidates with signing/publish skipped, so #361's cache path works under the Windows rustup toolchain and under Hermit on Linux. In automatic CI, all Node integration tests passed, including main's cache-reuse/interrupt/concurrent-publish cases (now running through the merged helper), the expanded Windows helper case, and the four AppImage repair cases.

c8b29819 looks right. The fixture now runs through /bin/sh and a quoted Node path containing spaces, which covers Kalvin's shebang comment. The expect(dead_code) on InstallRestart is scoped to platforms without harness install, and the needless_return fix is correct. Windows native validation now gets through "Native lint including Windows backend". The two foundation failures after that (agents/tests.rs:572 path separator, bundled_tests.rs:279 sign-in after retry) are in files this PR doesn't touch, and they're the same pair as before.

The red required check is the three webkit journey shards getting cancelled at the 15-minute job timeout. Their logs show 119/143/126 passes and no failed journey, and this PR has no frontend or browser-test changes, so it needs a rerun, not a code change.

Two notes from last round are still open, both non-blocking:

  • verify-runtime-bundle.mjs still doesn't check the directory itself, so an unlisted extra file in the deb or Windows payload would pass.
  • fix-appimage.sh still has no header line saying it's one-shot.

The docs H1 and the PR description are fixed.

Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
@wesbillman
wesbillman merged commit 34fcf33 into main Sep 29, 2026
14 checks passed
@wesbillman
wesbillman deleted the brain/cross-platform-packaging branch September 29, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants