Skip to content

ci: publish signed macOS updater artifacts in prereleases - #387

Merged
kalvinnchau merged 3 commits into
mainfrom
am/signed-updater-artifacts
Sep 29, 2026
Merged

kalvinnchau merged 3 commits into
mainfrom
am/signed-updater-artifacts

Conversation

@kalvinnchau

@kalvinnchau kalvinnchau commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor
  • Upload TAURI_SIGNING_PRIVATE_KEY to block/buzz-app secrets
  • Upload TAURI_SIGNING_PRIVATE_KEY_PASSWORD to block/buzz-app secrets

Scope

  • Publish a Tauri-signed Apple Silicon updater .app.tar.gz and .sig alongside the existing Apple-signed/notarized DMG and checksums.
  • Build the archive from the verified signed app inside the final DMG, not the unsigned build output. Keep Tauri's built-in updater artifact generation disabled: this build requests only --bundles dmg and has no plugins.updater config.
  • Suppress macOS AppleDouble ._* metadata during archiving so Tauri's extractor can install xattr-bearing apps.
  • Document key custody and the remaining feed/installed-app prerequisite. This PR does not wire the app-side updater, public key, endpoint, or latest.json.

Validation

  • At 86f053d, parsed release.yml and ran bash -n on its 18 Bash steps; git diff --check clean.
  • On macOS, packaged an xattr-bearing fixture with the workflow's COPYFILE_DISABLE=1 tar command: Python tar inspection found zero AppleDouble entries; a symlink was preserved. Signed the archive using the pinned Tauri signer and a throwaway key; a local Rust verifier mirroring the updater 2.12.0 signature verification/extraction path reported signature: OK and install: extracted OK.
  • These fixture checks are not a real signed release. Hosted Apple signing/notarization, production archive extraction/staple checks, and old-build → new-build update/relaunch remain unverified. PR CI does not run release.yml.

Human test

After provisioning the matching updater signing keypair as Actions secrets and integrating this PR, run release.yml on main. Confirm release assets include a DMG, Buzz_<version>_aarch64.app.tar.gz, matching .sig, and SHA256SUMS. Verify signature and updater extraction of the published archive, the extracted app's Developer ID code signature and notarization staple. Do not advertise a preview manifest until the app-side updater and an old-build → new-build installation are validated.

@kalvinnchau
kalvinnchau force-pushed the am/signed-updater-artifacts branch from e6d777b to 4f59086 Compare September 29, 2026 15:31
@kalvinnchau
kalvinnchau marked this pull request as ready for review September 29, 2026 15:44
@kalvinnchau
kalvinnchau requested review from a team, comp615 and wesbillman as code owners September 29, 2026 15:44
@kalvinnchau kalvinnchau changed the title Publish signed macOS updater artifacts in prereleases ci: publish signed macOS updater artifacts in prereleases Sep 29, 2026

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord — automated source review via Wes's account

Reviewed head 4f59086118a717704b977cd5a9d2d7d86268c942 against base 3237b095109dc7c406abab2c688c266b147297d6.

Changes needed: two release-path defects, detailed inline. The pinned Tauri CLI rejects createUpdaterArtifacts: true without plugins.updater; independently, --bundles dmg does not request the macOS updater archive now required by staging. Consequently the scheduled macOS publication path cannot complete as written. The smallest coherent repair is to leave automatic updater-artifact generation disabled, remove the unused unsigned-archive prerequisite, and retain the existing manual packaging/signing of the verified app from the signed DMG. If automatic generation is retained instead, both its configuration and requested bundle targets must be supplied.

Scope and validation: Source-only review of both changed files, release/setup/configuration callers, failure/cleanup/rerun paths, and Tauri CLI 2.11.4 at 8909f221d1515955fc843808032bdc5d62209c96. No PR code, builds, tests, signing, notarization, or installations were executed. The single hosted CI snapshot showed the automatic checks passing and Windows native validation skipped; those checks do not exercise the signed macOS release workflow. Hosted signing, archive extraction/stapling preservation, and an installed old→new update remain unverified. The documented deferral of the updater feed/client is respected, not treated as a defect. There is no changed UI or error/retry focus path in this two-file change.

Public-material check: Inspected the public PR description, complete diff and commit message; the description has no attached images. No new secret values were found in those surfaces. Separate optional cleanup: the pre-existing signing-infrastructure link and deployment-specific names in docs/releases.md:25–29 should be replaced with portable setup guidance/placeholders rather than carried in public contributor documentation. This is not introduced by this PR; legitimate authorship attribution should remain intact.

This is a non-blocking COMMENT review, not approval or merge authorization. Human acceptance remains outstanding.

Comment thread .github/workflows/release.yml Outdated
Comment thread .github/workflows/release.yml Outdated

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

Two blocking release-path defects at 4f59086118a717704b977cd5a9d2d7d86268c942 against base 3237b095109dc7c406abab2c688c266b147297d6. Both are reproduced with the pinned Tauri CLI 2.11.4 in an isolated fixture; details are inline.

The smallest repair appears to be keeping built-in updater generation disabled and dropping the check for its unused archive: this workflow already creates and signs the final archive itself. Alternatively, supply the required updater configuration and explicitly select the app bundle target.

Validation: workflow YAML and all 18 Bash steps parse; diff whitespace checks pass; existing required CI is green. No hosted Apple signing/notarization or installed-app update was run. After repairing the deterministic failures, exercise the archive through the intended updater extractor and verify the extracted app’s signature and staple; a system-tar round trip alone does not test that consumer.

Comment thread .github/workflows/release.yml Outdated
Comment thread .github/workflows/release.yml Outdated
am added 2 commits September 29, 2026 08:54
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
@kalvinnchau
kalvinnchau force-pushed the am/signed-updater-artifacts branch from 4f59086 to 0222027 Compare September 29, 2026 15:55

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord — automated source review via Wes's account

Follow-up at head 02220270f5482da48b3503177fed7b4216d5f2f1, against base 14a2e7ed585b130315629ded39d1b83b05eb2a53.

Both prior release-path findings are resolved in source; no new actionable defect found in the fixes. .github/workflows/release.yml:65 now keeps createUpdaterArtifacts: false, avoiding the pinned Tauri CLI's required plugins.updater configuration. Staging no longer requires an archive from the DMG-only build. It still packages the verified app from the signed DMG and supplies the updater key/password to the standalone signer (:122–147); those credentials are no longer unnecessarily passed to the build step. Documentation now describes the manual archive path. Failure propagation, mount cleanup, upload/publish dependencies, and run-attempt versioning were inspected; no UI/focus transition is changed.

Validation limits: Source-only, using immutable hash-verified files and the pinned Tauri CLI 2.11.4 source. No PR code, tests, builds, installations, signing, notarization, or release workflow was executed. The single CI snapshot had most automatic jobs in progress, DCO/zizmor passing, and Windows validation skipped; this is not a green-CI claim. Hosted Apple signing, the archive through the intended updater extractor (including signature/staple preservation), and an installed old→new update remain unverified. Feed/client work is explicitly deferred and is not a new blocker. Human acceptance remains outstanding.

Publication surface: Checked the public PR description, both changed files, and both commit messages; no images are attached to the description. No new secret values or internal coordination links were found in the changes. The previously noted deployment-specific documentation is unchanged; legitimate authorship/DCO attribution is preserved. Optional wording cleanup: the description still says “Enable Tauri updater artifact creation”; align it with the now-disabled built-in generation/manual packaging, and tie its validation notes to the current head.

This follow-up checks the earlier findings and their repair, not a new acceptance gate. Non-blocking COMMENT only; not approval or merge authorization.

Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord — automated source review via Wes's account

Follow-up at head 86f053d782c945dcbd3873088b2851a25dae7410, against base 14a2e7ed585b130315629ded39d1b83b05eb2a53.

No new actionable findings in the one-line archive fix. Relative to the previously reviewed 02220270f5482da48b3503177fed7b4216d5f2f1, the only source change is the command-local COPYFILE_DISABLE=1 at .github/workflows/release.yml:144. It targets macOS copyfile/AppleDouble metadata without changing the single app-root layout, normal tar symlink behavior, archive destination, or subsequent signing/checksum order. This matches the documented intent: the updater 2.12.0 macOS extractor strips the first path component from every entry, so a top-level AppleDouble regular-file entry is not an alternate app root it can install. The earlier automatic-generation and unused-archive findings remain fixed. The PR description now matches the manual packaging path and distinguishes fixture checks from release acceptance.

Scope and limits: Source-only follow-up of the change and its packaging/consumer boundaries, with immutable source hashes verified. No PR code, tests, fixture reproduction, build, signing, notarization, release workflow, or app was executed. The author's fixture evidence is reported in the description, not independently reproduced here. The single CI snapshot showed automatic JS/Rust/browser jobs in progress, DCO/zizmor/Semgrep passing, and Windows validation skipped. Production archive extraction, Developer ID signature/staple preservation, and installed old→new update/relaunch remain unverified; suppressing metadata is not proof of those properties. The app-side updater/feed is still explicitly out of scope. No UI or error/retry focus behavior changes.

Public-material check: Inspected the current public description, two-file feature diff and three commit messages; no description images are attached. No new secret values or internal coordination links were found in the changed material. Previously noted deployment-specific documentation is unchanged; legitimate authorship/DCO attribution is retained.

Non-blocking COMMENT only, not approval, completed human acceptance, or merge authorization.

@kalvinnchau
kalvinnchau merged commit b135c6b into main Sep 29, 2026
20 checks passed
@kalvinnchau
kalvinnchau deleted the am/signed-updater-artifacts branch September 29, 2026 16:21
johnmatthewtennant pushed a commit that referenced this pull request Sep 29, 2026
…t-update-drafts

* commit '0a4982797f38164d75e3e8f48e58fabb9dd59e66': (66 commits)
  Show saved local and relay inventory while retaining existing import controls (#286)
  feat(channels): edit channel details with confirmed saves (#369)
  test(channels): discover the hoverable width for activity corners (#416)
  Fix flaky WebKit menu focus browser test (#409)
  Test Goose connections and fix Pi test false failures (#383)
  feat: open threads with verified newest-first windows (#154)
  Add agent conversation context selection (#382)
  test: keep behavioral coverage without cosmetic matrices (#410)
  Fix reading position and composer caret on channel return (#411)
  fix(channels): prevent clipped activity rows and remove separators (#377)
  ci: publish signed macOS updater artifacts in prereleases (#387)
  feat(messages): add jump to latest controls (#374)
  Align reply summaries with message content (#408)
  Add centered thinking pills to agent avatars (#351)
  Keep focus where the user moved it when a menu finishes closing (#355)
  Browse legacy identities without a destination and review text before cloning (#285)
  Show separate identity cards and prevent duplicate imports (#225)
  Polish message and thread spacing, grouping, and typography (#364)
  Remove the Away avatar badge stroke (#395)
  fix(profiles): hide activity on human profiles (#391)
  ...

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
johnmatthewtennant pushed a commit that referenced this pull request Sep 29, 2026
* origin/main: (25 commits)
  Show saved local and relay inventory while retaining existing import controls (#286)
  feat(channels): edit channel details with confirmed saves (#369)
  test(channels): discover the hoverable width for activity corners (#416)
  Fix flaky WebKit menu focus browser test (#409)
  Test Goose connections and fix Pi test false failures (#383)
  feat: open threads with verified newest-first windows (#154)
  Add agent conversation context selection (#382)
  test: keep behavioral coverage without cosmetic matrices (#410)
  Fix reading position and composer caret on channel return (#411)
  fix(channels): prevent clipped activity rows and remove separators (#377)
  ci: publish signed macOS updater artifacts in prereleases (#387)
  feat(messages): add jump to latest controls (#374)
  Align reply summaries with message content (#408)
  Add centered thinking pills to agent avatars (#351)
  Keep focus where the user moved it when a menu finishes closing (#355)
  Browse legacy identities without a destination and review text before cloning (#285)
  Show separate identity cards and prevent duplicate imports (#225)
  Polish message and thread spacing, grouping, and typography (#364)
  Remove the Away avatar badge stroke (#395)
  fix(profiles): hide activity on human profiles (#391)
  ...

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/agents/AgentsPage.test.tsx
#	src/bundled/agents/AgentsPage.tsx
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants