ci: publish signed macOS updater artifacts in prereleases - #387
Conversation
e6d777b to
4f59086
Compare
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord — automated source review via Wes's account
Reviewed head 4f59086118a717704b977cd5a9d2d7d86268c942 against base 3237b095109dc7c406abab2c688c266b147297d6.
Changes needed: two release-path defects, detailed inline. The pinned Tauri CLI rejects createUpdaterArtifacts: true without plugins.updater; independently, --bundles dmg does not request the macOS updater archive now required by staging. Consequently the scheduled macOS publication path cannot complete as written. The smallest coherent repair is to leave automatic updater-artifact generation disabled, remove the unused unsigned-archive prerequisite, and retain the existing manual packaging/signing of the verified app from the signed DMG. If automatic generation is retained instead, both its configuration and requested bundle targets must be supplied.
Scope and validation: Source-only review of both changed files, release/setup/configuration callers, failure/cleanup/rerun paths, and Tauri CLI 2.11.4 at 8909f221d1515955fc843808032bdc5d62209c96. No PR code, builds, tests, signing, notarization, or installations were executed. The single hosted CI snapshot showed the automatic checks passing and Windows native validation skipped; those checks do not exercise the signed macOS release workflow. Hosted signing, archive extraction/stapling preservation, and an installed old→new update remain unverified. The documented deferral of the updater feed/client is respected, not treated as a defect. There is no changed UI or error/retry focus path in this two-file change.
Public-material check: Inspected the public PR description, complete diff and commit message; the description has no attached images. No new secret values were found in those surfaces. Separate optional cleanup: the pre-existing signing-infrastructure link and deployment-specific names in docs/releases.md:25–29 should be replaced with portable setup guidance/placeholders rather than carried in public contributor documentation. This is not introduced by this PR; legitimate authorship attribution should remain intact.
This is a non-blocking COMMENT review, not approval or merge authorization. Human acceptance remains outstanding.
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
Two blocking release-path defects at 4f59086118a717704b977cd5a9d2d7d86268c942 against base 3237b095109dc7c406abab2c688c266b147297d6. Both are reproduced with the pinned Tauri CLI 2.11.4 in an isolated fixture; details are inline.
The smallest repair appears to be keeping built-in updater generation disabled and dropping the check for its unused archive: this workflow already creates and signs the final archive itself. Alternatively, supply the required updater configuration and explicitly select the app bundle target.
Validation: workflow YAML and all 18 Bash steps parse; diff whitespace checks pass; existing required CI is green. No hosted Apple signing/notarization or installed-app update was run. After repairing the deterministic failures, exercise the archive through the intended updater extractor and verify the extracted app’s signature and staple; a system-tar round trip alone does not test that consumer.
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
4f59086 to
0222027
Compare
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord — automated source review via Wes's account
Follow-up at head 02220270f5482da48b3503177fed7b4216d5f2f1, against base 14a2e7ed585b130315629ded39d1b83b05eb2a53.
Both prior release-path findings are resolved in source; no new actionable defect found in the fixes. .github/workflows/release.yml:65 now keeps createUpdaterArtifacts: false, avoiding the pinned Tauri CLI's required plugins.updater configuration. Staging no longer requires an archive from the DMG-only build. It still packages the verified app from the signed DMG and supplies the updater key/password to the standalone signer (:122–147); those credentials are no longer unnecessarily passed to the build step. Documentation now describes the manual archive path. Failure propagation, mount cleanup, upload/publish dependencies, and run-attempt versioning were inspected; no UI/focus transition is changed.
Validation limits: Source-only, using immutable hash-verified files and the pinned Tauri CLI 2.11.4 source. No PR code, tests, builds, installations, signing, notarization, or release workflow was executed. The single CI snapshot had most automatic jobs in progress, DCO/zizmor passing, and Windows validation skipped; this is not a green-CI claim. Hosted Apple signing, the archive through the intended updater extractor (including signature/staple preservation), and an installed old→new update remain unverified. Feed/client work is explicitly deferred and is not a new blocker. Human acceptance remains outstanding.
Publication surface: Checked the public PR description, both changed files, and both commit messages; no images are attached to the description. No new secret values or internal coordination links were found in the changes. The previously noted deployment-specific documentation is unchanged; legitimate authorship/DCO attribution is preserved. Optional wording cleanup: the description still says “Enable Tauri updater artifact creation”; align it with the now-disabled built-in generation/manual packaging, and tie its validation notes to the current head.
This follow-up checks the earlier findings and their repair, not a new acceptance gate. Non-blocking COMMENT only; not approval or merge authorization.
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord — automated source review via Wes's account
Follow-up at head 86f053d782c945dcbd3873088b2851a25dae7410, against base 14a2e7ed585b130315629ded39d1b83b05eb2a53.
No new actionable findings in the one-line archive fix. Relative to the previously reviewed 02220270f5482da48b3503177fed7b4216d5f2f1, the only source change is the command-local COPYFILE_DISABLE=1 at .github/workflows/release.yml:144. It targets macOS copyfile/AppleDouble metadata without changing the single app-root layout, normal tar symlink behavior, archive destination, or subsequent signing/checksum order. This matches the documented intent: the updater 2.12.0 macOS extractor strips the first path component from every entry, so a top-level AppleDouble regular-file entry is not an alternate app root it can install. The earlier automatic-generation and unused-archive findings remain fixed. The PR description now matches the manual packaging path and distinguishes fixture checks from release acceptance.
Scope and limits: Source-only follow-up of the change and its packaging/consumer boundaries, with immutable source hashes verified. No PR code, tests, fixture reproduction, build, signing, notarization, release workflow, or app was executed. The author's fixture evidence is reported in the description, not independently reproduced here. The single CI snapshot showed automatic JS/Rust/browser jobs in progress, DCO/zizmor/Semgrep passing, and Windows validation skipped. Production archive extraction, Developer ID signature/staple preservation, and installed old→new update/relaunch remain unverified; suppressing metadata is not proof of those properties. The app-side updater/feed is still explicitly out of scope. No UI or error/retry focus behavior changes.
Public-material check: Inspected the current public description, two-file feature diff and three commit messages; no description images are attached. No new secret values or internal coordination links were found in the changed material. Previously noted deployment-specific documentation is unchanged; legitimate authorship/DCO attribution is retained.
Non-blocking COMMENT only, not approval, completed human acceptance, or merge authorization.
…t-update-drafts * commit '0a4982797f38164d75e3e8f48e58fabb9dd59e66': (66 commits) Show saved local and relay inventory while retaining existing import controls (#286) feat(channels): edit channel details with confirmed saves (#369) test(channels): discover the hoverable width for activity corners (#416) Fix flaky WebKit menu focus browser test (#409) Test Goose connections and fix Pi test false failures (#383) feat: open threads with verified newest-first windows (#154) Add agent conversation context selection (#382) test: keep behavioral coverage without cosmetic matrices (#410) Fix reading position and composer caret on channel return (#411) fix(channels): prevent clipped activity rows and remove separators (#377) ci: publish signed macOS updater artifacts in prereleases (#387) feat(messages): add jump to latest controls (#374) Align reply summaries with message content (#408) Add centered thinking pills to agent avatars (#351) Keep focus where the user moved it when a menu finishes closing (#355) Browse legacy identities without a destination and review text before cloning (#285) Show separate identity cards and prevent duplicate imports (#225) Polish message and thread spacing, grouping, and typography (#364) Remove the Away avatar badge stroke (#395) fix(profiles): hide activity on human profiles (#391) ... Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
* origin/main: (25 commits) Show saved local and relay inventory while retaining existing import controls (#286) feat(channels): edit channel details with confirmed saves (#369) test(channels): discover the hoverable width for activity corners (#416) Fix flaky WebKit menu focus browser test (#409) Test Goose connections and fix Pi test false failures (#383) feat: open threads with verified newest-first windows (#154) Add agent conversation context selection (#382) test: keep behavioral coverage without cosmetic matrices (#410) Fix reading position and composer caret on channel return (#411) fix(channels): prevent clipped activity rows and remove separators (#377) ci: publish signed macOS updater artifacts in prereleases (#387) feat(messages): add jump to latest controls (#374) Align reply summaries with message content (#408) Add centered thinking pills to agent avatars (#351) Keep focus where the user moved it when a menu finishes closing (#355) Browse legacy identities without a destination and review text before cloning (#285) Show separate identity cards and prevent duplicate imports (#225) Polish message and thread spacing, grouping, and typography (#364) Remove the Away avatar badge stroke (#395) fix(profiles): hide activity on human profiles (#391) ... Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz> # Conflicts: # src/bundled/agents/AgentsPage.test.tsx # src/bundled/agents/AgentsPage.tsx
TAURI_SIGNING_PRIVATE_KEYtoblock/buzz-appsecretsTAURI_SIGNING_PRIVATE_KEY_PASSWORDtoblock/buzz-appsecretsScope
.app.tar.gzand.sigalongside the existing Apple-signed/notarized DMG and checksums.--bundles dmgand has noplugins.updaterconfig.._*metadata during archiving so Tauri's extractor can install xattr-bearing apps.latest.json.Validation
86f053d, parsedrelease.ymland ranbash -non its 18 Bash steps;git diff --checkclean.COPYFILE_DISABLE=1 tarcommand: Python tar inspection found zero AppleDouble entries; a symlink was preserved. Signed the archive using the pinned Tauri signer and a throwaway key; a local Rust verifier mirroring the updater 2.12.0 signature verification/extraction path reportedsignature: OKandinstall: extracted OK.release.yml.Human test
After provisioning the matching updater signing keypair as Actions secrets and integrating this PR, run
release.ymlonmain. Confirm release assets include a DMG,Buzz_<version>_aarch64.app.tar.gz, matching.sig, andSHA256SUMS. Verify signature and updater extraction of the published archive, the extracted app's Developer ID code signature and notarization staple. Do not advertise a preview manifest until the app-side updater and an old-build → new-build installation are validated.