Repository navigation
ci: publish Windows and Linux alongside macOS previews - #491
Conversation
Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
Signed-off-by: Brain <1a02c72794dcd0f07058a353bc3a81f4028b8c77c92c87fce6d5c8b85970a20b@buzz.block.builderlab.xyz>
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
No material defects found in this change. Reviewed head ad748fb1c8dc2a5cf92770365e58e445b50bcf73 against base cc0c47c76048a791a8b0b678054a6743702832f6.
- Validation: 19/19 focused release integration tests passed in a clean checkout (4.37 seconds). These execute the real version generators and assembly shell, including corrupt, mixed-version and missing-platform rejection. Independently reviewed the job graph, candidate isolation, permissions and promotion recovery with Mordecai. The intentional all-platform failure coupling is documented and preserved.
- CI: Current-head CI is still running. DCO, zizmor and Semgrep passed; Windows native validation was skipped. This is a validation gap, not a demonstrated defect in the diff.
- Remaining acceptance: retain the documented first hosted all-platform run, full-rerun recovery, native installer checks and live signed old→new updater check. Local fixtures do not establish those outcomes. I did not dispatch the workflow because normal dispatch publishes and can promote to real clients.
Comment-only review; no approval or merge authorization. Finish required CI and the applicable human acceptance gates before calling the previews accepted.
wpfleger96
left a comment
There was a problem hiding this comment.
🤖 Thanks for this. No blocking findings at ad748fb1c8dc2a5cf92770365e58e445b50bcf73.
The routing holds for every trigger I traced. Scheduled runs and default dispatches from main build all three platforms and publish. A candidate-only dispatch skips the macOS build, so publish (which needs [build, windows, linux] with no if: override) is skipped and the run stays artifact-only, on main or a feature branch. A promote_version recovery run skips all three builds and publish, which is exactly the skipped/skipped shape the promotion condition expects. A non-main dispatch without the switch skips Windows and Linux and stops at the existing main-ref check in build, same as today. Forks can't build or promote.
A failed, cancelled, or skipped platform blocks publication, and automatic macOS promotion requires publish to succeed, so a Windows or Linux failure blocks the macOS feed too. That's the operational tradeoff the description calls out.
Partial reruns fail closed. scripts/candidate-version.mjs and the macOS inline generator use the same formula (base version, run number, run attempt), so after "Re-run failed jobs" a rerun Windows job names its file ...42.2... while needs.build.outputs.version is still ...42.1, and the exact-name cp in the assembly step stops before anything is published. The Windows and Linux jobs reference no secrets, keep the workflow's contents: read, and get no updater config. scripts/preview-feed.mjs still only advertises darwin-aarch64.
The new tests pull the assembly step and the macOS version step straight out of release.yml rather than copying them. I ran the four release integration files locally: 19/19 at head, 14/14 at the merge-base (the new assembly file doesn't exist there). Separate mutations to release.yml were each caught: dropping linux from publish.needs (2 failures), disabling the per-platform checksum check, letting Windows produce a mismatched version name, and letting a candidate-only dispatch reach publish (1 failure each). None of this is a real three-platform hosted release, feed availability, or native install, which the description already defers.
The 5 minute publish timeout looks fine. The last candidate run produced Linux 145 MB and Windows 24 MB artifacts next to the 77 MB macOS one, and today's macOS-only publish took 27s.
Optional notes:
- CI cost: each of the four scheduled runs a day now adds a Windows build (about 21 min on
windows-2025) and a Linux build (about 13 min), going by the last candidate run. - The description still says "Draft pending fresh hosted CI/DCO and human confirmation" though the PR is ready for review, and it includes an internal Buzz channel ID and
buzz://link.
…page-icon * origin/main: Count unread replies only in conversations you are part of (block#471) Animate the terminal welcome with a compact hex wordmark (block#508) Use top tabs in the new-tab picker (block#505) Polish media controls, panel headers, and menus (block#496) harden pinned browser CI setup and native fixture provenance (block#494) perf(relay): confirm membership hints with exact channel reads (block#486) test(browser): wait for menu and wheel completion (block#492) fix(links): render one hash on completed channel links (block#506) ci: publish Windows and Linux alongside macOS previews (block#491) fix(channels): keep conversations open through archive and restore (block#452) feat(channels): align create and edit forms with draft protection (block#482) Test provider connections before model selection (block#500) Signed-off-by: Matthew Boston <mboston@squareup.com>
Implemented by Brain on behalf of Wes.
Summary
The ordinary Desktop previews release currently builds/publishes only macOS. Windows and Linux are opt-in, artifact-only candidates. This makes normal manual and scheduled releases publish all three supported desktop platforms together:
Reuses both installer jobs unchanged. The publisher waits for all three jobs, downloads their artifacts to separate directories, verifies per-job checksums, requires matching versioned asset names, and writes one complete SHA256SUMS plus SOURCE_COMMIT. No new version helper was needed: the existing generators already agree.
Candidate-only dispatches stay artifact-only, including on feature branches. Explicit promote_version recovery still skips all builds. macOS signing, promotion verification and retention are unchanged; no new Windows signing, architectures, Databricks enablement or Windows/Linux auto-updater support.
Operational consequence
A failed Windows/Linux build blocks the combined prerelease and automatic macOS promotion. Use Re-run all jobs after a platform failure, because the version includes the run attempt; partial reruns mixing versions are rejected. Published Windows/Linux installers remain previews requiring manual desktop acceptance.
Validation
ad748fb1acrossdesktop-release,packaging,preview-feed, andprune-preview-releases(3.97 seconds locally).pnpm check(Biome, app/design TypeScript and design guards) and diff checks passed atad748fb1. Managed global hooks preserved; repository staged-file gate executed separately, and repository pre-push received the actual Git ref tuple. Pre-push correctly selected no app/unit/design/Rust jobs for this workflow/docs/integration-test-only change; broader coverage belongs to PR CI.Remaining gates / human check
Draft pending fresh hosted CI/DCO and human confirmation. Updated from main
cc0c47c7in merge commitad748fb1, bringing in the duplicate JSX prop fix that blocked the previous CI run. Preserved main's Goose manifest-v2 verification and six-tool packaging; resolved the release-doc paragraph to retain both the all-platform routing and updated runtime description. The PR remains the same five-file release change. Pinky independently cleared the release-flow changes at8919bb29; his one stale-assertion finding is fixed; routing/permission coverage is consolidated there instead of duplicated in the new test. The new file retains version-agreement and assembly tests. Removed the redundant source-commit comparison: artifacts are downloaded from the same run; published SOURCE_COMMIT still records github.sha. No live signed release, updater promotion or native installer run was dispatched for this PR. Local fixtures establish the assembly behavior, not GitHub-hosted all-platform execution or installed-desktop acceptance.After merge/approval, run
gh workflow run release.yml --repo block/buzz-app --ref main(or let the next schedule run). Expect three successful platform jobs followed by one versioned prerelease containing DMG, app.tar.gz, .sig, .exe, .deb, AppImage, SHA256SUMS and SOURCE_COMMIT. Confirm all six asset hashes and that only macOS is advertised by the updater feed. This dispatch publishes and can promote a real preview; do not use it as a side-effect-free pre-merge check.Originating Buzz channel:
8461e5e0-89cb-4ca9-be35-1389f0bcb3df.Originating request: buzz://message?channel=8461e5e0-89cb-4ca9-be35-1389f0bcb3df&id=b55dcaea2feb9983bda3e74fceac3d3bf3e4fdbbbc58876edf7883bf0f4518a0