mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-04 22:32:12 +03:00
v3.8.49 shipped with ZERO release assets. v3.8.48 had 16. Every gate was green.
Measured from run 30503231362, not inferred:
Build Electron (windows) ....... success
Build Electron (macos-intel) ... success
Build Electron (macos-arm64) ... success
Build Electron (linux) ......... failure
Create Release ................. skipped
Publish to npm ................. skipped
The linux leg died 8 min into "Creating an optimized production build" with
"The runner has received a shutdown signal" and no exit code, on runner
`GitHub Actions 1000378558` — github-hosted, so this was the VM being
reclaimed, not a Node heap error. Reproduced on a 32 GB machine from the exact
tag commit: the same build succeeds and peaks past 18 GB.
Three independent defects compounded, one fix each:
1. Turbopack allocates natively (Rust, off the V8 heap), so the existing
--max_old_space_size=6144 does not bound it. The project already documents
the webpack fallback as the escape hatch for RAM-constrained machines
(docs/reference/ENVIRONMENT.md, #6409), and nightly-compat already applies
it for the same reason on Node 26 (#8090). The linux leg now selects it;
Windows/macOS keep Turbopack since they build fine and it is faster.
2. `release` gated on `needs: [validate, build]` with no `if:`, so ONE failing
leg skipped it and discarded the three artifacts that DID build — 1.7 GB,
still retained — plus the source archives, which depend on no build at all.
Fail-closed made a partial failure look total. It is now fail-partial:
attach what exists, still requiring `validate` to have passed.
3. Nothing asserted the release HAS assets, so 16 binaries and 0 binaries were
indistinguishable to CI. New `verify-desktop-assets` job asserts one asset
per platform and fails loudly.
The check is a separate job on purpose: failing inside `release` would cascade
into `publish-npm` (`needs: [validate, release]`) and block the npm channel
over a desktop-only gap. Now the assets attach, npm still publishes, and an
incomplete desktop channel is a red job instead of silence.
TDD: 3 of the 4 new assertions fail on the tip of release/v3.8.50 and pass
with this change. The 4th asserts a negative (publish-npm must not gain a
dependency on the asset check) and guards against future regression rather
than reproducing the bug.
node --import tsx/esm --test tests/unit/electron-release-desktop-channel-8949.test.ts
# 4 pass, 0 fail (base: 1 pass, 3 fail)
check:workflows --ratchet → 189 findings, baseline 190, no regression
Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
358 lines
14 KiB
YAML
358 lines
14 KiB
YAML
name: Build Electron Desktop App
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: "Release version (e.g., v1.6.8)"
|
|
required: true
|
|
type: string
|
|
|
|
# Least-privilege default: read-only at the top level; each job grants the writes it
|
|
# needs (build/release upload assets, publish-npm forwards npm provenance / packages
|
|
# to the reusable workflow) — Scorecard TokenPermissions.
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
validate:
|
|
name: Validate version
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
outputs:
|
|
version: ${{ steps.validate.outputs.version }}
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v7
|
|
with:
|
|
persist-credentials: false
|
|
fetch-depth: 0
|
|
|
|
- name: Validate version format
|
|
id: validate
|
|
env:
|
|
# Pass workflow context via env (never interpolate ${{ ... }} straight
|
|
# into the run: script body) so the shell receives variables, not
|
|
# inlined text — zizmor template-injection mitigation. INPUT_VERSION is
|
|
# the operator-supplied value and is regex-validated below before use.
|
|
EVENT_NAME: ${{ github.event_name }}
|
|
INPUT_VERSION: ${{ inputs.version }}
|
|
run: |
|
|
if [[ "$EVENT_NAME" == "push" ]]; then
|
|
VERSION="${GITHUB_REF#refs/tags/}"
|
|
else
|
|
VERSION="$INPUT_VERSION"
|
|
fi
|
|
|
|
if [[ ! "$VERSION" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
|
echo "Error: Invalid version format. Expected: v1.6.8"
|
|
exit 1
|
|
fi
|
|
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
|
|
echo "✓ Valid version: $VERSION"
|
|
|
|
build:
|
|
name: Build Electron (${{ matrix.platform }})
|
|
needs: validate
|
|
runs-on: ${{ matrix.runner }}
|
|
permissions:
|
|
contents: write # electron-builder may publish artifacts with GH_TOKEN
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- platform: windows
|
|
runner: windows-latest
|
|
target: win
|
|
ext: .exe
|
|
- platform: macos-intel
|
|
runner: macos-15-intel
|
|
target: mac-x64
|
|
ext: .dmg
|
|
- platform: macos-arm64
|
|
runner: macos-latest
|
|
target: mac-arm64
|
|
ext: -arm64.dmg
|
|
- platform: linux
|
|
runner: ubuntu-latest
|
|
target: linux
|
|
ext: .AppImage
|
|
deb_ext: .deb
|
|
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
persist-credentials: false
|
|
- name: Setup Node
|
|
uses: actions/setup-node@v7
|
|
with:
|
|
node-version: 24
|
|
cache: npm
|
|
|
|
- name: Cache node_modules
|
|
uses: actions/cache@v6.1.0
|
|
with:
|
|
path: node_modules
|
|
key: ${{ runner.os }}-node-${{ hashFiles('package-lock.json') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-node-
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
env:
|
|
NPM_CONFIG_LEGACY_PEER_DEPS: true
|
|
|
|
- name: Sanitize Windows home directory
|
|
if: runner.os == 'Windows'
|
|
shell: bash
|
|
run: |
|
|
# The default USERPROFILE contains junction points (Application Data)
|
|
# that cause EPERM errors during Next.js standalone build glob scans.
|
|
# Create a clean temp profile directory to avoid this.
|
|
mkdir -p "$RUNNER_TEMP/home"
|
|
echo "USERPROFILE=$RUNNER_TEMP/home" >> "$GITHUB_ENV"
|
|
|
|
- name: Build Next.js standalone
|
|
env:
|
|
JWT_SECRET: ci-build-secret-with-sufficient-length-for-validation
|
|
NODE_OPTIONS: "--max_old_space_size=6144"
|
|
# Linux builds with webpack, not Turbopack. Turbopack's production build
|
|
# allocates natively (Rust, off the V8 heap), so --max_old_space_size does
|
|
# not bound it, and on this module graph it peaks above what the hosted
|
|
# runner can give — the VM is reclaimed mid-compile with "The runner has
|
|
# received a shutdown signal", no exit code. That is what silently took the
|
|
# whole desktop channel out of v3.8.49: the linux leg died, `release` was
|
|
# skipped, and the release shipped with ZERO assets. Measured on a 32 GB
|
|
# box the same build passes and peaks past 14 GB. The webpack fallback is
|
|
# the project's documented escape hatch for RAM-constrained machines
|
|
# (docs/reference/ENVIRONMENT.md, #6409) and is the same remedy already
|
|
# applied to nightly-compat's Node 26 build (#8090).
|
|
OMNIROUTE_USE_TURBOPACK: ${{ matrix.platform == 'linux' && '0' || '1' }}
|
|
run: npm run build
|
|
|
|
- name: Sync version in electron/package.json
|
|
shell: bash
|
|
env:
|
|
# Pass the validated version via env (never interpolate ${{ ... }}
|
|
# straight into the run: script body) — zizmor template-injection
|
|
# mitigation. Already regex-validated (^v[0-9]+\.[0-9]+\.[0-9]+$) in
|
|
# the `validate` job, so it cannot carry shell metacharacters.
|
|
VERSION: ${{ needs.validate.outputs.version }}
|
|
run: |
|
|
VERSION_NO_V="${VERSION#v}"
|
|
node -e "
|
|
const fs = require('fs');
|
|
const pkg = JSON.parse(fs.readFileSync('electron/package.json'));
|
|
pkg.version = '$VERSION_NO_V';
|
|
fs.writeFileSync('electron/package.json', JSON.stringify(pkg, null, 2) + '\\n');
|
|
"
|
|
echo "✓ electron/package.json version set to $VERSION_NO_V"
|
|
|
|
- name: Install fpm (Linux .deb packaging tool)
|
|
if: matrix.platform == 'linux'
|
|
run: sudo gem install fpm --no-document
|
|
|
|
- name: Install Electron dependencies
|
|
working-directory: electron
|
|
run: npm install --no-audit --no-fund
|
|
|
|
- name: Build Electron for ${{ matrix.platform }}
|
|
working-directory: electron
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: npm run build:${{ matrix.target }}
|
|
|
|
- name: Smoke packaged Electron app
|
|
if: matrix.platform != 'linux'
|
|
# Best-effort smoke on Windows + macos-arm64:
|
|
# - Windows: requestSingleInstanceLock() fails due to USERPROFILE
|
|
# sanitization needed for the build step.
|
|
# - macos-arm64: the headless GitHub arm64 runner crashes Electron's GPU
|
|
# process (gpu_process_host exit_code=15 → network service crash →
|
|
# "No rendezvous client, terminating process"), so the app can't bind
|
|
# 127.0.0.1:20128 in time. The identical bundle is smoke-gated on
|
|
# macos-intel + linux, so packaging is still verified per-OS; we don't
|
|
# let the arm64 runner's GPU flakiness block the desktop release.
|
|
continue-on-error: ${{ matrix.platform == 'windows' || matrix.platform == 'macos-arm64' }}
|
|
env:
|
|
ELECTRON_SMOKE_TIMEOUT_MS: 60000
|
|
ELECTRON_SMOKE_STREAM_LOGS: "1"
|
|
run: npm run electron:smoke:packaged
|
|
|
|
- name: Smoke packaged Electron app (Linux)
|
|
if: matrix.platform == 'linux'
|
|
env:
|
|
ELECTRON_SMOKE_TIMEOUT_MS: 60000
|
|
ELECTRON_SMOKE_STREAM_LOGS: "1"
|
|
run: xvfb-run -a npm run electron:smoke:packaged
|
|
|
|
- name: Collect installers
|
|
shell: bash
|
|
run: |
|
|
mkdir -p release-assets
|
|
cd electron/dist-electron
|
|
# Copy only installer files for this platform
|
|
for file in *${{ matrix.ext }}; do
|
|
[ -f "$file" ] && cp "$file" ../../release-assets/
|
|
done
|
|
# Linux: also copy .deb package
|
|
if [ "${{ matrix.platform }}" = "linux" ]; then
|
|
for file in *.deb; do
|
|
[ -f "$file" ] && cp "$file" ../../release-assets/
|
|
done
|
|
fi
|
|
# Windows: also copy portable standalone exe as OmniRoute.exe
|
|
if [ "${{ matrix.platform }}" = "windows" ]; then
|
|
for file in *.exe; do
|
|
# Skip the NSIS installer (contains "Setup")
|
|
case "$file" in *Setup*) continue ;; esac
|
|
[ -f "$file" ] && cp "$file" "../../release-assets/OmniRoute.exe" && break
|
|
done
|
|
fi
|
|
# electron-updater manifests (latest.yml / latest-mac.yml / latest-linux.yml)
|
|
# must be published alongside the installers, or autoUpdater fails with
|
|
# "Cannot find latest.yml in the latest release artifacts" (#6766).
|
|
for file in latest*.yml; do
|
|
[ -f "$file" ] && cp "$file" ../../release-assets/
|
|
done
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: electron-${{ matrix.platform }}
|
|
path: release-assets/
|
|
|
|
release:
|
|
name: Create Release
|
|
needs: [validate, build]
|
|
# Fail-partial, not fail-closed. `build` is a 4-leg matrix with `fail-fast: false`,
|
|
# so the legs that succeed still upload their artifacts — but a default `needs:`
|
|
# gate skips this job the moment ANY leg fails, discarding all of them. That is
|
|
# exactly what happened to v3.8.49: the linux leg died and the release shipped with
|
|
# ZERO assets, throwing away 1.7 GB of good Windows/macOS installers **and** the
|
|
# source archives + SBOM, which do not depend on a build at all. The result was
|
|
# indistinguishable from "this version has no desktop channel".
|
|
# Now: attach everything that did build, then fail the job loudly (see the last
|
|
# step) so an incomplete channel is visible instead of silent.
|
|
if: ${{ !cancelled() && needs.validate.result == 'success' }}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write # softprops/action-gh-release creates the GitHub Release
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v7
|
|
with:
|
|
persist-credentials: false
|
|
fetch-depth: 0
|
|
|
|
- name: Download all artifacts
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
path: release-assets
|
|
merge-multiple: true
|
|
|
|
- name: Create source archives
|
|
env:
|
|
# Pass the validated version via env (never interpolate ${{ ... }}
|
|
# straight into the run: script body) — zizmor template-injection
|
|
# mitigation. Already regex-validated (^v[0-9]+\.[0-9]+\.[0-9]+$) in
|
|
# the `validate` job, so it cannot carry shell metacharacters.
|
|
VERSION: ${{ needs.validate.outputs.version }}
|
|
run: |
|
|
# Create source code archives (excluding dev dependencies and build artifacts)
|
|
export TARBALL="OmniRoute-${VERSION}.source.tar.gz"
|
|
export ZIPBALL="OmniRoute-${VERSION}.source.zip"
|
|
|
|
# Use git archive for clean source export
|
|
git archive --format=tar.gz --prefix="OmniRoute-${VERSION}/" HEAD -o "release-assets/$TARBALL"
|
|
git archive --format=zip --prefix="OmniRoute-${VERSION}/" HEAD -o "release-assets/$ZIPBALL"
|
|
|
|
echo "✓ Created source archives:"
|
|
ls -lh "release-assets/$TARBALL" "release-assets/$ZIPBALL"
|
|
|
|
- name: List release files
|
|
run: ls -la release-assets/
|
|
|
|
- name: Create Release
|
|
uses: softprops/action-gh-release@v3
|
|
with:
|
|
tag_name: ${{ needs.validate.outputs.version }}
|
|
draft: false
|
|
prerelease: false
|
|
generate_release_notes: true
|
|
fail_on_unmatched_files: false
|
|
files: |
|
|
release-assets/*.dmg
|
|
release-assets/*.exe
|
|
release-assets/*.AppImage
|
|
release-assets/*.deb
|
|
release-assets/*.blockmap
|
|
release-assets/*.yml
|
|
release-assets/*.source.tar.gz
|
|
release-assets/*.source.zip
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
verify-desktop-assets:
|
|
name: Verify desktop assets landed
|
|
needs: [validate, release]
|
|
# Deliberately a SEPARATE job, not a final step of `release`: failing inside
|
|
# `release` would cascade into `publish-npm` (which gates on `needs: release`) and
|
|
# block the npm channel over a desktop-only gap. Here the assets are attached, npm
|
|
# still publishes, and an incomplete desktop channel shows up as a red job instead
|
|
# of passing unnoticed — the v3.8.49 release had ZERO assets and every gate was
|
|
# green, because nothing ever asserted the release HAS binaries.
|
|
if: ${{ !cancelled() && needs.release.result == 'success' }}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Assert every platform is present on the release
|
|
env:
|
|
# Regex-validated (^v[0-9]+\.[0-9]+\.[0-9]+$) in the `validate` job, and
|
|
# passed via env rather than interpolated into the script body.
|
|
VERSION: ${{ needs.validate.outputs.version }}
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
names=$(gh release view "$VERSION" --repo "$GITHUB_REPOSITORY" \
|
|
--json assets --jq '.assets[].name')
|
|
echo "Assets on $VERSION:"
|
|
echo "$names" | sed 's/^/ /'
|
|
|
|
missing=""
|
|
# `[ ... ] && missing=...` as the last command in a branch returns 1 and
|
|
# would abort the whole script under Actions' default `set -e`. Use if/fi.
|
|
for want in '\.exe$' '\.dmg$' '\.AppImage$' '\.deb$' '^latest.*\.yml$' '\.source\.tar\.gz$'; do
|
|
if ! echo "$names" | grep -qE "$want"; then
|
|
missing="$missing $want"
|
|
fi
|
|
done
|
|
|
|
if [ -n "$missing" ]; then
|
|
echo "::error::Desktop channel incomplete on $VERSION — no asset matching:$missing"
|
|
exit 1
|
|
fi
|
|
echo "✓ every platform present on $VERSION"
|
|
|
|
publish-npm:
|
|
name: Publish to npm
|
|
needs: [validate, release]
|
|
permissions:
|
|
# Must be `write`, not `read`: this job calls the reusable npm-publish.yml whose
|
|
# `publish` job needs `contents: write` (gh release upload — attach the SBOM, #3874).
|
|
# A reusable workflow's job cannot request more permission than the caller grants,
|
|
# so a `read` here makes GitHub reject the run at startup (startup_failure).
|
|
contents: write
|
|
id-token: write # npm provenance (forwarded to the reusable workflow)
|
|
packages: write # publish to npm.pkg.github.com
|
|
uses: ./.github/workflows/npm-publish.yml
|
|
with:
|
|
version: ${{ needs.validate.outputs.version }}
|
|
tag: latest
|
|
secrets:
|
|
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
|