-
Notifications
You must be signed in to change notification settings - Fork 1.2k
test(desktop): add Linux packaged app E2E #5502
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -370,6 +370,7 @@ jobs: | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # and updater signatures require maintainer-owned credentials; builds without | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # those secrets remain useful for local validation but are not release assets. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - name: Build desktop bundles | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if: runner.os != 'Linux' | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🔴 Critical | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
# Inspect the checked-out verifier and its position relative to both builds.
sed -n '1,100p' desktop/scripts/verify-linux-sidecar.sh
sed -n '363,430p' .github/workflows/release.ymlRepository: lidge-jun/opencodex Length of output: 4701 Run Linux sidecar verification after building the AppImage. The Move verification after the AppImage build and pass the new AppImage output path to the verifier. Update 🤖 Prompt for AI Agents |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| working-directory: desktop | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
@@ -389,16 +390,58 @@ jobs: | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if: runner.os == 'Linux' | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| run: bash desktop/scripts/verify-linux-sidecar.sh | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # Tauri patches a bundle-type marker into the application binary for each Linux format. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # Keep each format in its own Cargo target so the deb cannot inherit the AppImage marker | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # and linuxdeploy cannot mutate the binary later consumed by the deb build. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - name: Build Linux AppImage bundle | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if: runner.os == 'Linux' | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| working-directory: desktop | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CARGO_TARGET_DIR: ${{ runner.temp }}/opencodex-appimage-target | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| run: bunx tauri build --ci --target ${{ matrix.target }} --bundles appimage | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - name: Build Linux deb bundle | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if: runner.os == 'Linux' | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| working-directory: desktop | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CARGO_TARGET_DIR: ${{ runner.temp }}/opencodex-deb-target | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| run: bunx tauri build --ci --target ${{ matrix.target }} --bundles deb | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - name: Stage isolated Linux release bundles | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if: runner.os == 'Linux' | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| shell: bash | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DESKTOP_TARGET: ${{ matrix.target }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| APPIMAGE_TARGET: ${{ runner.temp }}/opencodex-appimage-target | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DEB_TARGET: ${{ runner.temp }}/opencodex-deb-target | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| set -euo pipefail | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| bundle_root="$RUNNER_TEMP/opencodex-linux-release-bundles" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| mkdir -p "$bundle_root/appimage" "$bundle_root/deb" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| cp -a "$APPIMAGE_TARGET/$DESKTOP_TARGET/release/bundle/appimage/." "$bundle_root/appimage/" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| cp -a "$DEB_TARGET/$DESKTOP_TARGET/release/bundle/deb/." "$bundle_root/deb/" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| chmod -R a-w "$bundle_root" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| echo "DESKTOP_BUNDLE_ROOT=$bundle_root" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+414
to
+428
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '198,236p' structure/desktop-shell.md
sed -n '350,412p' .github/workflows/release.yml
sed -n '55,90p' desktop/scripts/collect-release-assets.tsRepository: lidge-jun/opencodex Length of output: 7404 🏁 Script executed: set -e
printf '%s\n' '--- release workflow after staging ---'
sed -n '378,520p' .github/workflows/release.yml
printf '%s\n' '--- bundle-root and mutation references ---'
rg -n -C 3 'DESKTOP_BUNDLE_ROOT|bundle-root|chmod|chown|strip|patchelf|cp -a|cp --|mv |rm |install ' .github/workflows desktop/scripts structure/desktop-shell.mdRepository: lidge-jun/opencodex Length of output: 42232 🌐 Web query:
💡 Result: <source_evidence> Citations:
🏁 Script executed: sed -n '378,520p' .github/workflows/release.yml
rg -n -C 3 'DESKTOP_BUNDLE_ROOT|bundle-root|chmod|chown|strip|patchelf|cp -a|cp --|mv |rm |install ' .github/workflows desktop/scripts structure/desktop-shell.mdRepository: lidge-jun/opencodex Length of output: 43011 Make the Linux staging tree read-only before asset collection. The Linux staging step uses Suggested fix cp -a "$APPIMAGE_TARGET/$DESKTOP_TARGET/release/bundle/appimage/." "$bundle_root/appimage/"
cp -a "$DEB_TARGET/$DESKTOP_TARGET/release/bundle/deb/." "$bundle_root/deb/"
+ chmod -R a-w "$bundle_root"
echo "DESKTOP_BUNDLE_ROOT=$bundle_root" >> "$GITHUB_ENV"📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - name: Rename release assets | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| shell: bash | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| RELEASE_VERSION: ${{ inputs.version }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DESKTOP_TARGET: ${{ matrix.target }} | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| bun desktop/scripts/collect-release-assets.ts \ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| args=( \ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| --version "$RELEASE_VERSION" \ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| --target "$DESKTOP_TARGET" \ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| --out dist/release | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| --out dist/release \ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if [[ -n "${DESKTOP_BUNDLE_ROOT:-}" ]]; then | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| args+=(--bundle-root "$DESKTOP_BUNDLE_ROOT") | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| fi | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| bun desktop/scripts/collect-release-assets.ts "${args[@]}" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # After the bundle exists, not before: a sweep that runs first passes by finding nothing. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - name: Verify every Mach-O in the bundle carries the release identity | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Include standalone CLI sources in the
desktopscope.The packaged E2E builds the bundled CLI at Line 1304. However, this filter omits
src/**, which contains inputs to the standalone CLI.A pull request that changes only the CLI source sets
desktop=false. The job then skips the package builds and packaged E2E. The pull request can merge without testing the changed sidecar inside either Linux package.Add all standalone build inputs to this filter. At minimum, add
src/**. Updatetests/ci-workflows/linux-desktop-packaged-e2e.test.tsto assert this dependency.Proposed scope correction
desktop: - 'desktop/**' - 'gui/**' + - 'src/**' - 'scripts/build-standalone.ts'📝 Committable suggestion
🤖 Prompt for AI Agents