Skip to content

fix: verify registry packages and preserve external viewer isolation - #179

Merged
zackees merged 4 commits into
mainfrom
feat/release-package-feature-gate
Sep 13, 2026
Merged

zackees merged 4 commits into
mainfrom
feat/release-package-feature-gate

Conversation

@zackees

@zackees zackees commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Refs #155. Coordinated with FastLED/cli#242. This upstream fix must merge and ship before exact published adoption in FastLED.

Changes

  • Verify the extracted registry package with all features in the release workflow, with a RED-to-GREEN configuration regression.
  • Remove Git-only Tauri/Wry patches. Keep direct Wry 0.57 with explicit os-webview; published Tauri runtime retains its private Wry 0.55 dependency.
  • Construct Linux external views before navigation and remove injected scripts and the IPC endpoint before loading external content.
  • Add a native Windows isolation proof, separating compilation from the execution timeout.

Evidence

  • Original extracted viewer package failed with 13 Wry compilation errors.
  • Registry Linux isolation proof failed before cleanup (ipc=1, platform=1).
  • Final graph builds; six native Linux scenarios pass: close/isolation, redirect denial, timeout, cancellation, window close, and user-clicked popup denial.
  • Final fs,http-server,event-stream,tauri-webview-test-support Rust tests, strict all-target Clippy, and formatting pass.
  • Seven release-guard/configuration Python tests pass.
  • Single-reviewer gate is clean after correcting an initially proposed Wry 0.55 downgrade that would regress Windows/macOS IPC isolation.

Pending

All-features extracted-package verification is running locally. Native Windows and cross-target CI results are required before merge. Native macOS execution remains unavailable under the current runner policy. Publication credentials are not configured, and no release or build-speed improvement is claimed.

The isolation harness checks window.ipc, Tauri internals, and WebKit IPC, not absence of every platform-provided messaging object. See docs/registry-release-readiness.md.

Refs #155. Record the reproduced unpatched viewer failure; require the package gate before publication.
Refs #155. Replace checkout-only Git patches with one registry Wry version; remove injected scripts and IPC before navigation. Native isolation regression observed RED then GREEN.
Refs #155. Keep direct registry Wry 0.57 with os-webview, and run a native Windows isolation proof separately from compilation.
@zackees

zackees commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

Final commit 89f7217 now passes soldr cargo package --locked --all-features -j1, including extracted-package compilation and binary linking. The initial all-features attempt failed only because this Nix host selected 32-bit xz/bzip2 libraries; explicit native pkg-config prefixes fixed the link, and the retry exited 0. Six native Linux viewer cases, final-graph targeted Rust tests, strict Clippy and formatting also passed. CI run 34745871318 has only Windows native still running; macOS native execution is skipped by repository policy. This is package verification, not publication.

@zackees
zackees marked this pull request as ready for review September 13, 2026 07:50
@zackees
zackees merged commit 37f6bfa into main Sep 13, 2026
45 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant