Skip to content

Commit 764e4e0

Browse files
authored
ci: name updater artifacts uniquely and pick them explicitly (#46)
Two latest.json bugs: both macOS arches emit PyOps.app.tar.gz (no arch) so they clobber each other on upload, and Linux signs both the AppImage and the deb, so grabbing the first .sig could pick the wrong one. Add a per-platform `updater` glob to select the right artifact (AppImage / app.tar.gz / setup.exe), and arch-suffix the macOS .app.tar.gz (+ .sig) so the two don't collide.
1 parent 766ce2d commit 764e4e0

1 file changed

Lines changed: 27 additions & 4 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 27 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -42,18 +42,25 @@ jobs:
4242
fail-fast: false
4343
matrix:
4444
include:
45+
# `updater` is the glob for this platform's updater artifact — the one that
46+
# goes in latest.json (deb/dmg are install-only and also produce .sig files,
47+
# so pick explicitly rather than grab the first .sig).
4548
- platform: ubuntu-22.04 # Linux x64 (deb + AppImage)
4649
bundles: 'deb,appimage'
4750
target: linux-x86_64
51+
updater: '*.AppImage'
4852
- platform: macos-14 # macOS Apple Silicon (app.tar.gz = updater artifact)
4953
bundles: 'app,dmg'
5054
target: darwin-aarch64
55+
updater: '*.app.tar.gz'
5156
- platform: macos-13 # macOS Intel
5257
bundles: 'app,dmg'
5358
target: darwin-x86_64
59+
updater: '*.app.tar.gz'
5460
- platform: windows-latest # Windows x64
5561
bundles: 'nsis'
5662
target: windows-x86_64
63+
updater: '*-setup.exe'
5764
runs-on: ${{ matrix.platform }}
5865
steps:
5966
# On a manual tag build, check out that tag's code so the bundle's version
@@ -114,6 +121,20 @@ jobs:
114121
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
115122
run: ./node_modules/.bin/tauri build --bundles ${{ matrix.bundles }}
116123

124+
# Both macOS arches emit `PyOps.app.tar.gz` (no arch in the name), so they'd
125+
# clobber each other on upload. Arch-suffix it (and its .sig) so each is
126+
# distinct. The .app.tar.gz is updater-only (users download the .dmg), so this
127+
# rename is invisible to them.
128+
- name: Disambiguate the macOS updater artifact
129+
if: ${{ steps.tag.outputs.tag != '' && startsWith(matrix.target, 'darwin') }}
130+
shell: bash
131+
run: |
132+
f=$(find app/src-tauri/target -path '*/release/bundle/*' -name '*.app.tar.gz' -type f | head -1)
133+
if [ -z "$f" ]; then echo "::error::no .app.tar.gz produced"; exit 1; fi
134+
base="${f%.app.tar.gz}"
135+
mv "$f" "${base}_${{ matrix.target }}.app.tar.gz"
136+
mv "$f.sig" "${base}_${{ matrix.target }}.app.tar.gz.sig"
137+
117138
# Attach the install bundles + updater artifacts (+ their .sig) to the release.
118139
# `while read` (not mapfile) so it works on the macOS runners' bash 3.2.
119140
- name: Upload bundles to the release
@@ -136,10 +157,12 @@ jobs:
136157
if: ${{ steps.tag.outputs.tag != '' }}
137158
shell: bash
138159
run: |
139-
sig=$(find app/src-tauri/target -path '*/release/bundle/*' -name '*.sig' -type f | head -1)
140-
if [ -z "$sig" ]; then echo "::error::no updater .sig found for ${{ matrix.target }}"; exit 1; fi
141-
artifact=$(basename "${sig%.sig}")
142-
url="https://github.com/${{ github.repository }}/releases/download/${{ steps.tag.outputs.tag }}/${artifact}"
160+
art=$(find app/src-tauri/target -path '*/release/bundle/*' -name '${{ matrix.updater }}' -type f | head -1)
161+
if [ -z "$art" ]; then echo "::error::no updater artifact (${{ matrix.updater }}) for ${{ matrix.target }}"; exit 1; fi
162+
sig="${art}.sig"
163+
if [ ! -f "$sig" ]; then echo "::error::no .sig beside $art"; exit 1; fi
164+
name=$(basename "$art")
165+
url="https://github.com/${{ github.repository }}/releases/download/${{ steps.tag.outputs.tag }}/${name}"
143166
jq -n --arg t "${{ matrix.target }}" --arg sig "$(cat "$sig")" --arg url "$url" \
144167
'{($t): {signature: $sig, url: $url}}' > "fragment-${{ matrix.target }}.json"
145168
cat "fragment-${{ matrix.target }}.json"

0 commit comments

Comments
 (0)