diff --git a/.gitea/workflows/build-app.yml b/.gitea/workflows/build-app.yml index 224b63b..c9454d5 100644 --- a/.gitea/workflows/build-app.yml +++ b/.gitea/workflows/build-app.yml @@ -206,6 +206,17 @@ jobs: cp app/src-tauri/target/release/bundle/appimage/*.AppImage artifacts/ 2>/dev/null || true ls -la artifacts/ + # A green job that published nothing is the worst outcome available: + # the release exists, carries no AppImage, and nobody is told. The + # `|| true` above is there so a missing bundle does not mask the real + # error, which makes this check the thing that catches it. + shopt -s nullglob + collected=(artifacts/*) + if [ ${#collected[@]} -eq 0 ]; then + echo "No artifacts collected — the bundler produced nothing." >&2 + exit 1 + fi + - name: Upload to Gitea release if: gitea.event_name == 'push' env: diff --git a/scripts/finalize-appimage.sh b/scripts/finalize-appimage.sh index 06ea5e9..2f8630b 100755 --- a/scripts/finalize-appimage.sh +++ b/scripts/finalize-appimage.sh @@ -103,8 +103,13 @@ CATEGORIES="Development;Utility;" repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" appdata_src="$repo_root/packaging/appimage/$APP_ID.appdata.xml" +# appimagetool looks for `.appdata.xml` and warns the +# metadata is missing under any other name — while the script cheerfully +# reported it present. The AppStream id inside the file is unchanged and is +# what actually identifies the component; only the filename follows the tool. +appdata_installed_as="Triple-C.appdata.xml" -dir="${1:?usage: unbundle-wayland-client.sh }" +dir="${1:?usage: finalize-appimage.sh }" cd "$dir" shopt -s nullglob @@ -125,15 +130,15 @@ echo "Inspecting $appimage" ( cd "$work" && "$here/$appimage" --appimage-extract >/dev/null ) root="$work/squashfs-root" -if [ ! -e "$root/usr/lib/$LIB" ]; then - # Not a failure: linuxdeploy may have stopped bundling it, which is the - # outcome this script exists to produce. - echo "$LIB is not bundled — leaving $appimage alone." - exit 0 -fi +# The demotion and the metadata are independent jobs, and an absent library +# must not skip the second. An early exit here also left `update-channel/` +# uncreated, which killed the publish step on a missing directory and took the +# tag and mirror jobs down with it — a half-published release. +demoted=false +if [ -e "$root/usr/lib/$LIB" ]; then -mkdir -p "$root/$FALLBACK_DIR" -mv "$root/usr/lib/$LIB" "$root/$FALLBACK_DIR/$LIB" + mkdir -p "$root/$FALLBACK_DIR" + mv "$root/usr/lib/$LIB" "$root/$FALLBACK_DIR/$LIB" cat > "$root/$HOOK" <<'HOOK_EOF' #! /usr/bin/env bash @@ -182,6 +187,11 @@ src = src.replace( ) open(path, "w").write(src) PATCH_EOF + fi + demoted=true + echo "Demoted $LIB to $FALLBACK_DIR." +else + echo "$LIB is not bundled — nothing to demote." fi # --- metadata ------------------------------------------------------------- @@ -193,7 +203,7 @@ version="$(printf '%s' "$appimage" | sed -n 's/.*_\([0-9][0-9.]*\)_.*/\1/p')" if [ -f "$appdata_src" ]; then mkdir -p "$root/usr/share/metainfo" sed -e "s/@VERSION@/$version/" -e "s/@DATE@/$(date -u +%Y-%m-%d)/" \ - "$appdata_src" > "$root/usr/share/metainfo/$APP_ID.appdata.xml" + "$appdata_src" > "$root/usr/share/metainfo/$appdata_installed_as" echo "Added AppStream metadata for $version." else echo "No AppStream source at $appdata_src — skipping." >&2 @@ -208,7 +218,7 @@ for desktop in "$root"/*.desktop; do fi done -echo "Demoted $LIB to $FALLBACK_DIR; repacking." +echo "Repacking." tool="$work/appimagetool" curl -fsSL -o "$tool" "$APPIMAGE_TOOL_URL" @@ -216,6 +226,7 @@ chmod +x "$tool" # --appimage-extract-and-run: CI runners generally have no FUSE. # -u embeds the update string and writes "$STABLE_NAME.zsync" beside the image. +rm -rf "$CHANNEL_DIR" mkdir -p "$CHANNEL_DIR" ARCH=x86_64 "$tool" --appimage-extract-and-run \ -u "$UPDATE_INFO" "$root" "$CHANNEL_DIR/$STABLE_NAME" >/dev/null @@ -237,16 +248,18 @@ out="$check/squashfs-root" fail() { echo "FAILED: $1" >&2; exit 1; } -[ -e "$out/usr/lib/$LIB" ] && fail "$LIB is still on the loader path." -[ -e "$out/$FALLBACK_DIR/$LIB" ] || fail "the fallback copy of $LIB is missing." -[ -e "$out/$HOOK" ] || fail "the fallback hook is missing." -grep -q "triple-c-wayland-fallback" "$out/AppRun" || fail "AppRun does not source the hook." +if [ "$demoted" = true ]; then + [ -e "$out/usr/lib/$LIB" ] && fail "$LIB is still on the loader path." + [ -e "$out/$FALLBACK_DIR/$LIB" ] || fail "the fallback copy of $LIB is missing." + [ -e "$out/$HOOK" ] || fail "the fallback hook is missing." + grep -q "triple-c-wayland-fallback" "$out/AppRun" || fail "AppRun does not source the hook." +fi [ -x "$out/usr/bin/triple-c" ] || fail "no executable usr/bin/triple-c." # An empty Categories or missing metadata ships an image a manager cannot file # or describe, and both fail silently at runtime rather than at build time. -grep -q "^Categories=.\+" "$out"/*.desktop || fail "Categories is still empty." -[ -f "$appdata_src" ] && { [ -e "$out/usr/share/metainfo/$APP_ID.appdata.xml" ] \ +! grep -q "^Categories=$" "$out"/*.desktop || fail "a desktop file still has an empty Categories." +[ -f "$appdata_src" ] && { [ -e "$out/usr/share/metainfo/$appdata_installed_as" ] \ || fail "AppStream metadata did not make it into the image."; } # The update string is the difference between adoptable and updatable. It @@ -258,15 +271,18 @@ grep -q "^Categories=.\+" "$out"/*.desktop || fail "Categories is still empty." [ -e "$CHANNEL_DIR/$STABLE_NAME" ] || fail "the stable-named image is missing." [ -e "$CHANNEL_DIR/$STABLE_NAME.zsync" ] || fail "appimagetool wrote no .zsync." -readelf -p .upd_info "$CHANNEL_DIR/$STABLE_NAME" 2>/dev/null | grep -q "$UPDATE_TAG" \ - || fail "the image carries no update information for the $UPDATE_TAG tag." +readelf -p .upd_info "$CHANNEL_DIR/$STABLE_NAME" 2>/dev/null | grep -qF "$UPDATE_INFO" \ + || fail "the image does not carry exactly the expected update information." grep -aq "^Filename: $STABLE_NAME$" "$CHANNEL_DIR/$STABLE_NAME.zsync" \ || fail "the .zsync names something other than $STABLE_NAME." # The versioned release must carry one AppImage, not two. This is the guard # for the duplicate that shipped in 0.4.20 and 0.4.21. -count="$(ls -1 *.AppImage 2>/dev/null | wc -l)" -[ "$count" = "1" ] || fail "expected 1 AppImage beside the release, found $count." +shopt -s nullglob +beside=(*.AppImage) +shopt -u nullglob +[ "${#beside[@]}" -eq 1 ] \ + || fail "expected 1 AppImage beside the release, found ${#beside[@]}." echo "OK: $appimage prefers the host $LIB (fallback kept) and carries AppStream" echo " metadata. Channel pair in $CHANNEL_DIR/, updating from the $UPDATE_TAG tag." diff --git a/scripts/publish-update-channel.sh b/scripts/publish-update-channel.sh index 2d07298..198a125 100755 --- a/scripts/publish-update-channel.sh +++ b/scripts/publish-update-channel.sh @@ -57,23 +57,63 @@ done gh() { curl -sf -H "Authorization: Bearer $GH_PAT" -H "Accept: application/vnd.github+json" "$@"; } tea() { curl -sf -H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" "$@"; } -# Anchor the tag in Gitea first — see the header. Moved rather than left -# alone: it has to name this build, and the mirror will carry whatever Gitea -# holds over the top of GitHub's copy. -echo "==> Anchoring the $TAG tag in Gitea at ${GITEA_SHA:0:9}" -tea -X DELETE "$GITEA_API/repos/$GITEA_REPO/tags/$TAG" >/dev/null 2>&1 || true -tea -X POST "$GITEA_API/repos/$GITEA_REPO/tags" \ - -d "{\"tag_name\": \"$TAG\", \"target\": \"$GITEA_SHA\", \"message\": \"Rolling Linux update channel\"}" \ - >/dev/null +# Anchor the tag in Gitea — see the header. **Created if absent, never moved.** +# +# An earlier version deleted and recreated it so the tag would name the current +# build. That was worse than useless: nothing about the channel depends on +# which commit the tag points at — the update string resolves the tag by *name* +# and the assets hang off the release object — while a DELETE followed by a +# failed POST destroys a working anchor and leaves a window in which a mirror +# run prunes GitHub's copy. A transient Gitea error would have converted a +# healthy channel into a dead one, which is strictly worse than this step not +# existing. Gitea's POST /tags has no force semantics, so the DELETE was only +# ever there to get around a 409; asking first removes the need. +echo "==> Anchoring the $TAG tag in Gitea" +if tea "$GITEA_API/repos/$GITEA_REPO/tags/$TAG" >/dev/null 2>&1; then + echo " already anchored — left alone" +else + echo " creating it at ${GITEA_SHA:0:9}" + tea -X POST "$GITEA_API/repos/$GITEA_REPO/tags" \ + -d "{\"tag_name\": \"$TAG\", \"target\": \"$GITEA_SHA\", \"message\": \"Rolling Linux update channel\"}" \ + >/dev/null +fi # Not best-effort. Without this tag the mirror removes GitHub's and the # channel dies silently somewhere between now and four hours from now. tea "$GITEA_API/repos/$GITEA_REPO/tags/$TAG" >/dev/null 2>&1 \ || { echo "FAILED: the $TAG tag does not exist in Gitea; the mirror would delete GitHub's copy." >&2; exit 1; } -echo "==> Looking for the $TAG release" -release="$(gh "$API/releases/tags/$TAG" 2>/dev/null || true)" -release_id="$(printf '%s' "$release" | python3 -c 'import sys,json;print(json.load(sys.stdin).get("id",""))' 2>/dev/null || true)" +# Look through the authenticated list rather than /releases/tags/, which never +# returns drafts. That matters here specifically: GitHub demotes a published +# release to a draft when its tag is deleted, which is the state every mirror +# run left behind, so the by-tag lookup reports "absent" while orphaned drafts +# sit there holding 86 MB each. Reuse the newest and delete the rest, or they +# accumulate one per release forever. +echo "==> Looking for the $TAG release (drafts included)" +all_releases="$(gh "$API/releases?per_page=100")" +mapfile -t existing < <(printf '%s' "$all_releases" | python3 -c ' +import sys, json +tag = sys.argv[1] +rs = [r for r in json.load(sys.stdin) if r.get("tag_name") == tag] +rs.sort(key=lambda r: r.get("created_at",""), reverse=True) +for r in rs: + print(r["id"]) +' "$TAG") + +release_id="${existing[0]:-}" + +for stale in "${existing[@]:1}"; do + echo " deleting orphaned duplicate release $stale" + gh -X DELETE "$API/releases/$stale" >/dev/null || true +done + +if [ -n "$release_id" ]; then + # A draft has no tag and serves no download URL, so it has to be republished. + echo " reusing release $release_id" + gh -X PATCH "$API/releases/$release_id" \ + -d "{\"tag_name\": \"$TAG\", \"draft\": false}" >/dev/null + release="$(gh "$API/releases/$release_id")" +fi if [ -z "$release_id" ]; then echo "==> Creating it" @@ -107,9 +147,12 @@ for a in json.load(sys.stdin).get("assets", []): gh -X DELETE "$API/releases/assets/$asset_id" >/dev/null || true done +# --retry/--max-time/--http1.1 for the reason the Gitea upload steps in this +# repo carry them: real mid-stream failures on large assets (curl 92 and 28). for asset in "${ASSETS[@]}"; do echo "==> Uploading $asset ($(du -h "$asset" | cut -f1))" - curl -sf -X POST \ + curl -sf --http1.1 --retry 5 --retry-all-errors --retry-delay 5 --max-time 900 \ + -X POST \ -H "Authorization: Bearer $GH_PAT" \ -H "Content-Type: application/octet-stream" \ --data-binary "@$asset" \ @@ -119,12 +162,22 @@ done # The updater is only as good as this URL, and a silent failure here means # every installed copy quietly stops updating. Confirm both are actually # fetchable at the address the AppImage was built to check. +# Size as well as status: a 200 only proves something is served at the +# address, not that it is this build. GitHub accepting a truncated upload +# would pass a status-only check and then fail every client's checksum. echo "==> Verifying the published URLs" for asset in "${ASSETS[@]}"; do url="https://github.com/$REPO/releases/download/$TAG/$asset" - code="$(curl -s -o /dev/null -w '%{http_code}' -L "$url")" - [ "$code" = "200" ] || { echo "FAILED: $url returned $code" >&2; exit 1; } - echo " $code $url" + local_size="$(stat -c %s "$asset")" + + headers="$(curl -sIL "$url" | tr -d '\r')" + code="$(printf '%s\n' "$headers" | awk '/^HTTP\//{c=$2} END{print c}')" + served="$(printf '%s\n' "$headers" | awk 'tolower($1)=="content-length:"{n=$2} END{print n}')" + + [ "$code" = "200" ] || { echo "FAILED: $url returned ${code:-no status}" >&2; exit 1; } + [ "$served" = "$local_size" ] \ + || { echo "FAILED: $url serves ${served:-unknown} bytes, built $local_size." >&2; exit 1; } + echo " $code $served bytes $url" done echo "OK: $TAG updated, and anchored in Gitea so the mirror preserves it."