Author SHA1 Message Date
shadowdaoandClaude Opus 5 d218f4c6f3 Surface API errors in the publish step
The publish job has never run successfully. When it failed on the v1.0.0
tag it reported "SyntaxError: Unexpected end of JSON input" from piping an
empty curl body into JSON.parse, which said nothing about the actual cause
(an unset token). An opaque failure there costs a full three-platform build.

Routes every call through a helper that captures the HTTP status and prints
the response body on 4xx/5xx. Also switches artifact iteration to while-read
so filenames with spaces cannot split, and dumps the artifact tree when
nothing matches.

Helper verified against the live API: existing tag resolves to its release
id, a missing tag reports HTTP 404 with the body and yields an empty id so
the create path runs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-28 20:39:45 -07:00
jknapp 1f79d7bcfe Merge pull request 'Match actual runner labels and use the injected token' (#4) from fix/runner-labels into main 2026-08-29 01:57:08 +00:00
shadowdaoandClaude Opus 5 394dc7107c Match actual runner labels and use the injected token
The mac job targeted macos-arm64, but the registered Mac runner is
labelled macos-latest, so that job would have queued forever rather than
failing -- a job with no matching runner is silently pending.

Also switches the publish step to secrets.GITEA_TOKEN, which Gitea injects
automatically and scopes to the repo, instead of requiring a hand-created
RELEASE_TOKEN. RELEASE_TOKEN still overrides it if wider rights are needed.

Runners confirmed via /api/v1/admin/actions/runners: ubuntu-latest,
windows-latest (x2) and macos-latest are all online.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-28 18:56:58 -07:00
jknapp f8d10d3a24 Merge pull request 'Build each platform on its own native runner' (#3) from ci/native-builders into main 2026-08-29 01:53:39 +00:00
+46 -17
View File
@@ -6,11 +6,13 @@ name: Build release artifacts
# queues silently rather than failing, so register all three before tagging: # queues silently rather than failing, so register all three before tagging:
# ubuntu-latest Linux AppImage # ubuntu-latest Linux AppImage
# windows-latest Windows NSIS installer + portable zip # windows-latest Windows NSIS installer + portable zip
# macos-arm64 macOS dmg + zip, both architectures (M-series builds both) # macos-latest macOS dmg + zip, both architectures (M-series builds both)
# #
# Nothing cross-builds any more: dmg requires macOS, and the Windows exe needs # Nothing cross-builds any more: dmg requires macOS, and the Windows exe needs
# rcedit on Windows to get its icon and version resources. # rcedit on Windows to get its icon and version resources.
# #
# A RELEASE_TOKEN secret is optional; GITEA_TOKEN is used by default.
#
# All output is unsigned. Once certificates exist: for macOS drop mac.identity # All output is unsigned. Once certificates exist: for macOS drop mac.identity
# from package.json and remove CSC_IDENTITY_AUTO_DISCOVERY; for Windows add the # from package.json and remove CSC_IDENTITY_AUTO_DISCOVERY; for Windows add the
# cert secrets. Until then users hit Gatekeeper and SmartScreen warnings. # cert secrets. Until then users hit Gatekeeper and SmartScreen warnings.
@@ -89,7 +91,7 @@ jobs:
if-no-files-found: error if-no-files-found: error
macos: macos:
runs-on: macos-arm64 runs-on: macos-latest
defaults: defaults:
run: run:
working-directory: desktop-client working-directory: desktop-client
@@ -133,39 +135,66 @@ jobs:
- name: Create release and attach artifacts - name: Create release and attach artifacts
env: env:
TOKEN: ${{ secrets.RELEASE_TOKEN }} # Gitea injects GITEA_TOKEN automatically, repo-scoped and short-lived.
# RELEASE_TOKEN is an optional override if wider rights are ever needed.
TOKEN: ${{ secrets.RELEASE_TOKEN || secrets.GITEA_TOKEN }}
API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }}
run: | run: |
set -euo pipefail set -euo pipefail
if [ -z "${TOKEN:-}" ]; then if [ -z "${TOKEN:-}" ]; then
echo "RELEASE_TOKEN secret is not set." >&2 echo "No token available (GITEA_TOKEN missing and RELEASE_TOKEN unset)." >&2
exit 1 exit 1
fi fi
release_id=$(curl -sf -H "Authorization: token $TOKEN" \ # Report the HTTP status and body on failure. A bare `curl -sf | JSON.parse`
"$API/releases/tags/$GITHUB_REF_NAME" \ # dies with "Unexpected end of JSON input" and hides the real cause, which is
| node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id" 2>/dev/null || true) # how the v1.0.0 run failed on a missing token.
api() {
local method="$1" path="$2"; shift 2
local out code
out=$(curl -s -w '\n%{http_code}' -X "$method" \
-H "Authorization: token $TOKEN" "$API$path" "$@")
code=$(printf '%s' "$out" | tail -n1)
body=$(printf '%s' "$out" | sed '$d')
if [ "$code" -ge 400 ]; then
echo "$method $path -> HTTP $code" >&2
echo "$body" >&2
return 1
fi
printf '%s' "$body"
}
# Reuse the release if the tag already has one, otherwise create it.
release_id=$(api GET "/releases/tags/$GITHUB_REF_NAME" 2>/dev/null \
| node -pe "JSON.parse(require('fs').readFileSync(0,'utf8')).id" 2>/dev/null || true)
if [ -z "${release_id:-}" ]; then if [ -z "${release_id:-}" ]; then
release_id=$(curl -sf -X POST -H "Authorization: token $TOKEN" \ echo "No release for $GITHUB_REF_NAME yet; creating it."
release_id=$(api POST "/releases" \
-H "Content-Type: application/json" \ -H "Content-Type: application/json" \
-d "{\"tag_name\":\"$GITHUB_REF_NAME\",\"name\":\"$GITHUB_REF_NAME\"}" \ -d "{\"tag_name\":\"$GITHUB_REF_NAME\",\"name\":\"$GITHUB_REF_NAME\"}" \
"$API/releases" \ | node -pe "JSON.parse(require('fs').readFileSync(0,'utf8')).id")
| node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id")
fi fi
if [ -z "${release_id:-}" ]; then
echo "Could not determine a release id." >&2
exit 1
fi
echo "Publishing to release $release_id"
# while-read rather than word-splitting a find, so spaces in names are safe.
found=0 found=0
for f in $(find artifacts -type f \( -name '*.AppImage' -o -name '*.zip' -o -name '*.dmg' -o -name '*.exe' \)); do while IFS= read -r f; do
name=$(basename "$f") name=$(basename "$f")
echo "Attaching $name" echo "Attaching $name ($(du -h "$f" | cut -f1))"
curl -sf -X POST -H "Authorization: token $TOKEN" \ api POST "/releases/$release_id/assets?name=$name" -F "attachment=@$f" >/dev/null
-F "attachment=@$f" \
"$API/releases/$release_id/assets?name=$name" -o /dev/null
found=$((found + 1)) found=$((found + 1))
done done < <(find artifacts -type f \( -name '*.AppImage' -o -name '*.zip' \
-o -name '*.dmg' -o -name '*.exe' \) | sort)
if [ "$found" -eq 0 ]; then if [ "$found" -eq 0 ]; then
echo "No artifacts found to attach." >&2 echo "No artifacts found to attach; build jobs produced nothing." >&2
find artifacts -type f | head -20 >&2
exit 1 exit 1
fi fi
echo "Attached $found artifacts to release $release_id" echo "Attached $found artifacts to release $release_id"