Author SHA1 Message Date
shadowdaoandClaude Opus 5 394dc7107c Match actual runner labels and use the injected token
The mac job targeted macos-arm64, but the registered Mac runner is
labelled macos-latest, so that job would have queued forever rather than
failing -- a job with no matching runner is silently pending.

Also switches the publish step to secrets.GITEA_TOKEN, which Gitea injects
automatically and scopes to the repo, instead of requiring a hand-created
RELEASE_TOKEN. RELEASE_TOKEN still overrides it if wider rights are needed.

Runners confirmed via /api/v1/admin/actions/runners: ubuntu-latest,
windows-latest (x2) and macos-latest are all online.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-28 18:56:58 -07:00
jknapp f8d10d3a24 Merge pull request 'Build each platform on its own native runner' (#3) from ci/native-builders into main 2026-08-29 01:53:39 +00:00
shadowdaoandClaude Opus 5 72485d44ff Build each platform on its own native runner
Splits the release workflow into linux, windows and macos jobs feeding a
single publish job. The publish step is separate so parallel builds cannot
race to create the release and fail on a duplicate tag.

Windows now builds natively, so signAndEditExecutable no longer has to be
disabled. That flag was suppressing rcedit, which is what embeds the icon
and version resources -- the v1.0.0 exe shipped with the stock Electron
icon as a result. Also adds an NSIS installer alongside the portable zip.

macOS gains a dmg target, which cannot be produced off macOS. Builds stay
unsigned pending a Developer ID, with CSC_IDENTITY_AUTO_DISCOVERY disabled
so electron-builder builds unsigned instead of failing on a real Mac.

Nothing cross-builds now; all three runners must be registered before
tagging, since a job with no matching runner queues silently.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-28 18:53:24 -07:00
jknapp 240535506b Merge pull request 'Add macOS target and platform-qualified artifact names' (#2) from release/v1.0.0 into main
Build AppImage / appimage (push) Failing after 22s
2026-08-29 01:11:44 +00:00
2 changed files with 138 additions and 27 deletions
+125 -22
View File
@@ -1,8 +1,21 @@
name: Build AppImage name: Build release artifacts
# Builds the Linux AppImage on a version tag and attaches it to a Gitea release. # Builds each platform natively on a v* tag and publishes one Gitea release.
# Tag must match the version in desktop-client/package.json, since electron-builder #
# names the artifact from package.json (not from the tag). # Runners required. None are registered yet, and a job with no matching runner
# queues silently rather than failing, so register all three before tagging:
# ubuntu-latest Linux AppImage
# windows-latest Windows NSIS installer + portable zip
# macos-latest macOS dmg + zip, both architectures (M-series builds both)
#
# Nothing cross-builds any more: dmg requires macOS, and the Windows exe needs
# rcedit on Windows to get its icon and version resources.
#
# A RELEASE_TOKEN secret is optional; GITEA_TOKEN is used by default.
#
# All output is unsigned. Once certificates exist: for macOS drop mac.identity
# from package.json and remove CSC_IDENTITY_AUTO_DISCOVERY; for Windows add the
# cert secrets. Until then users hit Gatekeeper and SmartScreen warnings.
on: on:
push: push:
tags: tags:
@@ -10,18 +23,19 @@ on:
workflow_dispatch: workflow_dispatch:
jobs: jobs:
appimage: linux:
runs-on: ubuntu-latest runs-on: ubuntu-latest
defaults: defaults:
run: run:
working-directory: desktop-client working-directory: desktop-client
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- uses: actions/setup-node@v4 - uses: actions/setup-node@v4
with: with:
node-version: '22' node-version: '22'
# Runs only here rather than in all three jobs: it is a repo-wide check,
# and this job uses bash, which is not guaranteed on the Windows runner.
- name: Verify tag matches package.json version - name: Verify tag matches package.json version
if: startsWith(github.ref, 'refs/tags/v') if: startsWith(github.ref, 'refs/tags/v')
run: | run: |
@@ -29,7 +43,7 @@ jobs:
tag_version="${GITHUB_REF_NAME#v}" tag_version="${GITHUB_REF_NAME#v}"
if [ "$pkg_version" != "$tag_version" ]; then if [ "$pkg_version" != "$tag_version" ]; then
echo "Tag $GITHUB_REF_NAME does not match package.json version $pkg_version." >&2 echo "Tag $GITHUB_REF_NAME does not match package.json version $pkg_version." >&2
echo "Bump package.json before tagging, or the AppImage will be misnamed." >&2 echo "Bump package.json before tagging, or artifacts will be misnamed." >&2
exit 1 exit 1
fi fi
@@ -42,31 +56,120 @@ jobs:
- name: Build AppImage - name: Build AppImage
run: npx electron-builder --linux AppImage --publish never run: npx electron-builder --linux AppImage --publish never
- name: Attach AppImage to release - uses: actions/upload-artifact@v3
if: startsWith(github.ref, 'refs/tags/v') with:
name: linux
path: desktop-client/dist/*.AppImage
if-no-files-found: error
windows:
runs-on: windows-latest
defaults:
run:
working-directory: desktop-client
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
- name: Install dependencies
run: npm ci
- name: Run tests
run: npm test
- name: Build installer and portable zip
run: npx electron-builder --win nsis zip --publish never
- uses: actions/upload-artifact@v3
with:
name: windows
path: |
desktop-client/dist/*.exe
desktop-client/dist/*-win-*.zip
if-no-files-found: error
macos:
runs-on: macos-latest
defaults:
run:
working-directory: desktop-client
env:
# No Developer ID yet: stop electron-builder auto-discovering an identity,
# which otherwise fails the build on a real Mac rather than building unsigned.
CSC_IDENTITY_AUTO_DISCOVERY: 'false'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
- name: Install dependencies
run: npm ci
- name: Run tests
run: npm test
- name: Build dmg and zip (both architectures)
run: npx electron-builder --mac --x64 --arm64 --publish never
- uses: actions/upload-artifact@v3
with:
name: macos
path: |
desktop-client/dist/*.dmg
desktop-client/dist/*-mac-*.zip
if-no-files-found: error
publish:
# Separate job so only one process touches the release: parallel build jobs
# would race to create it and one would fail on the duplicate tag.
needs: [linux, windows, macos]
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
steps:
- uses: actions/download-artifact@v3
with:
path: artifacts
- name: Create release and attach artifacts
env: env:
TOKEN: ${{ secrets.RELEASE_TOKEN }} # Gitea injects GITEA_TOKEN automatically, repo-scoped and short-lived.
# RELEASE_TOKEN is an optional override if wider rights are ever needed.
TOKEN: ${{ secrets.RELEASE_TOKEN || secrets.GITEA_TOKEN }}
API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }}
run: | run: |
set -euo pipefail set -euo pipefail
artifact=$(ls dist/*.AppImage | head -1) if [ -z "${TOKEN:-}" ]; then
echo "Publishing $artifact for $GITHUB_REF_NAME" echo "No token available (GITEA_TOKEN missing and RELEASE_TOKEN unset)." >&2
exit 1
fi
# Reuse the release if the tag already has one, otherwise create it.
release_id=$(curl -sf -H "Authorization: token $TOKEN" \ release_id=$(curl -sf -H "Authorization: token $TOKEN" \
"$API/releases/tags/$GITHUB_REF_NAME" | node -p \ "$API/releases/tags/$GITHUB_REF_NAME" \
"JSON.parse(require('fs').readFileSync(0,'utf8')).id" 2>/dev/null || true) | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id" 2>/dev/null || true)
if [ -z "${release_id:-}" ]; then if [ -z "${release_id:-}" ]; then
release_id=$(curl -sf -X POST -H "Authorization: token $TOKEN" \ release_id=$(curl -sf -X POST -H "Authorization: token $TOKEN" \
-H "Content-Type: application/json" \ -H "Content-Type: application/json" \
-d "{\"tag_name\":\"$GITHUB_REF_NAME\",\"name\":\"$GITHUB_REF_NAME\"}" \ -d "{\"tag_name\":\"$GITHUB_REF_NAME\",\"name\":\"$GITHUB_REF_NAME\"}" \
"$API/releases" | node -p \ "$API/releases" \
"JSON.parse(require('fs').readFileSync(0,'utf8')).id") | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id")
fi fi
curl -sf -X POST -H "Authorization: token $TOKEN" \ found=0
-F "attachment=@$artifact" \ for f in $(find artifacts -type f \( -name '*.AppImage' -o -name '*.zip' -o -name '*.dmg' -o -name '*.exe' \)); do
"$API/releases/$release_id/assets?name=$(basename "$artifact")" \ name=$(basename "$f")
-o /dev/null echo "Attaching $name"
echo "Attached $(basename "$artifact") to release $release_id" curl -sf -X POST -H "Authorization: token $TOKEN" \
-F "attachment=@$f" \
"$API/releases/$release_id/assets?name=$name" -o /dev/null
found=$((found + 1))
done
if [ "$found" -eq 0 ]; then
echo "No artifacts found to attach." >&2
exit 1
fi
echo "Attached $found artifacts to release $release_id"
+13 -5
View File
@@ -25,10 +25,11 @@
"main": "index.js" "main": "index.js"
}, },
"win": { "win": {
"target": "zip", "target": [
"sign": false, "nsis",
"signAndEditExecutable": false, "zip"
"certificateSubjectName": null ],
"icon": "build/icon.png"
}, },
"linux": { "linux": {
"target": [ "target": [
@@ -42,10 +43,17 @@
"artifactName": "${productName}-${version}-${os}-${arch}.${ext}", "artifactName": "${productName}-${version}-${os}-${arch}.${ext}",
"mac": { "mac": {
"target": [ "target": [
"dmg",
"zip" "zip"
], ],
"icon": "build/icon.png", "icon": "build/icon.png",
"category": "public.app-category.music" "category": "public.app-category.music",
"identity": null
},
"nsis": {
"oneClick": false,
"allowToChangeInstallationDirectory": true,
"perMachine": false
} }
}, },
"dependencies": { "dependencies": {