Skip to content

fix(relay): restore one-click deployment fallback and release integrity - #2894

Merged
bobleer merged 1 commit into
GCWing:mainfrom
bobleer:bob/fix-relay-deploy-fallback
Sep 8, 2026
Merged

bobleer merged 1 commit into
GCWing:mainfrom
bobleer:bob/fix-relay-deploy-fallback

Conversation

@bobleer

@bobleer bobleer commented Sep 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

Restore one-click Relay deployment when the current OpenBitFun stable image is not yet published. Missing/unreachable release artifacts or exhausted image pull/start attempts now fall back to a native Docker source build. Do not accept the retired image repository; invalid signed metadata remains an error after checking both origins.

Type and Areas

Bug fix; Relay deployment, Rust SSH services, Web UI, release workflows, mirror synchronization.

Motivation / Impact

  • Prepare Git/Buildx through the interactive terminal, keep sudo authorization alive during long builds, and start source builds by immutable local image ID. Preserve the running Relay until its replacement is ready and reuse existing health/rollback logic.
  • Include static pages in the source image, stop the failed-state spinner, and ignore late launch/poll results after the wizard closes or a new attempt starts. Update all three locales and deployment guidance.
  • Rebuild release images from their immutable release tag instead of the newer workflow commit. Mirror Relay/Linux metadata from the exact updater release and verify uploaded descriptor/signature bytes match the signed image-job artifacts.

Verification

  • cargo test --locked -p openbitfun-services-integrations --no-default-features --features remote-ssh-concrete --lib remote_ssh::relay_deploy::tests:: — 32 passed, including signed-metadata failover and sudo refresh lifetime.
  • node --test scripts/relay/*.test.mjs scripts/linux-binaries-manifest.test.mjs scripts/tauri-release-manifest.test.mjs — passed; covers real local Git fetch with simulated Docker failures, cancellation, restoration and release version selection.
  • pnpm run check:github-config, pnpm run check:web, pnpm run i18n:audit, pnpm run check:core-boundaries, pnpm run check:repo-hygiene, git diff --check — passed locally.
  • Downloaded the canonical v1.0.0-beta.3 Relay archives for both Linux architectures: verified renamed executable/static payloads, SHA256 checksums and minisign signatures against the Desktop trust root. Verified anonymous GHCR manifest access, its digest and both platforms.

Reviewer Notes

AI-assisted; tested locally with HTTP/Git and Docker-command fixtures. No actual VPS/SSH or source Docker build was run (local Docker daemon unavailable). Mobile remote control, Peer Device Mode and Detached Dispatch were not exercised. No persisted or wire DTO shape changes. Source fallback follows current canonical main and can take substantially longer than pulling an image.

Checklist

  • This PR is focused and does not include secrets, temporary prompts, generated scratch files, or unrelated artifacts.
  • Relevant verification is recorded above, or skipped checks are explained.
  • User-facing strings, docs, and locales are updated where applicable.

@bobleer
bobleer merged commit d95e471 into GCWing:main Sep 8, 2026
14 checks passed
@bobleer
bobleer deleted the bob/fix-relay-deploy-fallback branch September 24, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant