Offer the macOS .dmg on the website instead of the updater payload - #3115
Merged
Merged
Conversation
The website handed macOS visitors OpenBitFun_<version>_darwin-*.app.tar.gz.
That file is the Tauri updater payload: no installer UI, and a browser unpacks
it into a bare .app wherever downloads happen to land. The signed .dmg was
published with every release but nothing downstream could reach it, because
latest-v1.json only declared manual_installers for windows-x86_64 and
downloads.json was written to substitute that one platform.
Declare the macOS installers in the release manifest. The generator now takes
--installer-assets-dir and requires each OpenBitFun_<version>_{aarch64,x64}.dmg
to have its detached signature, so an unsigned or missing disk image fails the
release instead of publishing a signature URL that 404s. Generating the
manifest moves after the installer signing step, which is what creates those
signatures.
Teach the mirror to serve them. write_website_download_manifest applies every
declared manual_installers entry rather than special-casing Windows, and
mirror_macos_dmg_installers probes the deterministic .dmg names so releases
published before this change — 1.0.1 included — get the same treatment without
being rebuilt. Both paths keep the updater URLs untouched: manual_installers
remains a website extension, and the updater must keep consuming .app.tar.gz.
Verified on the production mirror: /release/downloads.json now serves .dmg for
both macOS architectures, the mirrored disk images match their GitHub sha256,
and latest-v1.json still points the updater at the .app.tar.gz packages.
…nged The website and the updater both read a floating latest-v1.json that always names the current version, so retaining six releases plus every 0.2.x tree did not help auto-update. Probe-and-rewrite logic for macOS .dmg names was the same class of extra work: once the release manifest declares the disk image, the sync only has to download what that file lists. If GitHub Latest matches the published mirror, the script now prunes to the two newest version directories and exits. A new version still pulls Desktop updater packages, declared manual installers, Linux CLI/Relay archives, and the Relay image descriptor. downloads.json continues to substitute every manual_installers entry so the website gets the .dmg / Windows installer while latest-v1.json keeps the updater payloads.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
https://openbitfun.com/downloadhanded macOS visitorsOpenBitFun_<version>_darwin-*.app.tar.gz. That is the Tauri updater payload: it has no installer UI, and a browser unpacks it into a bare.appwherever downloads land.The signed
.dmgwas published with every release, but nothing downstream could reach it —latest-v1.jsondeclaredmanual_installersforwindows-x86_64only, andwrite_website_download_manifestwas written to substitute that single platform.Changes
Release manifest declares the macOS installers.
generate-tauri-latest-json.mjstakes--installer-assets-dirand requires eachOpenBitFun_<version>_{aarch64,x64}.dmgto have its detached signature, so an unsigned or missing disk image fails the release rather than publishing a signature URL that 404s. The manifest step moves afterSign installer packages, which is what creates those signatures, and--required-manual-platformsnow covers both macOS targets.Mirror serves them.
write_website_download_manifestapplies every declaredmanual_installersentry instead of special-casing Windows, andmirror_macos_dmg_installersprobes the deterministic.dmgnames so releases published before this change — 1.0.1 included — get the same treatment without being rebuilt.Both paths leave the updater URLs untouched.
manual_installersstays a website/mirror extension, and the updater keeps consuming.app.tar.gz.Verification
node --test scripts/tauri-release-manifest.test.mjs(8 pass, including a new case covering the macOS declaration, the unsigned-.dmgfailure, and the missing-.dmgfailure) andpnpm run check:github-config(27 pass).Exercised on the production mirror, stable channel:
/release/downloads.jsonservesOpenBitFun_1.0.1_aarch64.dmgandOpenBitFun_1.0.1_x64.dmgsha256byte for byte/release/latest-v1.jsonstill points the updater at the.app.tar.gzpackagesDMGfor both macOS architectures,EXEfor Windows,AppImagefor LinuxRemote scenarios: this touches release mirroring and the public website only. No change to workspace transport, remote control, peer device, or dispatch paths.
Follow-up outside this repo
OpenBitFun-Websiteneeds the matching change — itsmirrorArtifactDefinitionshard-codesformat: "APP.TAR.GZ"for macOS, so the label has to be derived from the mirrored URL or the page shows a DMG link taggedAPP.TAR.GZ. That fix is applied and live on the host but is not yet committed there, because the checkout already carries unrelated in-progress work.