Skip to content

Offer the macOS .dmg on the website instead of the updater payload - #3115

Merged
bobleer merged 2 commits into
GCWing:mainfrom
bobleer:lwb/mirror-macos-dmg-installers
Sep 18, 2026
Merged

bobleer merged 2 commits into
GCWing:mainfrom
bobleer:lwb/mirror-macos-dmg-installers

Conversation

@bobleer

@bobleer bobleer commented Sep 18, 2026

Copy link
Copy Markdown
Collaborator

Problem

https://openbitfun.com/download handed macOS visitors OpenBitFun_<version>_darwin-*.app.tar.gz. That is the Tauri updater payload: it has no installer UI, and a browser unpacks it into a bare .app wherever downloads land.

The signed .dmg was published with every release, but nothing downstream could reach it — latest-v1.json declared manual_installers for windows-x86_64 only, and write_website_download_manifest was written to substitute that single platform.

Changes

Release manifest declares the macOS installers. generate-tauri-latest-json.mjs takes --installer-assets-dir and requires each OpenBitFun_<version>_{aarch64,x64}.dmg to have its detached signature, so an unsigned or missing disk image fails the release rather than publishing a signature URL that 404s. The manifest step moves after Sign installer packages, which is what creates those signatures, and --required-manual-platforms now covers both macOS targets.

Mirror serves them. write_website_download_manifest applies every declared manual_installers entry instead of special-casing Windows, and mirror_macos_dmg_installers probes the deterministic .dmg names so releases published before this change — 1.0.1 included — get the same treatment without being rebuilt.

Both paths leave the updater URLs untouched. manual_installers stays a website/mirror extension, and the updater keeps consuming .app.tar.gz.

Verification

node --test scripts/tauri-release-manifest.test.mjs (8 pass, including a new case covering the macOS declaration, the unsigned-.dmg failure, and the missing-.dmg failure) and pnpm run check:github-config (27 pass).

Exercised on the production mirror, stable channel:

  • /release/downloads.json serves OpenBitFun_1.0.1_aarch64.dmg and OpenBitFun_1.0.1_x64.dmg
  • mirrored disk images match their GitHub sha256 byte for byte
  • /release/latest-v1.json still points the updater at the .app.tar.gz packages
  • the rendered download page offers DMG for both macOS architectures, EXE for Windows, AppImage for Linux

Remote scenarios: this touches release mirroring and the public website only. No change to workspace transport, remote control, peer device, or dispatch paths.

Follow-up outside this repo

OpenBitFun-Website needs the matching change — its mirrorArtifactDefinitions hard-codes format: "APP.TAR.GZ" for macOS, so the label has to be derived from the mirrored URL or the page shows a DMG link tagged APP.TAR.GZ. That fix is applied and live on the host but is not yet committed there, because the checkout already carries unrelated in-progress work.

The website handed macOS visitors OpenBitFun_<version>_darwin-*.app.tar.gz.
That file is the Tauri updater payload: no installer UI, and a browser unpacks
it into a bare .app wherever downloads happen to land. The signed .dmg was
published with every release but nothing downstream could reach it, because
latest-v1.json only declared manual_installers for windows-x86_64 and
downloads.json was written to substitute that one platform.

Declare the macOS installers in the release manifest. The generator now takes
--installer-assets-dir and requires each OpenBitFun_<version>_{aarch64,x64}.dmg
to have its detached signature, so an unsigned or missing disk image fails the
release instead of publishing a signature URL that 404s. Generating the
manifest moves after the installer signing step, which is what creates those
signatures.

Teach the mirror to serve them. write_website_download_manifest applies every
declared manual_installers entry rather than special-casing Windows, and
mirror_macos_dmg_installers probes the deterministic .dmg names so releases
published before this change — 1.0.1 included — get the same treatment without
being rebuilt. Both paths keep the updater URLs untouched: manual_installers
remains a website extension, and the updater must keep consuming .app.tar.gz.

Verified on the production mirror: /release/downloads.json now serves .dmg for
both macOS architectures, the mirrored disk images match their GitHub sha256,
and latest-v1.json still points the updater at the .app.tar.gz packages.
…nged

The website and the updater both read a floating latest-v1.json that always
names the current version, so retaining six releases plus every 0.2.x tree
did not help auto-update. Probe-and-rewrite logic for macOS .dmg names was
the same class of extra work: once the release manifest declares the disk
image, the sync only has to download what that file lists.

If GitHub Latest matches the published mirror, the script now prunes to the
two newest version directories and exits. A new version still pulls Desktop
updater packages, declared manual installers, Linux CLI/Relay archives, and
the Relay image descriptor. downloads.json continues to substitute every
manual_installers entry so the website gets the .dmg / Windows installer
while latest-v1.json keeps the updater payloads.
@bobleer
bobleer merged commit 28bdeb4 into GCWing:main Sep 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant