Skip to content

ci(release): pin legacy update feeds to the 0.2.20 notice manifests - #3157

Merged
kev1n77 merged 1 commit into
GCWing:mainfrom
kev1n77:fmy/updater
Sep 20, 2026
Merged

kev1n77 merged 1 commit into
GCWing:mainfrom
kev1n77:fmy/updater

Conversation

@kev1n77

@kev1n77 kev1n77 commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator

Summary

Every stable release re-downloaded latest.json and linux-binaries.json from the v0.2.19 tag, which silently erased the 0.2.20 upgrade notice after each new 1.x tag. This PR copies the pinned legacy manifests from scripts/fixtures/legacy-update-feeds/ instead and validates them inline, so the notice survives every future stable release without manual re-upload.

Type and Areas

Type: CI (release workflow) + test + docs

Areas: GitHub Actions release pipeline, release guard tests, release docs

Motivation / Impact

  • 0.2.x desktop clients keep seeing the pinned 1.0.x upgrade notice (version 0.2.20 with bilingual notes pointing to manual download and the Data Migrator) on every stable release, instead of silently regressing to the silent 0.2.19 manifest.
  • The desktop feed's platforms block still resolves to the final 0.2.19 artifacts, so the notice never installs 1.x into a 0.2.x client. The CLI feed stays byte-for-byte on 0.2.19 (no note field exists there).
  • Publication now byte-compares the uploaded legacy feeds against the pinned fixtures, so a drifting fixture or stale upload fails the run.
  • The workflow step no longer shells out to curl/jq for the copy, and the verify step is unrolled per manifest.

No direct user-facing change in 1.x clients; 1.x keeps reading the versioned latest-v1.json / linux-binaries-v1.json feeds.

Verification

  • node --test --test-name-pattern "legacy updater" scripts/check-github-config.test.mjs — pass. The test mirrors the CI working tree in a sandbox, executes the real step script via bash, and asserts the copied feeds are byte-identical to the pinned fixtures while latest-v1.json stays untouched.
  • pnpm --dir src/web-ui exec node ../../scripts/check-github-config.mjs — pass (15 YAML files parsed).
  • Full node --test scripts/check-github-config.test.mjs: 24/26 pass on Windows; the 2 failures (Relay image rebuild..., release publication omits target...) reproduce on the base commit via stash comparison and stem from the local WSL bash stripping $ variables in spawnSync args — CI (ubuntu bash) is unaffected.
  • Fixture integrity checked after commit: latest.json = version 0.2.20 with non-empty notes; linux-binaries.json = version 0.2.19.

Reviewer Notes

  • .gitattributes pins the fixtures to text eol=lf because the publication step uses cmp byte comparison; newlines must survive any checkout platform unchanged.
  • Compatibility: the fixtures are static data read only by the release workflow; no runtime code path depends on them.
  • Rollback: revert this single commit; releases then fall back to re-downloading the v0.2.19 tag feeds (the pre-existing behavior, which loses the notice after each new tag).

Checklist

  • This PR is focused and does not include secrets, temporary prompts, generated scratch files, or unrelated artifacts.
  • Relevant verification is recorded above, or skipped checks are explained.
  • User-facing strings, docs, and locales are updated where applicable.

Every stable release re-downloaded latest.json and linux-binaries.json
from the v0.2.19 tag, which silently erased the 0.2.20 upgrade notice
after each new 1.x tag. Copy the pinned manifests from
scripts/fixtures/legacy-update-feeds/ instead and validate them inline
(desktop feed = 0.2.20 with non-empty notes, CLI feed = 0.2.19). The
publication step byte-compares the uploaded feeds against the fixtures
so a drifting fixture or stale upload fails the run.

The step no longer shells out to curl or jq, and the verify step is
unrolled per manifest so it runs on any bash environment without
relying on loop-variable expansion.
@kev1n77
kev1n77 merged commit c3f8527 into GCWing:main Sep 20, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant