Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
9ff2675
fix(desktop): ratchet renderer debt against the base tree, not its le…
liuxiaocs7 Aug 30, 2026
bdb103d
fix(desktop): remove first-send empty hero flash (#4246)
Sun-GLiang Aug 30, 2026
838936c
fix(desktop): retire consumed steering queue cards (#4232)
Sun-GLiang Aug 30, 2026
1451071
test(desktop): cover model picker failure and edge states (#4162)
liuxiaocs7 Aug 30, 2026
1f95a37
test(desktop): cover toast error and edge states (#4167)
liuxiaocs7 Aug 30, 2026
2db04c2
fix(desktop): preserve external-session rows across source switches (…
liuxiaocs7 Aug 30, 2026
7eb1ea4
fix(core): quarantine retired OpenCode Free model (#4216)
liuxiaocs7 Aug 30, 2026
2e2c552
test(desktop): cover change panel failure and edge states (#4169)
liuxiaocs7 Aug 30, 2026
19e211e
fix: align Desktop Nightly with the Infra rsync contract
Astro-Han Aug 30, 2026
2b82b9d
fix(runtime): fall back when Codex compaction is rejected (#4253)
liugddx Aug 30, 2026
f2e1033
fix(runtime): allow reading workspace ancestor directories under macO…
jsiu93 Aug 30, 2026
0c43678
fix(core,storage): unify the Codex thread source gate (#3702)
cat0825 Aug 30, 2026
ef073ff
refactor(cli): centralize localized TUI copy (#3990)
orangeCatDeveloper Aug 30, 2026
d50efcf
fix(desktop): stop Runtime Host after launcher loss (#4114)
hydraxman Aug 30, 2026
4c8b37c
fix(cli): wait for Host readiness before pairing (#4230)
orangeCatDeveloper Aug 30, 2026
c62980c
fix(runtime): discover contained symlinked skill directories (#4116)
Sun-GLiang Aug 30, 2026
3c52d2c
refactor(core): report capability audit facts directly (#3815)
joebasrawi Aug 30, 2026
be3a029
fix(desktop): realign renderer architecture ledger with source (#4255)
liuxiaocs7 Aug 30, 2026
1c52241
fix(core): refuse models whose declared output has no text (#4243)
Joob1n Aug 30, 2026
8f31305
feat(runtime-host): bind capability providers to Client owners (#4187)
me2seeks Aug 30, 2026
296b05a
ci: declare the Desktop Nightly environment (#4260)
Astro-Han Aug 30, 2026
d07ff87
feat(runtime-host): add Gitoxide candidate and accepted-tree read dat…
zhiiw Aug 30, 2026
95c80a7
feat(runtime): guide Auto tool selection by final tool surface (#3705)
testikun Aug 30, 2026
7bc66fd
test(core): unit-test the shared Unicode sanitizer (#3692)
rekcilyssup Aug 30, 2026
2cb1044
fix(desktop): show the Codex device sign-in code on connection-detail…
sosyz Aug 30, 2026
03ff1bc
test(desktop): story-cover Daily Review edge states (#4220)
liuxiaocs7 Aug 30, 2026
99c8705
test(desktop): story-cover Agent Graph edge states (#4212)
liuxiaocs7 Aug 30, 2026
aafc095
test(desktop): story-cover chat transcript edge states (#4211)
liuxiaocs7 Aug 30, 2026
be8608e
refactor: remove unvalidated review additions (#4264)
Astro-Han Aug 30, 2026
9582ce3
fix(runtime): canonicalize macOS sandbox temp roots (#4234)
jsiu93 Aug 30, 2026
4cbe224
fix(desktop): connect shared sessions through Peer Mesh (#4238)
M4n5ter Aug 30, 2026
b832348
fix: pin Desktop Nightly feed channel (#4266)
Astro-Han Aug 30, 2026
9793520
refactor(cli): ship one Eval runtime in the npm CLI package (#3946)
liuxiaocs7 Aug 30, 2026
60cb8b7
fix(build): derive Astryx surface inventory from @astryxdesign/core (…
liuxiaocs7 Aug 30, 2026
5058b29
fix(cli): refresh connection identities after /setup saves a connecti…
jsiu93 Aug 30, 2026
5d519d6
fix: bootstrap the Desktop Nightly destination (#4271)
Astro-Han Aug 30, 2026
756b34e
fix: support rsync 3.1 for Nightly bootstrap (#4280)
Astro-Han Aug 30, 2026
462a861
perf(runtime): remove generic turn tail injection (#4278)
Astro-Han Aug 30, 2026
66e6f4e
test: make Desktop Nightly validation deterministic (#4282)
Astro-Han Aug 30, 2026
8f797cf
fix(ui): allow composer attachments while a turn is running (#4231)
Sun-GLiang Aug 31, 2026
ac59b47
测试:扩展桌面端无障碍行为覆盖 (#4202)
1625567290 Aug 31, 2026
bc1b1d6
docs(readme): link Desktop Nightly downloads (#4294)
Astro-Han Aug 31, 2026
4a2e081
test(desktop): story-cover the terminal panel's failure and edge stat…
liuxiaocs7 Aug 31, 2026
f66e7ad
fix(desktop): name the session in the usage activity task column (#4219)
liuxiaocs7 Aug 31, 2026
c5bb068
docs(eval): restructure README with navigation and a troubleshooting …
amaldevcm Aug 31, 2026
1340990
feat(storage): define quiescent session snapshot boundary (#2968)
MicroGery Aug 31, 2026
4050099
feat(cli): reconcile externally replaced npm Runtime Hosts (#4069)
me2seeks Aug 31, 2026
28bdbc6
feat(runtime-host): bind OAuth login to Connection entities (#3924)
me2seeks Aug 31, 2026
e160eed
refactor(desktop): separate shared sessions from Runtime Host profile…
M4n5ter Aug 31, 2026
00389bd
refactor(runtime-host): reconcile Peer Mesh membership state (#4274)
M4n5ter Aug 31, 2026
a5610a5
feat(runtime-host): project peer Host reachability (#4275)
M4n5ter Aug 31, 2026
1d380b2
feat(desktop): make Peer Mesh operations responsive (#4276)
M4n5ter Aug 31, 2026
1e75800
feat(desktop): manage WSL host projects (#4306)
M4n5ter Aug 31, 2026
ef94235
fix(runtime-host): copy user-uploaded attachments when branching a co…
liuxiaocs7 Aug 31, 2026
6e6af95
chore(desktop): drop the completed hook transition section (#4332)
Astro-Han Aug 31, 2026
c54092e
feat(desktop): migrate Nightly to GitHub Releases (#4317)
Astro-Han Aug 31, 2026
bd951aa
refactor(runtime): persist durable Tool Result projections (#4287)
Astro-Han Aug 31, 2026
29d02dc
fix: preserve skill outcomes across queued-message recovery
Sun-GLiang Aug 31, 2026
dd92521
feat(storage): add semantic transcript position snapshots
Sun-GLiang Aug 30, 2026
0d8325a
chore(ci): retrigger checks after base repair
Sun-GLiang Aug 30, 2026
25919b5
fix(storage): unify turn position recovery primitives
Sun-GLiang Aug 30, 2026
d5d5305
feat(storage): add projection-aware semantic positions
Sun-GLiang Aug 30, 2026
15eb6b0
fix(storage): recover legacy bodyless admissions
Sun-GLiang Aug 30, 2026
59260d7
fix(storage): persist admission recovery fixed point
Sun-GLiang Aug 30, 2026
44307e1
fix(storage): invalidate admission recovery on purge
Sun-GLiang Aug 30, 2026
9f0e847
fix(storage): persist recovery failure provenance
Sun-GLiang Aug 30, 2026
650f0ac
fix(storage): constrain recovery failure pairs
Sun-GLiang Aug 30, 2026
7bcb2f9
fix(storage): export semantic transcript position limits
Sun-GLiang Aug 31, 2026
70c7177
feat(runtime-host): page semantic transcript turns
Sun-GLiang Aug 30, 2026
7e1e96d
test(storage): follow current transcript schema version
Sun-GLiang Aug 31, 2026
76b56d0
fix(runtime-host): sync semantic transcript epoch declaration
Sun-GLiang Aug 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
9 changes: 9 additions & 0 deletions .asf.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -110,6 +110,15 @@ github:
policies:
- name: main
type: branch
nightly:
required_reviewers: []
wait_timer: 0
prevent_self_review: false
deployment_branch_policy:
protected_branches: false
policies:
- name: main
type: branch
product-release:
required_reviewers:
- id: M4n5ter
Expand Down
21 changes: 12 additions & 9 deletions .github/DESKTOP_NIGHTLY.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,19 +21,22 @@

Desktop Nightly is an ephemeral developer snapshot, not an Apache release. It builds the current `main` commit every day so contributors can try recent Desktop changes and report problems without waiting for an ASF source-release vote.

The npm publication workflow gives each snapshot an immutable version such as `0.2.0-dev.42.20260829`. The run number is the sole ordering authority. After that exact npm version is public, it triggers Desktop Nightly with a version-only artifact; the authenticated workflow event supplies the exact source commit and upstream run. A packaged Nightly accepts updates only from `https://nightlies.apache.org/maka/desktop/`, advances only to a higher run number, and verifies that downloaded bytes were attested by `.github/workflows/desktop-nightly.yml` on `main`. A formal Desktop build continues to use the GitHub Release feed and the formal product-release attestation identity.
The npm publication workflow gives each snapshot an immutable version such as `0.2.0-dev.42.20260829`. The run number is the sole ordering authority. After that exact npm version is public, it triggers Desktop Nightly with a version-only artifact; the authenticated workflow event supplies the exact source commit and upstream run. Each fresh Desktop Nightly creates a protected `v<version>` tag and one GitHub draft prerelease containing the macOS and Windows packages, blockmaps, `dev-mac.yml`, `dev.yml`, and one offline Sigstore bundle. The workflow verifies every remote asset before it publishes the prerelease as non-Latest. Packaged Nightlies use the GitHub `dev` channel and verify that downloaded bytes were attested by `.github/workflows/desktop-nightly.yml` on `main`. A formal Desktop build uses the separate stable GitHub Release channel and formal product-release attestation identity.

Nightly currently uses the same application identity as the formal Desktop. Installing it replaces the existing Maka installation rather than creating a second side-by-side app. Its user data remains in the same location. Testers who need the formal build should reinstall that build before returning to the formal channel.
Nightly currently uses the same application identity as the formal Desktop. Installing it replaces the existing Maka installation rather than creating a second side-by-side app. Its user data remains in the same location. Testers who need the formal build should reinstall that build before returning to the formal channel. Builds previously downloaded from `nightlies.apache.org` do not migrate automatically; testers must install the newest GitHub prerelease once, after which GitHub Nightlies update automatically.

## One-time setup

1. Ask Apache Infra to allow `apache/maka` to publish GitHub Actions output to `nightlies.apache.org`, provide the SSH `known_hosts` entry through an authenticated channel, and confirm whether retention is service-managed or requires a separate project cleanup job. Do not enable scheduled publication until that retention owner is explicit.
2. Create a GitHub Environment named `nightly` that permits only `main`. Store `NIGHTLIES_RSYNC_PATH`, `NIGHTLIES_RSYNC_HOST`, `NIGHTLIES_RSYNC_PORT`, `NIGHTLIES_RSYNC_USER`, `NIGHTLIES_RSYNC_KEY`, and the Infra-verified `NIGHTLIES_RSYNC_KNOWN_HOSTS` value as Environment secrets. Configure its macOS signing and notarization secrets: `CSC_LINK`, `CSC_KEY_PASSWORD`, `APPLE_API_KEY`, `APPLE_API_KEY_ID`, and `APPLE_API_ISSUER`. Do not expose these secrets to repository-wide or pull-request workflows.
3. Configure npm Trusted Publishing for `apache/maka` and `.github/workflows/npm-publication.yml`, restricted to the `npm-publication` Environment and with both `npm publish` and `npm stage publish` allowed. Do not create or store a long-lived npm token.
4. After npm Trusted Publishing is ready, set `NPM_NIGHTLY_ENABLED` to `true`, run `npm publication` from `main` with `channel=nightly`, and verify the exact npm version and `nightly` dist-tag. This does not depend on Desktop Infra.
5. After Infra publishing and the `nightly` Environment secrets are ready, set `DESKTOP_NIGHTLY_ENABLED` to `true` and start a fresh npm Nightly. Confirm that its successful run triggers `Desktop Nightly`.
6. Verify the download page, `latest-mac.yml`, and `latest.yml` under `https://nightlies.apache.org/maka/desktop/`, install both platform artifacts on clean machines, and confirm one automatic update before sharing the channel with testers.
1. After the checked-in `.asf.yaml` reaches `main`, verify that ASF reconciliation created the `nightly` GitHub Environment with only `main` permitted and no approval gate. Do not maintain that policy manually in GitHub. Configure its macOS signing and notarization secrets: `CSC_LINK`, `CSC_KEY_PASSWORD`, `APPLE_API_KEY`, `APPLE_API_KEY_ID`, and `APPLE_API_ISSUER`. Do not expose these secrets to repository-wide or pull-request workflows.
2. Configure npm Trusted Publishing for `apache/maka` and `.github/workflows/npm-publication.yml`, restricted to the `npm-publication` Environment and with both `npm publish` and `npm stage publish` allowed. Do not create or store a long-lived npm token.
3. Enable GitHub Immutable Releases for `apache/maka` before distributing Desktop Nightlies so published tags and assets cannot be replaced or deleted.
4. After npm Trusted Publishing is ready, set `NPM_NIGHTLY_ENABLED` to `true`, run `npm publication` from `main` with `channel=nightly`, and verify the exact npm version and `nightly` dist-tag.
5. Set `DESKTOP_NIGHTLY_ENABLED` to `true` and manually dispatch a fresh npm Nightly. Confirm that its successful run triggers `Desktop Nightly`. Do not rerun a failed attempt in place.
6. Verify that `v<version>` points to the exact source SHA and that its GitHub Release is published with Draft off, Prerelease on, Latest off, Immutable on, and exactly the nine expected assets. Install that prerelease on both platforms.
7. Publish one later fresh Nightly and confirm a GitHub-to-GitHub automatic and differential update on both platforms before sharing the channel with testers.

The npm schedule starts at 18:17 UTC. Before changing the npm tag, the workflow requires its run number to exceed the current `nightly` version. Desktop applies the same check against both remote feed files before uploading anything. It then appends a new immutable Desktop version directory and advances the mutable update metadata last. Each platform feed file is replaced independently after its complete payload exists, so an interrupted feed transfer may temporarily leave macOS and Windows on different valid Nightly versions. Do not rerun a failed workflow attempt in place; start a fresh npm Nightly so it receives a new version. Historical payload cleanup is separate from publication, targets the Nightlies retention policy, and must never rewrite a published version or delete one referenced by a feed. Apache Nightlies storage is temporary; it must not be used as a formal release archive.
The npm schedule starts at 18:17 UTC. Before changing the npm tag, the workflow requires its run number to exceed the current `nightly` version. Desktop assembles and verifies a draft before one publish mutation; a packaging, attestation, tag, upload, or digest failure leaves no partially published GitHub Release. Never rerun a failed workflow attempt in place; dispatch a fresh npm Nightly with a newer version.

GitHub Release retention is intentionally outside this workflow. Do not delete an old Nightly prerelease or its tag while any installed client may need its payload or blockmap. Disabling `DESKTOP_NIGHTLY_ENABLED` stops new Desktop publication without mutating tags or releases.

Remote Runtime Host setup uses the exact `maka-agent@<nightly-version>` package embedded in the Desktop manifest. The npm package is verified before Desktop artifacts become visible, so clean remote setup never depends on an unpublished Runtime Host version.
8 changes: 4 additions & 4 deletions .github/RELEASE_CHECKLIST.md
Original file line number Diff line number Diff line change
Expand Up @@ -63,10 +63,10 @@ Before the first product release, confirm the checked-in `.asf.yaml` has reconci
- the `Immutable release tags` ruleset blocks updates, force-pushes, and deletions of `v*` tags;
- the `release` Environment accepts only its declared source-candidate tag pattern and requires a
reviewer other than the triggering user;
- `npm-publication` and `product-release` accept only `main`; `product-release` requires a reviewer
other than the triggering user. `npm-publication` has no GitHub
approval gate because scheduled Nightly publication is automatic; formal npm publication still
requires human 2FA approval after staging.
- `npm-publication`, `nightly`, and `product-release` accept only `main`; `product-release` requires
a reviewer other than the triggering user. `npm-publication` and `nightly` have no GitHub approval
gate because scheduled npm and Desktop Nightly publication is automatic; formal npm publication
still requires human 2FA approval after staging.

These controls close the check-to-upload and check-to-stage windows. Finalize uses GitHub Actions
OIDC rather than a stored signing key to attest every convenience artifact. Keep the Release in
Expand Down
6 changes: 4 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@ jobs:
fi

- name: Install dependencies
if: steps.plan.outputs.code == 'true' || steps.plan.outputs.asf_source == 'true' || steps.plan.outputs.cli_package == 'true' || steps.plan.outputs.release_contract == 'true'
if: steps.plan.outputs.code == 'true' || steps.plan.outputs.astryx_surface == 'true' || steps.plan.outputs.asf_source == 'true' || steps.plan.outputs.cli_package == 'true' || steps.plan.outputs.release_contract == 'true'
run: npm ci

# The header audit above remains install-free. The complete source gate
Expand Down Expand Up @@ -181,7 +181,9 @@ jobs:
# directly instead of being hidden behind an earlier compilation failure.
- name: Astryx surface inventory
if: steps.plan.outputs.code == 'true' || steps.plan.outputs.astryx_surface == 'true'
run: npm run astryx:surface-inventory
run: |
npm run astryx:surface-inventory
npm run astryx:surface-inventory:test

- name: Build
if: steps.plan.outputs.code == 'true' || steps.plan.outputs.cli_package == 'true' || steps.plan.outputs.release_contract == 'true'
Expand Down
105 changes: 43 additions & 62 deletions .github/workflows/desktop-nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -184,14 +184,14 @@ jobs:
"apps/desktop/release/Maka-$NIGHTLY_VERSION-mac-arm64.dmg" \
"apps/desktop/release/Maka-$NIGHTLY_VERSION-mac-arm64.zip" \
"apps/desktop/release/Maka-$NIGHTLY_VERSION-mac-arm64.zip.blockmap" \
apps/desktop/release/latest-mac.yml \
apps/desktop/release/dev-mac.yml \
"$STAGE_DIRECTORY/"
else
cp -- \
"apps/desktop/release/Maka-$NIGHTLY_VERSION-win-x64.exe" \
"apps/desktop/release/Maka-$NIGHTLY_VERSION-win-x64.exe.blockmap" \
"apps/desktop/release/Maka-$NIGHTLY_VERSION-win-x64.zip" \
apps/desktop/release/latest.yml \
apps/desktop/release/dev.yml \
"$STAGE_DIRECTORY/"
fi

Expand All @@ -212,7 +212,7 @@ jobs:
permissions:
artifact-metadata: write
attestations: write
contents: read
contents: write
id-token: write
steps:
- name: Reject in-place workflow reruns
Expand Down Expand Up @@ -243,29 +243,26 @@ jobs:
path: ${{ github.workspace }}/.nightly-input
merge-multiple: true

- name: Stage the versioned Nightly site
- name: Stage the exact GitHub Release assets
env:
NIGHTLY_VERSION: ${{ needs.identity.outputs.version }}
SOURCE_COMMIT: ${{ needs.identity.outputs.source_commit }}
run: |
node scripts/desktop-nightly.mjs stage \
"$GITHUB_WORKSPACE/.nightly-input" \
"$GITHUB_WORKSPACE/.nightly-publish" \
"$NIGHTLY_VERSION" \
"$SOURCE_COMMIT"
"$GITHUB_WORKSPACE/.nightly-stage" \
"$NIGHTLY_VERSION"

- name: Attest the exact Nightly payloads
- name: Attest every GitHub Nightly asset subject
id: attest
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: ${{ github.workspace }}/.nightly-publish/versions/${{ needs.identity.outputs.version }}/*
subject-path: ${{ github.workspace }}/.nightly-stage/release/*

- name: Verify the issued Nightly provenance
env:
ATTESTATION_BUNDLE: ${{ steps.attest.outputs.bundle-path }}
CERTIFICATE_IDENTITY: https://github.com/${{ github.repository }}/.github/workflows/desktop-nightly.yml@refs/heads/main
GH_TOKEN: ${{ github.token }}
NIGHTLY_VERSION: ${{ needs.identity.outputs.version }}
run: |
verified=0
while IFS= read -r -d '' artifact; do
Expand All @@ -275,67 +272,51 @@ jobs:
--cert-identity "$CERTIFICATE_IDENTITY" \
--cert-oidc-issuer https://token.actions.githubusercontent.com
verified=$((verified + 1))
done < <(find "$GITHUB_WORKSPACE/.nightly-publish/versions/$NIGHTLY_VERSION" -maxdepth 1 -type f -print0)
if (( verified == 0 )); then
echo "No Desktop Nightly artifacts were verified" >&2
done < <(find "$GITHUB_WORKSPACE/.nightly-stage/release" -maxdepth 1 -type f -print0)
if (( verified != 8 )); then
echo "Expected 8 verified Desktop Nightly subjects, found $verified" >&2
exit 1
fi

- name: Add the offline provenance bundle
- name: Add the one offline provenance bundle
env:
ATTESTATION_BUNDLE: ${{ steps.attest.outputs.bundle-path }}
NIGHTLY_VERSION: ${{ needs.identity.outputs.version }}
run: >-
cp -- "$ATTESTATION_BUNDLE"
"$GITHUB_WORKSPACE/.nightly-publish/versions/$NIGHTLY_VERSION/Maka-$NIGHTLY_VERSION-attestation.sigstore.json"
run: |
node scripts/desktop-nightly.mjs add-attestation \
"$GITHUB_WORKSPACE/.nightly-stage" \
"$NIGHTLY_VERSION" \
"$ATTESTATION_BUNDLE"

- name: Prepare authenticated Nightlies SSH transport
- name: Ensure the exact versioned Nightly tag
env:
NIGHTLIES_RSYNC_HOST: ${{ secrets.NIGHTLIES_RSYNC_HOST }}
NIGHTLIES_RSYNC_KEY: ${{ secrets.NIGHTLIES_RSYNC_KEY }}
NIGHTLIES_RSYNC_KNOWN_HOSTS: ${{ secrets.NIGHTLIES_RSYNC_KNOWN_HOSTS }}
NIGHTLIES_RSYNC_PATH: ${{ secrets.NIGHTLIES_RSYNC_PATH }}
NIGHTLIES_RSYNC_PORT: ${{ secrets.NIGHTLIES_RSYNC_PORT }}
NIGHTLIES_RSYNC_USER: ${{ secrets.NIGHTLIES_RSYNC_USER }}
GH_TOKEN: ${{ github.token }}
NIGHTLY_VERSION: ${{ needs.identity.outputs.version }}
SOURCE_COMMIT: ${{ needs.identity.outputs.source_commit }}
run: |
test -n "$NIGHTLIES_RSYNC_HOST"
test -n "$NIGHTLIES_RSYNC_KEY"
test -n "$NIGHTLIES_RSYNC_KNOWN_HOSTS"
test -n "$NIGHTLIES_RSYNC_PATH"
test -n "$NIGHTLIES_RSYNC_USER"
[[ "$NIGHTLIES_RSYNC_PORT" =~ ^[0-9]{1,5}$ ]]
(( NIGHTLIES_RSYNC_PORT >= 1 && NIGHTLIES_RSYNC_PORT <= 65535 ))
ssh_directory="$RUNNER_TEMP/nightlies-ssh"
install -m 700 -d "$ssh_directory"
umask 077
printf '%s\n' "$NIGHTLIES_RSYNC_KEY" > "$ssh_directory/key"
printf '%s\n' "$NIGHTLIES_RSYNC_KNOWN_HOSTS" > "$ssh_directory/known_hosts"
{
echo "NIGHTLIES_RSYNC_TARGET=$NIGHTLIES_RSYNC_USER@$NIGHTLIES_RSYNC_HOST:${NIGHTLIES_RSYNC_PATH%/}/maka/desktop"
echo "RSYNC_RSH=ssh -i $ssh_directory/key -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o UserKnownHostsFile=$ssh_directory/known_hosts -p $NIGHTLIES_RSYNC_PORT"
} >> "$GITHUB_ENV"

- name: Require the Desktop Nightly feed to advance
gh auth setup-git
node scripts/product-release-tag.mjs ensure "v$NIGHTLY_VERSION" "$SOURCE_COMMIT"

- name: Prepare and verify the draft GitHub Prerelease
env:
GH_TOKEN: ${{ github.token }}
NIGHTLY_VERSION: ${{ needs.identity.outputs.version }}
SOURCE_COMMIT: ${{ needs.identity.outputs.source_commit }}
run: |
mkdir -p .nightly-current-feed
rsync -rlptDz --protect-args \
--include='/latest-mac.yml' \
--include='/latest.yml' \
--exclude='*' \
"$NIGHTLIES_RSYNC_TARGET/" \
.nightly-current-feed/
node scripts/desktop-nightly.mjs assert-feed-advance \
.nightly-current-feed \
"$NIGHTLY_VERSION"

- name: Publish immutable Nightly payloads
run: rsync -rlptDvz --protect-args .nightly-publish/versions/ "$NIGHTLIES_RSYNC_TARGET/versions/"

- name: Advance the Nightly update feed last
run: rsync -rlptDvz --protect-args .nightly-publish/feed/ "$NIGHTLIES_RSYNC_TARGET/"
node scripts/desktop-nightly-release.mjs prepare \
"$GITHUB_WORKSPACE/.nightly-stage/release" \
"$NIGHTLY_VERSION" \
"$SOURCE_COMMIT" \
"$GITHUB_REPOSITORY"

- name: Remove the temporary Nightlies credentials
if: always()
run: rm -f "$RUNNER_TEMP/nightlies-ssh/key" "$RUNNER_TEMP/nightlies-ssh/known_hosts"
- name: Publish the complete GitHub Prerelease
env:
GH_TOKEN: ${{ github.token }}
NIGHTLY_VERSION: ${{ needs.identity.outputs.version }}
SOURCE_COMMIT: ${{ needs.identity.outputs.source_commit }}
run: |
node scripts/desktop-nightly-release.mjs publish \
"$GITHUB_WORKSPACE/.nightly-stage/release" \
"$NIGHTLY_VERSION" \
"$SOURCE_COMMIT" \
"$GITHUB_REPOSITORY"
4 changes: 2 additions & 2 deletions .github/workflows/windows-recovery.yml
Original file line number Diff line number Diff line change
Expand Up @@ -158,8 +158,8 @@ jobs:
$exitCode = $LASTEXITCODE
if ($exitCode -ne 0) { exit $exitCode }
$output = Get-Content "$env:RUNNER_TEMP/skill-catalog.tap"
if ($output -notcontains '# tests 90' -or $output -notcontains '# pass 90' -or $output -notcontains '# skipped 0') {
Write-Error 'Skill catalog gate did not run exactly 90 passing Windows tests'
if ($output -notcontains '# tests 91' -or $output -notcontains '# pass 91' -or $output -notcontains '# skipped 0') {
Write-Error 'Skill catalog gate did not run exactly 91 passing Windows tests'
exit 1
}

Expand Down
Loading