Skip to content

fix(release): stage the whisper helper built from the release's own sources - #928

Merged
EtienneLescot merged 1 commit into
mainfrom
claude/pin-whisper-helper
Sep 30, 2026
Merged

EtienneLescot merged 1 commit into
mainfrom
claude/pin-whisper-helper

Conversation

@EtienneLescot

@EtienneLescot EtienneLescot commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Release builds stage whisper-stt-server from a build-whisper-stt.yml artifact. stage-whisper-stt.sh took the most recent artifact of any branch, so the helper a release shipped was whatever branch last pushed a helper change.

The script now takes the most recent successful run built from the same helper sources as the checked-out commit: the electron/native/whisper-stt tree, scripts/build-whisper-stt.sh and the workflow, compared by git object id. A release branch's cherry-pick matches the run built from main. No match fails the build with the command to run; it never falls back to "latest".

Related issue

Refs #917

Type of change

  • Bug fix

Release impact

  • No release note needed

Desktop impact

  • Installer / packaging

Testing

Resolution run locally against real runs (read-only gh):

Commit Run picked Why
main (46c304e) 36768174595 release branch's build, same sources
v2.0.0-rc.2 36768174595 its own branch's build
v2.0.0-rc.1 35702820234 main at the #639 merge, what rc.1 shipped
#919 branch 36765178472 its own build (different sources)
v1.13.0 34873691882 main before the VAD work

build.yml dispatched on this branch to run the new staging on all platforms (linked in a comment).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Windows installer builds now select a successful speech-to-text helper build that matches the packaged commit. If no matching build is available, staging fails with guidance to run the workflow on the target branch or tag.
    • Artifact download errors now identify the relevant workflow ref.
  • Documentation

    • Release guidance now explains helper build selection and what to do after cherry-picking helper changes.

…ources

stage-whisper-stt.sh downloaded the most recent whisper-stt artifact of
any branch. v2.0.0-rc.1 shipped whatever main had last built that way, and
on 2026-09-30 the most recent artifact came from a PR branch built from
main without the fix rc.2 was cut for.

It now takes the most recent successful build-whisper-stt run whose helper
sources (the electron/native/whisper-stt tree, the build script and the
workflow) are the objects checked out, compared by git object id, and fails
with the command to run when there is none.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Repository guideline files applied to this review (1)
technical-documentation/engineering/release-and-secrets.md — configured

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 792a6f9b-c7e2-418d-8495-f7ac52e55a45

📥 Commits

Reviewing files that changed from the base of the PR and between 46c304e and e6c7333.

📒 Files selected for processing (3)
  • .github/workflows/build.yml
  • scripts/stage-whisper-stt.sh
  • technical-documentation/engineering/release-and-secrets.md

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

The staging script now selects a successful helper build whose source files match the checked-out commit. It downloads the artifact from that run and exits with an error if no matching build exists.

Changes

STT artifact matching

Layer / File(s) Summary
Select and stage a matching helper artifact
scripts/stage-whisper-stt.sh, .github/workflows/build.yml, technical-documentation/engineering/release-and-secrets.md
The script checks up to 50 successful helper workflow runs for matching source object IDs and downloads the artifact from the matching run. The workflow comment and release guidance describe this behavior and the failure condition when no matching run exists.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant StagingScript as stage-whisper-stt.sh
  participant GitHubActions as build-whisper-stt.yml runs
  participant Git as Git object IDs
  StagingScript->>GitHubActions: List up to 50 successful runs
  GitHubActions-->>StagingScript: Return workflow runs
  StagingScript->>Git: Compare helper-source object IDs with HEAD
  Git-->>StagingScript: Return comparison results
  StagingScript->>GitHubActions: Download artifact from matching run ID
Loading

Merge Risk: ⚪ Minimal · up to e6c73

The change makes release staging use a helper build made from the release's own sources and fail clearly when none exists. No actionable merge-blocking risk was identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to e6c73

Release packaging now rejects helper builds from mismatched sources. The change strengthens release integrity, but matching selected source files does not establish complete build provenance or producer authorization.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A compromised eligible helper could execute during the staging load check with the release step's repository token and subsequently reach desktop installers. This producer-consumer exposure predates the PR; source matching narrows eligible runs rather than creating that execution path.

Trust Boundaries and Controls

  • observed — The new control rejects mismatched declared sources and binds download to the selected run in the configured repository. It does not validate actor, event, or branch authorization. Repository-scoped selection is counterevidence against accepting an arbitrary fork-hosted artifact, but actual producer access policies were not supplied.

Resilience and Maintainability Implications

  • inferred — No-match, download, and extraction failures precede destination writes, and temporary downloads are cleaned on exit. Installation itself remains non-atomic and unlocked. Interrupted copying or failed validation can leave files that a later invocation accepts through the existing-binary shortcut. This recovery limitation and shortcut predate the PR; no increased exposure was established.

Hardening Proposals

  • proposed — If helper-producing branches are less trusted than release authors, consider verifying approved producer provenance and broader build-input identity. This would extend the current source-match guarantee; it is not evidence of a newly introduced vulnerability.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: staging the Whisper helper built from the release's own sources.
Description check ✅ Passed The description follows the required template and includes the summary, related issue, change type, release impact, desktop impact, and detailed testing results.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@EtienneLescot

Copy link
Copy Markdown
Collaborator Author

Verified on CI: build.yml on this branch staged the helper from run 36768174595 (same helper sources) on all five jobs (Windows installer, Windows Store, macOS x64, macOS arm64, Linux), load check OK on each. I cancelled the run once staging had passed; the installer steps after it do not exercise this change.

🤖 Generated with Claude Code

@EtienneLescot
EtienneLescot merged commit 409cf4d into main Sep 30, 2026
19 of 26 checks passed
@EtienneLescot
EtienneLescot deleted the claude/pin-whisper-helper branch September 30, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant