fix(release): stage the whisper helper built from the release's own sources - #928
Conversation
…ources stage-whisper-stt.sh downloaded the most recent whisper-stt artifact of any branch. v2.0.0-rc.1 shipped whatever main had last built that way, and on 2026-09-30 the most recent artifact came from a PR branch built from main without the fix rc.2 was cut for. It now takes the most recent successful build-whisper-stt run whose helper sources (the electron/native/whisper-stt tree, the build script and the workflow) are the objects checked out, compared by git object id, and fails with the command to run when there is none.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Repository guideline files applied to this review (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 6 remain after this review. 📝 WalkthroughWalkthroughThe staging script now selects a successful helper build whose source files match the checked-out commit. It downloads the artifact from that run and exits with an error if no matching build exists. ChangesSTT artifact matching
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant StagingScript as stage-whisper-stt.sh
participant GitHubActions as build-whisper-stt.yml runs
participant Git as Git object IDs
StagingScript->>GitHubActions: List up to 50 successful runs
GitHubActions-->>StagingScript: Return workflow runs
StagingScript->>Git: Compare helper-source object IDs with HEAD
Git-->>StagingScript: Return comparison results
StagingScript->>GitHubActions: Download artifact from matching run ID
Merge Risk: ⚪ Minimal · up to The change makes release staging use a helper build made from the release's own sources and fail clearly when none exists. No actionable merge-blocking risk was identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Release packaging now rejects helper builds from mismatched sources. The change strengthens release integrity, but matching selected source files does not establish complete build provenance or producer authorization. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Verified on CI: build.yml on this branch staged the helper from run 36768174595 (same helper sources) on all five jobs (Windows installer, Windows Store, macOS x64, macOS arm64, Linux), load check OK on each. I cancelled the run once staging had passed; the installer steps after it do not exercise this change. 🤖 Generated with Claude Code |
Summary
Release builds stage
whisper-stt-serverfrom abuild-whisper-stt.ymlartifact.stage-whisper-stt.shtook the most recent artifact of any branch, so the helper a release shipped was whatever branch last pushed a helper change.v2.0.0-rc.1shipped the helpermainhad last built (with the feat(stt): add cross-platform Silero VAD pre-pass via whisper.cpp #639 timing bug).mainwithout the fix(stt): keep transcript words on the audio's clock when the VAD cuts silence #917 fix. rc.2 only shipped the fix because it was cut right after the release branch's own helper build.The script now takes the most recent successful run built from the same helper sources as the checked-out commit: the
electron/native/whisper-stttree,scripts/build-whisper-stt.shand the workflow, compared by git object id. A release branch's cherry-pick matches the run built frommain. No match fails the build with the command to run; it never falls back to "latest".Related issue
Refs #917
Type of change
Release impact
Desktop impact
Testing
Resolution run locally against real runs (read-only
gh):main(46c304e)v2.0.0-rc.2v2.0.0-rc.1mainat the #639 merge, what rc.1 shippedv1.13.0mainbefore the VAD workbuild.ymldispatched on this branch to run the new staging on all platforms (linked in a comment).🤖 Generated with Claude Code
Summary by CodeRabbit
Bug Fixes
Documentation