Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m45s
Phase A of the desktop Release + install path (M10 / tasks 2014, 1998): - .forgejo/workflows/desktop.yml: tag-gated "Publish release" step + contents:write. On a v* tag the build now publishes a Fabled-Git Release with the de-bundled AppImage + .deb attached — a stable, versioned fetch target (Actions artifacts are ephemeral/test-only). Dormant on dev/main. - desktop/packaging/publish-release.sh: creates/reuses the Release via the Forgejo API using the runner-injected token; idempotent asset replace. - desktop/packaging/install.sh: curl|sh one-command installer — native .deb on Debian/Ubuntu, de-bundled AppImage everywhere else (installed to ~/Applications/ThoughtSync.AppImage, matching src/integration.rs so the app sees itself integrated). AppImage path needs no sudo. Plumbing only — no release cut (rule 2); activates on the operator's first v* tag. In-app self-update (tauri-plugin-updater + signed latest.json) is Phase B, gated on the operator's signing key. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
106 lines
4.5 KiB
YAML
106 lines
4.5 KiB
YAML
# Tauri desktop (Linux) build — SEPARATE from ci.yml on purpose: this is a heavy
|
|
# Rust + AppImage build (~20-40 min) that should NOT run on backend/frontend-only
|
|
# pushes. Scoped to desktop/** (+ this file). Produces the .deb and .AppImage.
|
|
#
|
|
# Toolchain comes from the ci-tauri image (Rust + Node + WebKitGTK 4.1 + tauri-cli);
|
|
# runs-on is just a registered scheduling label (Label Model B), not a per-purpose
|
|
# runner. The frontend is built here because tauri's generate_context! embeds it.
|
|
name: Desktop (Tauri)
|
|
|
|
on:
|
|
push:
|
|
branches: [dev, main]
|
|
tags: ["v*"]
|
|
paths:
|
|
- "desktop/**"
|
|
# The desktop app embeds the frontend, and the data seam / Tauri bridge are
|
|
# what the offline core rides on — rebuild the app when those change too.
|
|
- "frontend/src/adapters/**"
|
|
- "frontend/src/desktop/**"
|
|
- ".forgejo/workflows/desktop.yml"
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: desktop-${{ github.ref }}
|
|
cancel-in-progress: ${{ !startsWith(github.ref, 'refs/tags/') }}
|
|
|
|
permissions:
|
|
# write (not read) so the tag build can publish a Release with the bundles
|
|
# attached (the "Publish release" step). Read is enough for dev/main builds,
|
|
# but the token scope is per-workflow, so it's set once here.
|
|
contents: write
|
|
|
|
jobs:
|
|
build:
|
|
name: Tauri desktop (Linux)
|
|
if: github.ref == 'refs/heads/dev' || github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v')
|
|
runs-on: python-ci
|
|
container:
|
|
image: git.fabledsword.com/bvandeusen/ci-tauri:1.97
|
|
env:
|
|
# AppImage tooling (linuxdeploy) FUSE-mounts itself by default; CI containers
|
|
# have no /dev/fuse, so tell it to extract-and-run instead. Without this the
|
|
# AppImage bundle step fails with a FUSE error.
|
|
APPIMAGE_EXTRACT_AND_RUN: "1"
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
# tauri's generate_context! embeds the built frontend at compile time, so the
|
|
# frontend must exist before any cargo compile (clippy/test/build), not just
|
|
# at bundle time.
|
|
- name: Build the shared frontend
|
|
run: npm ci && npm run build
|
|
working-directory: frontend
|
|
|
|
- name: Rust format check
|
|
run: cargo fmt --check
|
|
working-directory: desktop/src-tauri
|
|
|
|
- name: Clippy
|
|
run: cargo clippy --all-targets -- -D warnings
|
|
working-directory: desktop/src-tauri
|
|
|
|
- name: Test
|
|
run: cargo test
|
|
working-directory: desktop/src-tauri
|
|
|
|
# Frontend already built above; skip the beforeBuildCommand rebuild.
|
|
- name: Tauri build (deb + AppImage)
|
|
run: cargo tauri build --config '{"build":{"beforeBuildCommand":""}}'
|
|
working-directory: desktop/src-tauri
|
|
|
|
# Tauri's AppImage bundles the build host's graphics/display libs
|
|
# (libEGL/libGL/libdrm/libgbm/libwayland-*), which clash with end-user GPU
|
|
# drivers and abort to a black window (EGL_BAD_PARAMETER, issue 2021).
|
|
# Strip that host-coupled stack so the app uses the running system's
|
|
# graphics libs; webkit/gtk stay bundled. Runs from the repo root (the
|
|
# script resolves its own paths), overwriting the AppImage in place.
|
|
- name: De-bundle AppImage graphics libraries
|
|
run: bash desktop/packaging/appimage/debundle-graphics.sh
|
|
|
|
# Make the built .deb + .AppImage downloadable from the run (for hand-testing).
|
|
# continue-on-error: the Forgejo artifact backend may not be configured yet; a
|
|
# failed upload must not fail the build itself.
|
|
# Forgejo doesn't support the v4 artifact protocol (@actions/artifact v2+),
|
|
# so pin v3, which uses the older protocol the instance accepts.
|
|
- name: Upload bundles
|
|
continue-on-error: true
|
|
uses: actions/upload-artifact@v3
|
|
with:
|
|
name: thoughtsync-linux
|
|
path: |
|
|
desktop/src-tauri/target/release/bundle/appimage/*.AppImage
|
|
desktop/src-tauri/target/release/bundle/deb/*.deb
|
|
if-no-files-found: warn
|
|
|
|
# Tag builds only: publish a real, versioned Fabled-Git Release with the
|
|
# AppImage + .deb attached — the stable fetch target the install script and
|
|
# the in-app updater consume (Actions artifacts above are ephemeral/test).
|
|
# Cutting the tag is the operator's action (rule 2); this only publishes a
|
|
# Release for a tag that already exists. Dormant on dev/main pushes.
|
|
- name: Publish release
|
|
if: startsWith(github.ref, 'refs/tags/v')
|
|
env:
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
run: bash desktop/packaging/publish-release.sh
|