Repository navigation
141 lines (138 loc) · 5.96 KB
/
Copy pathpackage-linux.yml
File metadata and controls
141 lines (138 loc) · 5.96 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
# Ubuntu packages, built and exercised on the exact distribution we support.
#
# This workflow deliberately produces an artifact instead of publishing a
# partial release. That keeps release credentials and publication authority
# in the unified release workflow while making every release candidate
# reproducible from an exact ref. Attach the resulting files to the matching
# canonical OpenMausBot release after the smoke test passes.
name: Package Ubuntu
on:
workflow_dispatch:
inputs:
ref:
description: "Commit/tag/branch to build (defaults to the branch this is run from)"
required: false
type: string
permissions:
contents: read
jobs:
package:
name: DEB + AppImage (Ubuntu 24.04 x64)
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.ref || github.ref }}
persist-credentials: false
- uses: pnpm/action-setup@ff378ebe6b225b0680b81c1ad4498ae0d1d3a5e3 # v6.0.10
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: pnpm
- name: Install package validation and native smoke tools
run: >-
sudo apt-get update && sudo apt-get install -y
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools x11-utils xdotool xvfb
- run: pnpm install --frozen-lockfile
- name: Clean generated output
run: pnpm clean
- name: Stage the pinned CUA runtime
run: pnpm build:cua:linux
- name: Prove overlay-free X11 input routing
run: dbus-run-session -- xvfb-run -a pnpm smoke:cua-x11-input
- name: Package from the verified offline CUA stage
run: pnpm package:linux:offline
- name: Verify package contents and metadata
run: node scripts/verify-linux-package.mjs
- name: Match a normal Ubuntu package parent on the ephemeral runner
run: |
test ! -L /opt
test "$(stat -c '%F %U:%G' /opt)" = "directory root:root"
case "$(stat -c '%a' /opt)" in
755) ;;
775|777) sudo chmod 0755 /opt ;;
*) echo "Unexpected /opt mode: $(stat -c '%a' /opt)" >&2; exit 1 ;;
esac
test "$(stat -c '%U:%G %a' /opt)" = "root:root 755"
- name: Reproduce and verify an in-place DEB upgrade
run: |
deb=(release/*.deb)
test "${#deb[@]}" -eq 1
sudo --preserve-env=CI,RUNNER_TEMP node scripts/smoke-deb-upgrade.mjs "${deb[0]}"
- name: Prove the handed-over Ubuntu command installs
# The .deb path ends with a command on the user's clipboard, so the
# command is the deliverable. Runs it as root on a clean Ubuntu through
# a real shell, and checks that the `dpkg -i` it replaced still fails
# there — the reason the app must not run that itself.
run: |
deb=(release/*.deb)
test "${#deb[@]}" -eq 1
pnpm smoke:deb-command "${deb[0]}"
- name: Prove an AppImage update lands on the launched path
# Installs the current published release over a copy named after a
# version, which is the shape that used to orphan the launcher. Runs
# against the real feed, so it also covers the differential download.
run: pnpm smoke:linux-update
- name: Configure Chromium sandbox for the unpacked app
run: |
sudo chown root:root release/linux-unpacked/chrome-sandbox
sudo chmod 4755 release/linux-unpacked/chrome-sandbox
test "$(stat -c '%U:%G %a' release/linux-unpacked/chrome-sandbox)" = "root:root 4755"
- name: Verify the installed browser with Ubuntu sandbox restrictions
run: node scripts/smoke-browser-bundle.mjs --resources /opt/OpenMausBot/resources
- name: Launch packaged app and verify lifecycle
env:
OMB_KEEP_SMOKE_DIR: "1"
OMB_SMOKE_INSTALLED_DEB: "1"
run: pnpm smoke:linux-package
- name: Remove the installed upgrade fixture
if: always()
run: sudo dpkg --purge openmausbot || true
- name: Prepare release assets
id: release
shell: bash
run: |
set -euo pipefail
version="$(node -p "require('./package.json').version")"
appimage="release/OpenMausBot-${version}-x86_64.AppImage"
deb="release/OpenMausBot-${version}-amd64.deb"
test -f "$appimage"
test -f "$deb"
cp "$appimage" release/OpenMausBot.AppImage
cp "$deb" release/OpenMausBot-amd64.deb
chmod 0755 release/OpenMausBot.AppImage
(
cd release
sha256sum \
"$(basename "$appimage")" \
"$(basename "$deb")" \
OpenMausBot.AppImage \
OpenMausBot-amd64.deb > SHA256SUMS-ubuntu-x64.txt
)
echo "artifact-name=openmausbot-ubuntu-${version}-x64" >> "$GITHUB_OUTPUT"
echo "version: $version"
echo "commit: $(git rev-parse HEAD)"
cat release/SHA256SUMS-ubuntu-x64.txt
- name: Upload smoke diagnostics on failure
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: failure()
with:
name: openmausbot-ubuntu-smoke-diagnostics
path: |
/tmp/omb-linux-smoke-*
/tmp/omb-linux-smoke-runtime-*
if-no-files-found: warn
include-hidden-files: true
retention-days: 7
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ steps.release.outputs.artifact-name }}
path: |
release/OpenMausBot-*-amd64.deb
release/OpenMausBot-*-x86_64.AppImage
release/OpenMausBot-amd64.deb
release/OpenMausBot.AppImage
release/SHA256SUMS-ubuntu-x64.txt
if-no-files-found: error
retention-days: 14