Files
camoufox/.github/workflows/build.yml
T
Jake WriterandClaude Opus 5.5 be9f38b08e chore: remove build tooling nothing uses
- The developer UI (scripts/developer.py, `make edits`). It depended on
  easygui, which no requirements file declares, and every action it offered is
  a Makefile target: patch, unpatch, workspace, revert, diff. Its two helpers in
  scripts/_mixin.py (is_bootstrap_patch, patch) had no other callers.
- legacy/, the Go launcher deprecated in 2024-11. Nothing built or shipped it.
  Its Makefile targets and scripts/run-pw.py go with it, and so does Go from
  every dependency list and workflow.
- jsonvv/ and settings/camoucfg.jvv. Nothing read the .jvv schema: config is
  validated against settings/properties.json, and the two had already drifted.
  The jsonvv package stays on PyPI.
- Scripts with no caller: bootstrap.py, moztree, setup-wasi-linux.sh,
  package-helper.sh, install-local-build.sh, mozfetch.sh (copied into lw/ but
  never packaged), examples/.
- The pre-ESM Juggler copies JugglerFrameParent.jsm and JugglerFrameChild.jsm,
  and hidden-scrollbars.css. Juggler loads the .sys.mjs actors and deliberately
  no stylesheet, but jar.mn still packaged all three.
- patches/librewolf/*.opt, which list_patches() never picks up; the roverfox
  second pass in patch.py, whose directory no longer exists; the unread
  --no-settings-pane option.
- The CAMOUFOX_PASSWD secret passed to `make fetch` and closedsrc_rev in
  upstream.sh, which nothing reads.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 15:20:45 -06:00

162 lines
5.5 KiB
YAML

name: Build and Release
on:
workflow_dispatch:
push:
tags:
- "*"
# The font bundle ships as its own release, in a separate tag namespace so
# it does not appear among the browser downloads. Those tags must not
# trigger a browser build (see scripts/fetch-fonts.py).
- "!font-bundle-*"
jobs:
build:
runs-on: ubuntu-24.04
strategy:
matrix:
target: [linux, windows, macos]
arch: [x86_64, arm64, i686]
exclude:
# Fails (.mozbuild does not include clang++-cl)
- target: windows
arch: arm64
# Unsupported
- target: macos
arch: i686
- target: linux
arch: i686
steps:
- name: Maximize build space
uses: AdityaGarg8/remove-unwanted-software@v4.1
with:
remove-dotnet: "true"
remove-android: "true"
remove-haskell: "true"
remove-codeql: "true"
remove-docker-images: "true"
remove-cached-tools: "true"
remove-swapfile: "true"
verbose: "false"
- name: Remove unwanted tools
# Originally from here: https://github.com/AdityaGarg8/remove-unwanted-software/blob/master/action.yml
run: |
sudo apt-get remove -y '^aspnetcore-.*' > /dev/null
sudo apt-get remove -y '^dotnet-.*' > /dev/null
sudo apt-get remove -y '^llvm-.*' > /dev/null
sudo apt-get remove -y 'php.*' > /dev/null
sudo apt-get remove -y '^mongodb-.*' > /dev/null
sudo apt-get remove -y '^mysql-.*' > /dev/null
sudo apt-get remove -y azure-cli google-chrome-stable firefox ${POWERSHELL} mono-devel libgl1-mesa-dri --fix-missing > /dev/null
if [[ (${CODENAME} = focal) || (${CODENAME} = jammy) ]]; then
sudo apt-get remove -y google-cloud-sdk --fix-missing > /dev/null
sudo apt-get remove -y google-cloud-cli --fix-missing > /dev/null
fi
sudo apt-get autoremove -y > /dev/null
sudo apt-get clean > /dev/null
- uses: actions/checkout@v2
with:
fetch-depth: 1
- name: Set up Python
uses: actions/setup-python@v2
with:
python-version: "3.11"
- name: Set up LLVM
run: |
wget https://apt.llvm.org/llvm.sh
chmod +x llvm.sh
sudo ./llvm.sh 18
sudo apt-get install -y lld-18 clang-18
if [ "${{ matrix.arch }}" != "x86_64" ]; then
sudo apt-get install -y libc6-i386 lib32gcc-s1 lib32stdc++6 gcc-multilib g++-multilib
fi
sudo update-alternatives --install /usr/bin/ld.lld ld.lld /usr/bin/ld.lld-18 100
- name: Check disk space
run: df -h
- name: Install dependencies
run: |
sudo apt-get update
# ccache: the mozconfig enables --with-ccache, but the runner image no
# longer ships it, so configure fails with "Cannot find ccache".
# fontconfig: scripts/verify-fonts.py resolves every reportable family
# through fc-list/fc-match, so the bundle is checked with the same tool
# the browser uses rather than assumed correct.
sudo apt-get install -y msitools p7zip-full aria2 ccache fontconfig
- name: Fetch the font bundle
# The bundle is a release asset, not repo content (~2.16 GB extracted,
# 843 MB as .tar.xz -- see scripts/fetch-fonts.py). Without this the
# package would ship with NO fonts while pythonlib/camoufox/fonts.json
# still reports hundreds of families, which is a reverse leak in the
# shipped browser. After the dependency install, so the download uses
# aria2c's parallel connections rather than the curl fallback.
run: make fonts-extract
- name: Verify the font bundle matches the manifest
# Full run, not --quick: this is the release path, and the one invariant
# that cannot be recovered after publishing is a family fonts.json
# reports that the packaged fontconfig cannot resolve.
run: python3 scripts/verify-fonts.py
- name: Fetch source
run: |
make fetch
- name: Setup and bootstrap
run: |
make setup-minimal
make mozbootstrap
mkdir -p dist
- name: Create swap space
run: |
sudo fallocate -l 24G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
free -h
df -h /
- name: Build
env:
# Cap Rust parallelism to lower peak memory (avoids OOM/SIGTERM).
# Tune to taste: higher = faster but more RAM.
CARGO_BUILD_JOBS: "1"
run: python3 ./multibuild.py --target ${{ matrix.target }} --arch ${{ matrix.arch }}
- name: Upload artifacts
uses: actions/upload-artifact@v4
with:
name: CamoufoxBuilds-${{ matrix.target }}-${{ matrix.arch }}
path: dist/*
release:
needs: build
permissions:
contents: write
runs-on: ubuntu-latest
steps:
- name: Download all artifacts
uses: actions/download-artifact@v4
with:
path: artifacts
- name: Create Release
uses: softprops/action-gh-release@v1
if: startsWith(github.ref, 'refs/tags/')
with:
files: artifacts/**/*
generate_release_notes: true
draft: true
prerelease: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}