diff --git a/.github/workflows/adhoc-mac-build.yml b/.github/workflows/adhoc-mac-build.yml index bb5bdba37ae..17184e35509 100644 --- a/.github/workflows/adhoc-mac-build.yml +++ b/.github/workflows/adhoc-mac-build.yml @@ -6,7 +6,9 @@ name: Adhoc macOS + Windows Dev Build # # Deliberately narrow scope: # - macOS and Windows desktop installers. Linux keeps using RC/stable. -# - No tests, no lint, no e2e. PR CI and release-cut remain the gates. +# - No tests, no lint, no e2e. PR CI and release-cut remain the gates. The one +# exception is the orcad template: like release-cut, it is merged from the +# node-server lanes that build and qualify each SSH target's slot. # - macOS is signed and notarized so TCC grants survive updates. # - Windows is unsigned; the published release notes explain the one-time # SmartScreen/manual-install requirement. @@ -93,9 +95,59 @@ jobs: with: ref: ${{ inputs.ref || github.ref_name }} - build-adhoc-mac: - needs: relay-windows-process-tree + # Why: a branch cut before the orcad template landed has none to build or ship. + orcad-template-support: if: github.repository == 'stablyai/orca' + runs-on: ubuntu-latest + timeout-minutes: 5 + permissions: + contents: read + outputs: + ships: ${{ steps.detect.outputs.ships }} + steps: + - name: Checkout the template packager only + uses: actions/checkout@v6 + with: + ref: ${{ inputs.ref || github.ref_name }} + sparse-checkout: | + /config/scripts/packaged-orcad-template.cjs + sparse-checkout-cone-mode: false + persist-credentials: false + - name: Detect whether the ref ships the orcad template + id: detect + shell: bash + run: | + if [[ -f config/scripts/packaged-orcad-template.cjs ]]; then + echo "ships=true" >>"$GITHUB_OUTPUT" + else + echo "ships=false" >>"$GITHUB_OUTPUT" + echo "::notice::This ref predates the orcad template; the build ships without it." + fi + + # Design D2, as release-cut does: every desktop build ships the orcad template (server JS plus + # every target's addons), merged from the node-server lanes that qualify each slot at this ref. + # Without it an adhoc build cannot deploy managed orcad to an SSH host. No secrets, like the + # relay job, and the mac job vets the ref before anything is signed. + orcad-template: + needs: orcad-template-support + if: needs.orcad-template-support.outputs.ships == 'true' + permissions: + contents: read + uses: ./.github/workflows/node-server-tests.yml + with: + ref: ${{ inputs.ref || github.ref_name }} + build_template: true + + build-adhoc-mac: + needs: [relay-windows-process-tree, orcad-template-support, orcad-template] + # Why not the implicit success(): a ref without the orcad template skips that job on purpose. + if: >- + !cancelled() && github.repository == 'stablyai/orca' && + needs.relay-windows-process-tree.result == 'success' && + needs.orcad-template-support.result == 'success' && + (needs.orcad-template.result == 'success' || + (needs.orcad-template.result == 'skipped' && + needs.orcad-template-support.outputs.ships == 'false')) # Why an environment: it gives the signing/notary/App secrets somewhere to # live that a stale copy of this workflow on an old branch cannot reach. # Referencing it is a no-op until repo settings give it teeth; the intended @@ -109,6 +161,7 @@ jobs: version: ${{ steps.adhoc.outputs.version }} head_sha: ${{ steps.adhoc.outputs.head_sha }} published: ${{ steps.publish_live.outcome == 'success' && 'true' || 'false' }} + ships_orcad_template: ${{ needs.orcad-template-support.outputs.ships }} runs-on: blacksmith-6vcpu-macos-15 # Why 150: it must exceed the worst case the retry budgets below can produce # (install 3x10 + publish 2x45 = 120, plus ~25 for checkout/build/verify), or @@ -292,6 +345,14 @@ jobs: # sshd's job for a standard user on a Windows SSH host. ORCA_REQUIRE_RELAY_NATIVE_ADDONS: x64,arm64 + # After the app build so nothing that cleans out/ can drop it; electron-builder ships it. + - name: Download the orcad deployment template + if: needs.orcad-template-support.outputs.ships == 'true' + uses: actions/download-artifact@v8 + with: + name: orcad-template + path: out/orcad-template + # Why the token is minted here and not at the top: installation tokens live # one hour, everything before this point writes nothing, and the notary round # trip inside the publish step can be tens of minutes. Minting after the build @@ -366,6 +427,8 @@ jobs: GH_TOKEN: ${{ steps.app_token.outputs.token }} ORCA_ADHOC_BUILD_VERSION: ${{ steps.adhoc.outputs.version }} ORCA_BUILD_COMMIT: ${{ steps.adhoc.outputs.commit }} + # beforePack and afterPack fail the package when the template is absent. + ORCA_REQUIRE_ORCAD_TEMPLATE: ${{ needs.orcad-template-support.outputs.ships == 'true' && '1' || '' }} CSC_LINK: ${{ secrets.MAC_CERTS }} CSC_KEY_PASSWORD: ${{ secrets.MAC_CERTS_PASSWORD }} # Why all three: electron-builder's notarize step authenticates to the @@ -514,3 +577,4 @@ jobs: tag: ${{ needs.build-adhoc-mac.outputs.tag }} ref: ${{ needs.build-adhoc-mac.outputs.head_sha }} version: ${{ needs.build-adhoc-mac.outputs.version }} + orcad_template: ${{ needs.build-adhoc-mac.outputs.ships_orcad_template == 'true' }} diff --git a/.github/workflows/dev-channel-win-build.yml b/.github/workflows/dev-channel-win-build.yml index 3f8e162e073..04e3b84ff7f 100644 --- a/.github/workflows/dev-channel-win-build.yml +++ b/.github/workflows/dev-channel-win-build.yml @@ -58,6 +58,11 @@ on: description: Version to package, without the leading v required: true type: string + orcad_template: + description: Ship the orcad-template artifact the calling run built (adhoc does; hourly and daily do not yet) + required: false + type: boolean + default: false workflow_dispatch: inputs: channel: @@ -264,6 +269,14 @@ jobs: # is correct for unvetted artifacts. Same as the mac dev channels. ORCA_DIAGNOSTICS_TOKEN_URL: https://www.onorca.dev/diagnostics/token + # After the app build so nothing that cleans out/ can drop it; electron-builder ships it. + - name: Download the orcad deployment template + if: inputs.orcad_template + uses: actions/download-artifact@v8 + with: + name: orcad-template + path: out/orcad-template + # Why the token is minted here and not at the top: installation tokens live # one hour and nothing before this point writes anything. - name: Mint dev channel repo token @@ -301,6 +314,8 @@ jobs: env: GH_TOKEN: ${{ steps.app_token.outputs.token }} ORCA_BUILD_COMMIT: ${{ inputs.ref }} + # beforePack and afterPack fail the package when the template is absent. + ORCA_REQUIRE_ORCAD_TEMPLATE: ${{ inputs.orcad_template && '1' || '' }} # Why: electron-publish refuses to upload into a release published more # than two hours ago (gitHubPublisher.getOrCreateRelease). The mac leg # publishes the draft live as soon as *it* finishes, so a slow notary