perf(ci): compile release JavaScript once for all packaging hosts (#25828)

* perf(ci): share release JavaScript across packaging hosts

* fix(ci): verify the projected web entry in release archives

* fix(ci): use the Windows system archive tool for release bundles

* test(ci): retain stylesheet evidence in release build comparisons

* test(ci): verify release parity across native color rounding

* test(ci): normalize manifest asset references without changing import order

* test(ci): compare portable outputs across Windows text and color formatting

* test(ci): preserve module identity across dependent asset hashes

* fix(ci): keep SVG build inputs identical across release hosts

* fix(ci): stabilize compiler inputs and projected web bindings

* fix(ci): retain vendor minification in projected web output

* test(ci): normalize platform-specific pnpm manifest source paths

* fix(packaging): exclude shared build staging from application files

* test: align thinking-state fixtures with the current source shape

* test(mobile): reuse message fixtures within the line limit
This commit is contained in:
Neil
2026-10-06 13:22:04 -07:00
committed by GitHub
parent 9e8a3a5c67
commit 83cf7cf5e2
25 changed files with 1268 additions and 35 deletions
+35 -14
View File
@@ -1212,12 +1212,25 @@ jobs:
with:
ref: refs/tags/${{ needs.cut.outputs.tag }}
# Compilation can overlap the release gates; signing remains behind release-preflight.
release-javascript:
needs: cut
if: needs.cut.outputs.should_release == 'true'
permissions:
contents: read
uses: ./.github/workflows/release-javascript.yml
with:
ref: refs/tags/${{ needs.cut.outputs.tag }}
secrets:
ORCA_POSTHOG_WRITE_KEY: ${{ secrets.ORCA_POSTHOG_WRITE_KEY }}
build:
needs:
- cut
- create-release
- orcad-template
- release-preflight
- release-javascript
- relay-windows-process-tree
# Why not the implicit success(): a tag without the orcad template skips that job on purpose.
if: >-
@@ -1226,6 +1239,7 @@ jobs:
needs.cut.outputs.should_release == 'true' &&
needs.create-release.result == 'success' &&
needs.release-preflight.result == 'success' &&
needs.release-javascript.result == 'success' &&
needs.relay-windows-process-tree.result == 'success' &&
(needs.orcad-template.result == 'success' ||
(needs.orcad-template.result == 'skipped' && needs.cut.outputs.ships_orcad_template == 'false'))
@@ -1460,26 +1474,30 @@ jobs:
}
cargo --version
# Why ORCA_POSTHOG_WRITE_KEY here: this is the only build that
# produces a published binary, so this is the only place the secret
# needs to be in scope. The key is a PostHog *project* API key, not
# a server secret — it ships in every official binary's app.asar
# and is therefore extractable from any release. We still keep it
# in GitHub Actions secrets so the literal stays out of the repo
# (and out of fork CI runs / log scrapers / casual greps).
# Why ORCA_BUILD_IDENTITY here (not in env at the job level): the
# value comes from the per-tag classification above and electron-vite
# reads it from `process.env` during `pnpm build:release` only.
# Why ORCA_DIAGNOSTICS_TOKEN_URL here: official builds pin crash
# diagnostic uploads to Orca's endpoint at compile time, matching the
# telemetry gate's "official binary only" behavior.
# Consumers verify the same official build configuration before restoring the bundle.
- name: Download release JavaScript
if: needs.release-javascript.outputs.supported == 'true'
uses: actions/download-artifact@v8
with:
name: release-javascript
path: .build/release-javascript
- name: Build app
run: pnpm build:release
shell: bash
run: |
if [ "$SHARED_JAVASCRIPT" = true ]; then
node config/scripts/release-javascript-artifact.mjs restore
pnpm run build:release:host
else
pnpm run build:release
fi
env:
# Why: Vite's web build crossed Node's default old-space ceiling on
# the macOS release runner, leaving v1.4.2-rc.8 as an incomplete draft.
NODE_OPTIONS: --max-old-space-size=4096
ORCA_BUILD_IDENTITY: ${{ steps.tag-classify.outputs.identity }}
SHARED_JAVASCRIPT: ${{ needs.release-javascript.outputs.supported }}
ORCA_RELEASE_JAVASCRIPT_SOURCE_SHA: ${{ needs.release-javascript.outputs.source_sha }}
ORCA_DIAGNOSTICS_TOKEN_URL: https://www.onorca.dev/diagnostics/token
ORCA_POSTHOG_WRITE_KEY: ${{ secrets.ORCA_POSTHOG_WRITE_KEY }}
# Fail the release rather than ship a relay that cannot launch outside
@@ -2330,6 +2348,7 @@ jobs:
- create-release
- orcad-template
- release-preflight
- release-javascript
# release-mac-build.yml downloads the relay addons from this run.
- relay-windows-process-tree
# Why not the implicit success(): a tag without the orcad template skips that job on purpose.
@@ -2339,6 +2358,7 @@ jobs:
needs.cut.outputs.should_release == 'true' &&
needs.create-release.result == 'success' &&
needs.release-preflight.result == 'success' &&
needs.release-javascript.result == 'success' &&
needs.relay-windows-process-tree.result == 'success' &&
(needs.orcad-template.result == 'success' ||
(needs.orcad-template.result == 'skipped' && needs.cut.outputs.ships_orcad_template == 'false'))
@@ -2364,6 +2384,7 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
RELEASE_MAC_BUILD_REF: ${{ github.ref_name }}
RELEASE_MAC_BUILD_RELEASE_RUN_ID: ${{ github.run_id }}
RELEASE_MAC_BUILD_JAVASCRIPT_SOURCE_SHA: ${{ needs.release-javascript.outputs.supported == 'true' && needs.release-javascript.outputs.source_sha || '' }}
RELEASE_MAC_BUILD_TAG: ${{ needs.cut.outputs.tag }}
RELEASE_MAC_BUILD_WORKFLOW: release-mac-build.yml
@@ -0,0 +1,120 @@
name: Release JavaScript comparison
on:
pull_request:
paths: ['.github/workflows/release-javascript-benchmark.yml']
workflow_dispatch:
permissions:
contents: read
concurrency:
group: release-javascript-comparison-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
env:
ORCA_BACKGROUND_LAUNCH: '1'
ORCA_DIAGNOSTICS_TOKEN_URL: https://www.onorca.dev/diagnostics/token
ORCA_POSTHOG_WRITE_KEY: ci-build-comparison
NODE_OPTIONS: --max-old-space-size=4096
jobs:
bundle:
uses: ./.github/workflows/release-javascript.yml
with:
ref: ${{ github.sha }}
secrets:
ORCA_POSTHOG_WRITE_KEY: ci-build-comparison
measure:
needs: bundle
name: ${{ matrix.mode }} ${{ matrix.host.platform }} ${{ matrix.host.arch }}
runs-on: ${{ matrix.host.os }}
timeout-minutes: 30
strategy:
fail-fast: false
max-parallel: 8
matrix:
mode: [baseline, shared]
host:
- os: ubuntu-latest
platform: linux
arch: x64
- os: ubuntu-24.04-arm
platform: linux
arch: arm64
- os: windows-2022
platform: win32
arch: x64
- os: macos-15
platform: darwin
arch: arm64
steps:
- uses: actions/checkout@v6
with:
ref: ${{ needs.bundle.outputs.source_sha }}
persist-credentials: false
- uses: ./.github/actions/install-node-dependencies
with:
native-runtime: node
persist-native-cache: 'false'
- uses: ./.github/actions/install-mobile-dependencies
- name: Install Linux provider dependencies
if: runner.os == 'Linux'
run: sudo apt-get update && sudo apt-get install -y python3-gi gir1.2-atspi-2.0 at-spi2-core xclip xdotool
- name: Resolve build identity
shell: bash
run: |
RELEASE_TAG="v$(node -p 'require("./package.json").version')"
export RELEASE_TAG
echo "ORCA_BUILD_IDENTITY=$(node config/scripts/release-javascript-artifact.mjs identity)" >> "$GITHUB_ENV"
- name: Download shared JavaScript
if: matrix.mode == 'shared'
uses: actions/download-artifact@v8
with:
name: release-javascript
path: .build/release-javascript
- name: Measure release build
shell: bash
env:
MEASUREMENT_MODE: ${{ matrix.mode }}
ORCA_RELEASE_JAVASCRIPT_SOURCE_SHA: ${{ needs.bundle.outputs.source_sha }}
run: node config/scripts/release-javascript-benchmark.mjs "$MEASUREMENT_MODE"
- uses: actions/upload-artifact@v7
with:
name: release-javascript-measurement-${{ matrix.mode }}-${{ matrix.host.platform }}-${{ matrix.host.arch }}
path: .build/release-javascript-measurements/
retention-days: 7
comparison:
needs: [bundle, measure]
runs-on: ubuntu-slim
permissions:
contents: read
actions: read
steps:
- uses: actions/checkout@v6
with:
ref: ${{ needs.bundle.outputs.source_sha }}
persist-credentials: false
- uses: actions/setup-node@v6
with:
node-version-file: package.json
- uses: ./.github/actions/install-node-dependencies
- uses: actions/download-artifact@v8
with:
pattern: release-javascript-measurement-*
path: .build/release-javascript-measurements
- name: Compare build and transfer timings
env:
GH_TOKEN: ${{ github.token }}
run: |
gh api "repos/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID/jobs?per_page=100" > .build/release-javascript-measurements/jobs.json
node config/scripts/release-javascript-benchmark.mjs summary
cat .build/release-javascript-measurements/comparison.md >> "$GITHUB_STEP_SUMMARY"
- uses: actions/upload-artifact@v7
if: always()
with:
name: release-javascript-comparison
path: .build/release-javascript-measurements/comparison.md
retention-days: 30
+79
View File
@@ -0,0 +1,79 @@
name: Release JavaScript bundle
on:
workflow_call:
inputs:
ref:
required: true
type: string
outputs:
supported:
value: ${{ jobs.bundle.outputs.supported }}
source_sha:
value: ${{ jobs.bundle.outputs.source_sha }}
secrets:
ORCA_POSTHOG_WRITE_KEY:
required: true
permissions:
contents: read
env:
ORCA_BACKGROUND_LAUNCH: '1'
jobs:
bundle:
runs-on: ubuntu-latest
timeout-minutes: 20
outputs:
supported: ${{ steps.source.outputs.supported }}
source_sha: ${{ steps.source.outputs.sha }}
steps:
- uses: actions/checkout@v6
with:
ref: ${{ inputs.ref }}
persist-credentials: false
# Older release refs retain their original per-platform build commands.
- name: Resolve bundle source and support
id: source
shell: bash
run: |
echo "sha=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT"
node -e 'const p = require("./package.json"); console.log("supported=" + Boolean(p.scripts["build:release:javascript"] && p.scripts["build:release:host"]))' >> "$GITHUB_OUTPUT"
- uses: ./.github/actions/install-node-dependencies
if: steps.source.outputs.supported == 'true'
with:
native-runtime: node
- uses: ./.github/actions/install-mobile-dependencies
if: steps.source.outputs.supported == 'true'
- name: Resolve release build identity
id: identity
if: steps.source.outputs.supported == 'true'
run: |
RELEASE_TAG="v$(node -p 'require("./package.json").version')"
export RELEASE_TAG
echo "value=$(node config/scripts/release-javascript-artifact.mjs identity)" >> "$GITHUB_OUTPUT"
- name: Build and archive release JavaScript
if: steps.source.outputs.supported == 'true'
env:
NODE_OPTIONS: --max-old-space-size=4096
ORCA_BUILD_IDENTITY: ${{ steps.identity.outputs.value }}
ORCA_DIAGNOSTICS_TOKEN_URL: https://www.onorca.dev/diagnostics/token
ORCA_POSTHOG_WRITE_KEY: ${{ secrets.ORCA_POSTHOG_WRITE_KEY }}
run: |
pnpm run build:release:javascript
node config/scripts/release-javascript-artifact.mjs pack
- uses: actions/upload-artifact@v7
if: steps.source.outputs.supported == 'true'
with:
name: release-javascript
path: .build/release-javascript/
compression-level: 0
retention-days: 7
if-no-files-found: error
+22 -1
View File
@@ -13,6 +13,11 @@ on:
description: release-cut workflow run that requested this build
required: true
type: string
javascript_source_sha:
description: Commit of the shared JavaScript artifact; empty keeps the legacy build
required: false
default: ''
type: string
permissions:
# actions: read downloads the orcad template the parent release-cut run built.
@@ -143,13 +148,29 @@ jobs:
run-id: ${{ inputs.release_run_id }}
github-token: ${{ github.token }}
- name: Download release JavaScript from the release run
if: inputs.javascript_source_sha != ''
uses: actions/download-artifact@v8
with:
name: release-javascript
path: .build/release-javascript
run-id: ${{ inputs.release_run_id }}
github-token: ${{ github.token }}
- name: Build app
run: pnpm build:release
run: |
if [ -n "$ORCA_RELEASE_JAVASCRIPT_SOURCE_SHA" ]; then
node config/scripts/release-javascript-artifact.mjs restore
pnpm run build:release:host
else
pnpm run build:release
fi
env:
# Why: Vite's web build crossed Node's default old-space ceiling on
# the macOS release runner, leaving v1.4.2-rc.8 as an incomplete draft.
NODE_OPTIONS: --max-old-space-size=4096
ORCA_BUILD_IDENTITY: ${{ steps.tag-classify.outputs.identity }}
ORCA_RELEASE_JAVASCRIPT_SOURCE_SHA: ${{ inputs.javascript_source_sha }}
ORCA_DIAGNOSTICS_TOKEN_URL: https://www.onorca.dev/diagnostics/token
ORCA_POSTHOG_WRITE_KEY: ${{ secrets.ORCA_POSTHOG_WRITE_KEY }}
# Fail the release rather than ship a relay that cannot launch outside