Repository navigation
187 lines (181 loc) · 9.57 KB
/
Copy pathci.yml
File metadata and controls
187 lines (181 loc) · 9.57 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
name: CI
on:
pull_request:
push:
branches:
- main
permissions:
contents: read
jobs:
dependency-audit:
name: Dependency audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: 24
cache: npm
cache-dependency-path: package-lock.json
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: 1.97.1
- run: npm ci
- run: npm audit --audit-level=high
- name: Install pinned cargo-audit
run: cargo install cargo-audit --version 0.22.2 --locked
- name: Audit Rust lockfiles
run: |
cargo audit --file src-tauri/Cargo.lock
cargo audit --file src-tauri/startup-launcher/Cargo.lock
cargo audit --file tools/updater-signature-verifier/Cargo.lock
frontend:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
- name: Reject retired product identity
run: |
retired_identity="pre""view"
if git grep -I -n -i "$retired_identity" -- ':!src-tauri/Cargo.lock' ':!package-lock.json'; then
exit 1
fi
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: 24
cache: npm
cache-dependency-path: package-lock.json
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: 1.97.1
- run: npm ci
- name: Validate release updater configuration
shell: bash
run: |
set -euo pipefail
npx tauri signer generate --ci --password validation-only --write-keys "$RUNNER_TEMP/updater.key"
SWITCHIFY_UPDATER_PUBLIC_KEY="$(cat "$RUNNER_TEMP/updater.key.pub")" node scripts/render-updater-config.mjs "$RUNNER_TEMP/tauri.release.json"
node -e 'const c=require(process.argv[1]); if (!c.bundle.createUpdaterArtifacts || c.plugins.updater.endpoints.length !== 1 || !c.plugins.updater.pubkey) process.exit(1)' "$RUNNER_TEMP/tauri.release.json"
cargo build --locked --manifest-path tools/updater-signature-verifier/Cargo.toml
verifier="$GITHUB_WORKSPACE/tools/updater-signature-verifier/target/debug/switchify-updater-signature-verifier"
mkdir -p "$RUNNER_TEMP/artifacts/macos-release" "$RUNNER_TEMP/artifacts/windows-release"
mac_artifact="$RUNNER_TEMP/artifacts/macos-release/Switchify.PC.app.tar.gz"
windows_artifact="$RUNNER_TEMP/artifacts/windows-release/Switchify.PC_1.0.0_x64-setup.exe"
node -e 'require("fs").writeFileSync(process.argv[1], require("zlib").gzipSync("archive fixture"))' "$mac_artifact"
node -e 'const b=Buffer.alloc(128); b.write("MZ"); b.writeUInt32LE(64, 0x3c); b.write("PE\0\0", 64); require("fs").writeFileSync(process.argv[1], b)' "$windows_artifact"
npx tauri signer sign --private-key-path "$RUNNER_TEMP/updater.key" --password validation-only "$mac_artifact"
npx tauri signer sign --private-key-path "$RUNNER_TEMP/updater.key" --password validation-only "$windows_artifact"
export SWITCHIFY_UPDATER_PUBLIC_KEY="$(cat "$RUNNER_TEMP/updater.key.pub")"
node scripts/create-update-feed.mjs "$RUNNER_TEMP/artifacts" 1.0.0-beta.1 v1.0.0-beta.1 "$RUNNER_TEMP/latest.json" "$verifier"
node -e 'const f=require(process.argv[1]); if (!f.platforms["darwin-aarch64"].signature || !f.platforms["windows-x86_64"].signature) process.exit(1)' "$RUNNER_TEMP/latest.json"
if node scripts/create-update-feed.mjs "$RUNNER_TEMP/artifacts" 1.0.0-beta.1 v1.0.0-beta.2 "$RUNNER_TEMP/invalid.json" "$verifier"; then
echo 'Mismatched update tag was accepted.' >&2
exit 1
fi
printf 'not-a-tauri-signature' > "$mac_artifact.sig"
if node scripts/create-update-feed.mjs "$RUNNER_TEMP/artifacts" 1.0.0-beta.1 v1.0.0-beta.1 "$RUNNER_TEMP/invalid.json" "$verifier"; then
echo 'Invalid updater signature was accepted.' >&2
exit 1
fi
printf 'not an updater archive' > "$mac_artifact"
npx tauri signer sign --private-key-path "$RUNNER_TEMP/updater.key" --password validation-only "$mac_artifact"
if node scripts/create-update-feed.mjs "$RUNNER_TEMP/artifacts" 1.0.0-beta.1 v1.0.0-beta.1 "$RUNNER_TEMP/invalid.json" "$verifier"; then
echo 'Wrong-format updater payload was accepted.' >&2
exit 1
fi
- run: npm run lint
- run: npm test
- run: npm run build
native:
strategy:
fail-fast: false
matrix:
include:
- os: windows-latest
bundles: nsis
- os: macos-14
bundles: app,dmg
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: 24
cache: npm
cache-dependency-path: package-lock.json
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: 1.97.1
components: rustfmt, clippy
- run: npm ci
- name: Fetch prediction model and released companion workers
run: npm run prediction-model
- name: Diagnose released ARM worker
if: runner.os == 'macOS'
env:
SWITCHIFY_BENCHMARK_MODEL: src-tauri/resources/prediction-model/english.sqlite
SWITCHIFY_BENCHMARK_WORKER: src-tauri/binaries/switchify-smol-worker-aarch64-apple-darwin
run: python3 scripts/probe-neural-worker.py
- run: cargo fmt --manifest-path src-tauri/Cargo.toml --check
- run: cargo clippy --locked --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings
- run: cargo test --locked --manifest-path src-tauri/Cargo.toml
- run: cargo fmt --manifest-path tools/updater-signature-verifier/Cargo.toml --check
- run: cargo clippy --locked --manifest-path tools/updater-signature-verifier/Cargo.toml --all-targets -- -D warnings
- run: cargo test --locked --manifest-path tools/updater-signature-verifier/Cargo.toml
- if: runner.os == 'Windows'
run: cargo fmt --manifest-path src-tauri/startup-launcher/Cargo.toml --check
- if: runner.os == 'Windows'
run: cargo clippy --locked --manifest-path src-tauri/startup-launcher/Cargo.toml --all-targets -- -D warnings
- if: runner.os == 'Windows'
run: cargo test --locked --manifest-path src-tauri/startup-launcher/Cargo.toml
- if: runner.os == 'macOS'
run: npm run tauri build -- --bundles ${{ matrix.bundles }} --no-sign
- if: runner.os == 'Windows'
run: pwsh ./scripts/Build-WindowsUiAccess.ps1 -SkipSign
- if: runner.os == 'Windows'
run: |
$env:SWITCHIFY_ALLOW_UNSIGNED_UIACCESS_PACKAGE = '1'
pwsh ./scripts/Verify-WindowsUiAccessPackage.ps1
- name: Verify macOS packaged prediction resources
if: runner.os == 'macOS'
shell: bash
run: |
model=$(node scripts/check-packaged-prediction.mjs src-tauri/target/release/bundle/macos)
echo "SWITCHIFY_BENCHMARK_MODEL=$model" >> "$GITHUB_ENV"
echo "SWITCHIFY_BENCHMARK_WORKER=$(node scripts/check-packaged-prediction.mjs src-tauri/target/release/bundle/macos --worker)" >> "$GITHUB_ENV"
- name: Verify Windows packaged prediction resources
if: runner.os == 'Windows'
shell: pwsh
run: |
$installer = Get-ChildItem src-tauri/target/release/bundle/nsis/*.exe | Select-Object -First 1
$unpacked = Join-Path $env:RUNNER_TEMP 'prediction-package'
& 7z x $installer.FullName "-o$unpacked" -y | Out-Null
if ($LASTEXITCODE -ne 0) { throw 'Could not extract the installer.' }
$model = node scripts/check-packaged-prediction.mjs $unpacked
if ($LASTEXITCODE -ne 0) { throw 'Packaged prediction resources failed verification.' }
"SWITCHIFY_BENCHMARK_MODEL=$model" >> $env:GITHUB_ENV
$worker = node scripts/check-packaged-prediction.mjs $unpacked --worker
if ($LASTEXITCODE -ne 0) { throw 'Packaged workers failed verification.' }
"SWITCHIFY_BENCHMARK_WORKER=$worker" >> $env:GITHUB_ENV
- name: Measure packaged prediction without desktop input
env:
SWITCHIFY_BENCHMARK_REPORT: prediction-benchmark.json
run: cargo test --release --lib --locked --manifest-path src-tauri/Cargo.toml bundled_prediction_benchmark -- --ignored --nocapture --test-threads=1
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: '3.13'
- name: Measure packaged neural integration without desktop input
run: |
python -m pip install psutil==7.0.0
python scripts/measure-neural.py --build --output src-tauri/neural-benchmark.json
- name: Diagnose packaged worker after benchmark failure
if: failure() && env.SWITCHIFY_BENCHMARK_WORKER != ''
run: python scripts/probe-neural-worker.py
- name: Upload prediction measurements
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: prediction-benchmark-${{ runner.os }}
path: |
src-tauri/prediction-benchmark.json
src-tauri/neural-benchmark.json
if-no-files-found: error