Skip to content

release(main): carry native sidecar packaging repair - #5532

Merged
lidge-jun merged 1 commit into
mainfrom
codex/main-native-sidecar-packaging
Sep 22, 2026
Merged

lidge-jun merged 1 commit into
mainfrom
codex/main-native-sidecar-packaging

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

  • Repair two desktop packaging failures observed in preview dry-run 35718064920: linuxdeploy rewrites the compiled Bun sidecar before its GTK pass fails ldd, and the universal macOS bundle lacks its universal sidecar filename.
  • Preserve only the exact, byte-identical Linux ocx sidecar during RPATH rewriting, delegate other ELF operations normally, and require extracted AppImage CLI byte equality plus a bounded version probe before collecting assets. Combine both prepared macOS CLI slices with lipo and require both architectures.
  • This is an owner-authorized maintainer main promotion of dev PR fix(desktop): preserve packaged CLI and assemble universal sidecar #5530 (a5e8047). The channel version stays unchanged. Integration is explicitly authorized immediately without waiting for CI. This is not a CI-pass claim; publication still requires the canonical checks, asset verification and signatures.

Verification

  • Hosted failure evidence: Linux job 106714839327, macOS job 106714839349. Windows MSI and all five standalone packages passed in the same dry-run.
  • Independent Sol source and security review covers the narrow wrapper, platform conditions, artifact checks and unchanged signing/publication boundaries.
  • Added workflow wiring assertions. The next hosted release dry-run exercises the actual packaged binaries.
  • Local tests, typechecks, builds and runtime probes: NOT RUN, as explicitly required by the owner. Commit and push use --no-verify.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 22, 2026 11:13
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@lidge-jun
lidge-jun merged commit 5aa92e9 into main Sep 22, 2026
9 of 17 checks passed
@lidge-jun
lidge-jun deleted the codex/main-native-sidecar-packaging branch September 22, 2026 11:13
@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0df09af4-1f26-45fb-b51d-0ab4f449841a

📥 Commits

Reviewing files that changed from the base of the PR and between 891674c and 53e6eb5.

📒 Files selected for processing (5)
  • .github/workflows/release.yml
  • desktop/scripts/appimage-patchelf.py
  • desktop/scripts/verify-linux-sidecar.sh
  • structure/desktop-shell.md
  • tests/ci-workflows/release-desktop-scripts.test.ts
 __________________________________________________
< Are you a real coder or just a pretty committer? >
 --------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

lidge-jun added a commit that referenced this pull request Oct 7, 2026
…6711)

* release: v2.33.0-preview.20260825

* release: v2.34.0-preview.20260827

* release: v2.36.0-preview.20260829

* fix(release): pass the bump job's permissions through the reusable-workflow call (#3262)

Both v2.40.0 release dispatches (33615174183 preview, 33615177849 main) died
at startup_failure: a workflow_call cannot grant its callee more than the
calling job holds, and dev-version-bump.yml's job declares contents+pull-
requests write. #3129 wired the call but never dispatched a release, so this
is its first live run. The caller job now declares exactly the callee's two
permissions; no other job in release.yml gains anything.

Co-authored-by: jun <jun@lidge.dev>
(cherry picked from commit 7ce0ba5)

* release: set preview channel version 2.48.0-preview.20260908

* release: set main channel version 2.48.0

* chore(release): promote 2.55.0-preview.20260914 to preview

Promotes the dev product snapshot 62f0222 to the preview train.

The 2.55.0 line carries the #4546 cost-guard work: one send budget per logical request with a
shared final-recovery reserve, zero-is-zero refusals with a typed error rather than a synthetic
502, compact and the Kiro inner retries admitted against that budget, a finite send ceiling per
root workflow with an interactive reserve a fan-out cannot take, and a healthy detour promoted on
transient-hold expiry instead of released cold.

The previous preview tip 2.54.0-preview.20260914 is already tagged and published and is outranked
by v2.54.0, so it could not be re-released; this is a new candidate rather than a re-cut.

* chore(release): promote the verified 2.55.0 product tree to main

Same product tree as preview 7bdd1b2 / 2.55.0-preview.20260914, which published successfully with its registry smoke green. Only package.json version differs.

* ci(release): expose Linux bundler diagnostics for stable artifacts

* fix(release): prepare stable platform bundles

* fix(desktop): carry native sidecar packaging repair to main (#5532)

* chore(ci): refresh main release verification (#5534)

* fix(release): carry lipo argument fix to main (#5537)

* fix(release): carry checksum and signature repair to main (#5546)

* fix(release): carry Windows checksum record support to main (#5552)

* fix(release): publish the GitHub release only after its verified assets attach (#5555) (#5558)

GitHub freezes a release when it is published, so the attach step's upload
came back HTTP 422 "Cannot upload assets to an immutable release". Every
release from v2.55.0 to v2.60.0 therefore shipped with zero assets and the
desktop updater had nothing to download.

Create the release as a draft and flip it to published in attach-release,
after the verified bundle is uploaded. Release notes still come from the
validated notes file written at creation.

* release: prepare 2.63.0 version metadata (#5612)

* release: prepare 2.69.0 version metadata

* fix(release): sign the packaged macOS keyring addons before notarization (#6271)

* fix(release): sign the packaged macOS keyring addons before notarization

Notarization rejected the 2.73.0 preview app: Resources/keyring/*.node, bundled
since #6161, were unsigned or ad-hoc and had no secure timestamp, and Tauri does
not sign files under Resources. Sign each darwin addon in place with the
Developer ID identity, hardened runtime and timestamp after the certificate
import and before tauri build, verify the result, and fail a real release that
lacks signing material.

* fix(release): match keyring signature fields without a pipe

(cherry picked from commit 11782ee)

* chore(release): 2.74.0

* fix: demote developer to user for OrcaSAQ-2 leading-system template

The OrcaSAQ-2-Cyber-27B GGUF pins the same chat-template contract as
Qwen3.8-27B — a non-leading `system` raises and `developer` is
unsupported — so translated requests carrying a mid-conversation
developer reminder failed upstream with a 500 template error. Widen
the leading-system matcher to the OrcaSAQ family (org prefix optional,
quant tag optional) so the reminder keeps its slot as `user`.

---------

Co-authored-by: JUN <bitkyc08@gmail.com>
Co-authored-by: jun <jun@junui-MacBookPro.local>
Co-authored-by: jun <jun@lidge.dev>
Co-authored-by: lidge-jun <243035832+lidge-jun@users.noreply.github.com>
Co-authored-by: t <a@b.com>
Co-authored-by: JUN <jun@lidgeai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant