fix(release): harden cross-platform offline installers (#131)

This commit is contained in:
laodouuu
2026-07-30 16:02:25 +08:00
committed by GitHub
parent 081fe2d172
commit de6380f278
14 changed files with 786 additions and 131 deletions
+7
View File
@@ -45,6 +45,9 @@ jobs:
- name: Unit tests (vitest)
run: pnpm test
- name: Offline bundle and POSIX installer tests
run: sh scripts/test-offline-bundles.sh
# The secret is exposed only in this step (step-level env); earlier steps and third-party actions can't see it.
# The secrets context can't be used in if expressions, so skip inside the shell when it's absent (e.g. forks).
- name: E2E (live LLM via DeepSeek)
@@ -108,3 +111,7 @@ jobs:
}
}
if ($failed) { exit 1 }
- name: Windows offline installer tests
shell: pwsh
run: ./scripts/test-offline-install.ps1
+20 -5
View File
@@ -110,12 +110,13 @@ jobs:
run: pnpm build
# lib/: the CLI and its production deps (including workspace core/server/skills, all build outputs);
# pnpm 10's deploy needs --legacy (this repo doesn't enable inject-workspace-packages).
# Use pnpm's current deploy implementation with injected workspace packages; the hoisted target layout
# avoids deeply nested .pnpm/node_modules paths that exceed Windows PowerShell 5.1's legacy MAX_PATH limit.
# bin/penguin launcher: resolve its own real path (following symlinks) -> default PENGUIN_WEB_DIST to
# the sibling web/ -> use the bundled runtime (node/bin/node) if present, else fall back to system node.
- name: Assemble penguin/ (lib + web + bin)
run: |
pnpm --filter @prismshadow/penguin-cli --prod deploy --legacy "$PWD/out/penguin/lib"
pnpm --config.node-linker=hoisted --filter @prismshadow/penguin-cli --prod deploy "$PWD/out/penguin/lib"
cp -r packages/web/dist out/penguin/web
mkdir -p out/penguin/bin
cat > out/penguin/bin/penguin <<'EOF'
@@ -155,10 +156,12 @@ jobs:
fi
mv "/tmp/node-runtime/$name" out/penguin/node
rm -rf out/penguin/node/share/doc out/penguin/node/share/man
printf '{"schemaVersion":1,"target":"%s"}\n' "$os-$arch" > out/penguin/package-manifest.json
tar -czf "dist-artifacts/penguin-$os-$arch.tar.gz" -C out penguin
done
# Universal package: no bundled runtime, requires system Node >= 24.
rm -rf out/penguin/node
printf '{"schemaVersion":1,"target":"universal"}\n' > out/penguin/package-manifest.json
tar -czf dist-artifacts/penguin-universal.tar.gz -C out penguin
# Windows package: same lib/ + web/ layout, but a .zip (the native format), the official
@@ -192,6 +195,7 @@ jobs:
test -f out/penguin/git/usr/bin/sh.exe
test -f out/penguin/git/etc/profile
rm -f out/penguin/bin/penguin
printf '{"schemaVersion":1,"target":"win32-x64"}\n' > out/penguin/package-manifest.json
cat > out/penguin/bin/penguin.cmd <<'EOF'
@echo off
setlocal
@@ -221,15 +225,26 @@ jobs:
sed -i 's/$/\r/' out/penguin/bin/penguin.ps1
(cd out && zip -qr ../dist-artifacts/penguin-win32-x64.zip penguin)
# SHA256SUMS summary + a same-named .sha256 per artifact (install.sh / install.ps1 verify against the latter).
- name: Generate SHA256 checksums
# Per-payload checksums are included inside the offline bundles and are also consumed by
# the online install.sh / install.ps1 downloads.
- name: Generate payload SHA256 checksums
run: |
cd dist-artifacts
sha256sum *.tar.gz *.zip > SHA256SUMS
for f in *.tar.gz *.zip; do
sha256sum "$f" > "$f.sha256"
done
# Each offline bundle contains exactly one platform payload, its checksum and the native installer.
# Users extract once, then run install.sh (Linux/macOS) or double-click install.cmd (Windows).
- name: Package offline installer bundles
run: sh scripts/package-offline-bundles.sh dist-artifacts
# Summary covers both raw program archives and their offline installer wrappers.
- name: Generate SHA256SUMS
run: |
cd dist-artifacts
sha256sum *.tar.gz *.zip > SHA256SUMS
# Release notes come from changelog/<version>/RELEASE.md, written during release preparation and
# committed BEFORE the tag (the release job runs on the tag's checkout, so a file added afterwards
# is invisible here). Present and non-empty -> published verbatim as the body; absent -> GitHub