Skip to content

ci/release: remove macOS entirely (zero macOS) - #60

Merged
ryanleecode merged 2 commits into
devfrom
chore/remove-macos
Oct 7, 2026
Merged

ryanleecode merged 2 commits into
devfrom
chore/remove-macos

Conversation

@ryanleecode

@ryanleecode ryanleecode commented Oct 7, 2026 •

Copy link
Copy Markdown

Summary

Removes macOS completely from CI, release, and distribution. Windows and Linux distribution are unchanged.

CI / tests

  • cross-platform-tests.yml: deleted the macos-tests job (macos-15 / macos-26 / macos-15-intel legs).
  • benchmark-targets.yml: removed the macos / apple-silicon matrix entry.
  • perf.yml / rust.yml: already Linux-only — no change needed.

Release / distribution

  • build-release-artifacts.yml: deleted the build_macos job; removed the MACOS_SIGNING_* / MACOS_NOTARY_* secret declarations from workflow_call; removed macOS artifact download + payload assembly in publish_release_assets; the Homebrew cask is now generated from Linux AppImages only (no .dmg args).
  • scripts/generate-homebrew-cask.sh: rewritten to emit a Linux-only cask (AppImage). The Homebrew tap deploy (deploy-homebrew-tap.yml / release-manual-main.yml deploy_homebrew_tap) is kept and now ships the Linux cask.
  • Deleted macOS-only scripts: scripts/package-macos.sh, scripts/notarize-macos.sh, scripts/macos-cargo-config.sh.
  • docs/macos-release-signing.md: deleted.

Gates kept green

  • deployment-ci.yml: deleted the macos-packaging-smoke job; removed the deleted macOS scripts from the path triggers and the bash -n validation; rewrote the synthetic-cask generation step and its assertions to a Linux-only cask (asserts os linux: / on_linux / AppImage binary and now fails if any macos / .dmg / GitComet.app content appears).

Docs

  • README.md: "Available for Linux and Windows."; Homebrew section retitled "Homebrew (Linux)".
  • CONTRIBUTING.md: dropped the macOS packaging commands and the macOS artifact bullet; cask bullet now says Linux-only.

Out of scope (intentionally untouched)

  • Application source code with cfg(target_os = "macos") in crates/** (per the task, CI/release/distribution/flake only). No tombstone comments added.
  • No flake.nix exists in this repo, so there was nothing to change there.

Now-unused repo secrets (NOT deleted — just no longer referenced)

These macOS signing/notarization secrets are no longer read by any workflow and can be removed by a maintainer at their discretion:

  • MACOS_SIGNING_IDENTITY
  • MACOS_SIGNING_CERT_BASE64
  • MACOS_SIGNING_CERT_PASSWORD
  • MACOS_NOTARY_KEY_ID
  • MACOS_NOTARY_ISSUER_ID
  • MACOS_NOTARY_API_KEY_P8

Verification done locally

  • All 12 workflow files parse as YAML.
  • bash -n on generate-homebrew-cask.sh and the remaining release scripts.
  • Ran generate-homebrew-cask.sh and replayed the full deployment-ci cask gate (Linux-only assertions pass; the new no-macOS negative assert passes).
  • Confirmed the build-release-artifacts.yml job graph has no dangling needs after removing build_macos.

Note (extra finding, not changed)

release-manual-main.yml enforces dispatch from main only, but this repo's trunk is dev (no main branch exists). That predates this change and is unrelated to macOS, so it is left as-is.

Pre-existing failing checks (inherited from dev, NOT caused by this PR)

This PR changes zero Rust/Cargo.* files, so it cannot affect compilation, tests, or the dependency audit. The following checks fail on this PR and were confirmed failing on dev HEAD (2f5b3b7) by dispatching rust.yml and cross-platform-tests.yml against dev:

Check This PR On dev HEAD (proof)
Dependency audit (cargo-audit) fail dev run 37576805274 → cargo-audit
Git backend integration fail dev run 37576805274 → backend integration
Linux Headless Suite (x86_64-linux) fail dev run 37576808134 → x86_64 headless
Linux Headless Suite (Fedora container) fail dev run 37576808134 → Fedora headless
Linux Headless Suite (aarch64-linux) fail dev run 37576808134 → aarch64 headless

Root causes (for maintainers; deliberately left unchanged by this macOS-scoped PR):

  • cargo-audit: rust.yml's audit step builds --ignore flags with "${IGNORES[@]/#/--ignore }", which fuses --ignore RUSTSEC-… into a single argument; a newer cargo-audit rejects it (error: unexpected argument '--ignore RUSTSEC-2025-0052' found).
  • Linux Headless Suite / Git backend integration: pre-existing test-environment failures on dev.

The only gate this PR actually fixed is deployment-ci's "Validate deployment workflow config keys" step (commit 6770e9c5): its microsoft/microsoft-store-apppublisher@v1.4 grep did not match the SHA-pinned @cc9910a8… # v1.4 reference. That step was first exercised by this PR because this is the first change to touch the deployment-ci trigger paths. It now passes.

ryanleecode added 2 commits October 7, 2026 00:59
… Homebrew cask)

Removes all macOS from CI, release, and distribution:
- cross-platform-tests: drop macos-tests job (macos-15/26/intel legs)
- benchmark-targets: drop macos/apple-silicon matrix entry
- build-release-artifacts: drop build_macos job, MACOS_SIGNING_*/MACOS_NOTARY_* secrets, macOS artifact download/assembly, dmg args in cask generation
- release path: Homebrew cask is now Linux-only (AppImage); deploy-homebrew-tap keeps publishing the Linux cask
- deployment-ci: drop macos-packaging-smoke job; drop deleted macOS scripts from path triggers and bash -n; cask gate asserts Linux-only (no macos/.dmg/.app)
- delete scripts/package-macos.sh, scripts/notarize-macos.sh, scripts/macos-cargo-config.sh
- rewrite scripts/generate-homebrew-cask.sh to a Linux-only cask
- delete docs/macos-release-signing.md; drop macOS from README/CONTRIBUTING install+packaging docs

Windows and Linux distribution unchanged. App source cfg(target_os=macos) untouched (out of scope). Repo secrets not deleted; now-unused macOS secrets listed in PR body.
The 'Validate deployment workflow config keys' step asserted the literal microsoft/microsoft-store-apppublisher@v1.4, but deploy-microsoft-store.yml pins that action by commit SHA (@cc9910a8... # v1.4). Match the action reference plus its '# v1.4' version comment so the gate stays green. This step first runs on this PR because it is the first change to touch the deployment-ci trigger paths.
@ryanleecode
ryanleecode merged commit 6a237de into dev Oct 7, 2026
18 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant