Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions .github/workflows/benchmark-targets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,6 @@ jobs:
include:
- name: linux / ubuntu-22.04
runs_on: ubuntu-22.04
- name: macos / apple-silicon
runs_on: macos-latest
- name: windows / x86_64
runs_on: windows-latest
- name: windows / arm64
Expand Down
221 changes: 3 additions & 218 deletions .github/workflows/build-release-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,18 +19,6 @@ on:
secrets:
AZURE_CREDENTIALS:
required: false
MACOS_SIGNING_IDENTITY:
required: false
MACOS_SIGNING_CERT_BASE64:
required: false
MACOS_SIGNING_CERT_PASSWORD:
required: false
MACOS_NOTARY_KEY_ID:
required: false
MACOS_NOTARY_ISSUER_ID:
required: false
MACOS_NOTARY_API_KEY_P8:
required: false
workflow_dispatch:
inputs:
tag:
Expand Down Expand Up @@ -534,201 +522,11 @@ jobs:
if-no-files-found: error
retention-days: 7

build_macos:
name: Build macOS artifacts (${{ matrix.target_platform }})
runs-on: ${{ matrix.runs_on }}
timeout-minutes: 120
needs: prepare
strategy:
fail-fast: false
matrix:
include:
- target_platform: aarch64-darwin
arch: arm64
runs_on: macos-latest
- target_platform: x86_64-darwin
arch: x86_64
runs_on: macos-15-intel
env:
TAG: ${{ needs.prepare.outputs.tag }}
VERSION: ${{ needs.prepare.outputs.version }}
ARCH: ${{ matrix.arch }}
MACOS_SIGNING_IDENTITY: ${{ secrets.MACOS_SIGNING_IDENTITY }}
MACOS_SIGNING_CERT_BASE64: ${{ secrets.MACOS_SIGNING_CERT_BASE64 }}
MACOS_SIGNING_CERT_PASSWORD: ${{ secrets.MACOS_SIGNING_CERT_PASSWORD }}
MACOS_NOTARY_KEY_ID: ${{ secrets.MACOS_NOTARY_KEY_ID }}
MACOS_NOTARY_ISSUER_ID: ${{ secrets.MACOS_NOTARY_ISSUER_ID }}
MACOS_NOTARY_API_KEY_P8: ${{ secrets.MACOS_NOTARY_API_KEY_P8 }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
ref: ${{ needs.prepare.outputs.tag }}
fetch-depth: 0

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable

- name: Cache Rust artifacts
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
with:
cache-targets: false

- name: Determine macOS signing mode
id: macos_signing_mode
run: |
set -euo pipefail

required=(
MACOS_SIGNING_IDENTITY
MACOS_SIGNING_CERT_BASE64
MACOS_SIGNING_CERT_PASSWORD
MACOS_NOTARY_KEY_ID
MACOS_NOTARY_ISSUER_ID
MACOS_NOTARY_API_KEY_P8
)
present=()
missing=()

for name in "${required[@]}"; do
if [ -n "${!name:-}" ]; then
present+=("$name")
else
missing+=("$name")
fi
done

if [ "${#present[@]}" -eq 0 ]; then
echo "enabled=false" >> "$GITHUB_OUTPUT"
echo "macOS signing is not configured; building unsigned macOS artifacts."
exit 0
fi

if [ "${#missing[@]}" -gt 0 ]; then
echo "::error title=Incomplete macOS signing configuration::Missing required secret(s): ${missing[*]}"
echo "::error title=Partial macOS signing configuration::Either provide all macOS signing and notarization secrets or leave them all unset to build unsigned artifacts."
exit 1
fi

echo "enabled=true" >> "$GITHUB_OUTPUT"

- name: Prepare macOS signing and notarization credentials
if: ${{ steps.macos_signing_mode.outputs.enabled == 'true' }}
id: macos_signing
run: |
set -euo pipefail

keychain_path="${RUNNER_TEMP}/gitcomet-signing.keychain-db"
keychain_password="$(openssl rand -hex 24)"
cert_path="${RUNNER_TEMP}/gitcomet-signing-cert.p12"
api_key_path="${RUNNER_TEMP}/AuthKey_${MACOS_NOTARY_KEY_ID}.p8"
default_keychain="$(security default-keychain -d user | tr -d '"' | xargs)"

if base64 --help 2>&1 | grep -q -- '--decode'; then
printf '%s' "$MACOS_SIGNING_CERT_BASE64" | base64 --decode > "$cert_path"
else
printf '%s' "$MACOS_SIGNING_CERT_BASE64" | base64 -D > "$cert_path"
fi

security create-keychain -p "$keychain_password" "$keychain_path"
security set-keychain-settings -lut 21600 "$keychain_path"
security unlock-keychain -p "$keychain_password" "$keychain_path"
security import "$cert_path" \
-k "$keychain_path" \
-P "$MACOS_SIGNING_CERT_PASSWORD" \
-T /usr/bin/codesign \
-T /usr/bin/security
security set-key-partition-list -S apple-tool:,apple: -s -k "$keychain_password" "$keychain_path"
security default-keychain -d user -s "$keychain_path"

security find-identity -v -p codesigning "$keychain_path"

printf '%s' "$MACOS_NOTARY_API_KEY_P8" > "$api_key_path"
chmod 600 "$api_key_path"

echo "keychain_path=$keychain_path" >> "$GITHUB_OUTPUT"
echo "api_key_path=$api_key_path" >> "$GITHUB_OUTPUT"
echo "default_keychain=$default_keychain" >> "$GITHUB_OUTPUT"

- name: Show macOS disk usage before packaging
run: |
set -euo pipefail
df -h || true
for path in target "$HOME/.cargo/registry" "$HOME/.cargo/git" dist "$RUNNER_TEMP"; do
if [ -e "$path" ]; then
du -sh "$path" || true
else
echo "missing: $path"
fi
done

- name: Package macOS release assets
env:
GITCOMET_MACOS_PACKAGE_CLEAN_TARGET: "1"
run: |
set -euo pipefail
package_args=(
--version "${VERSION}"
--arch "${ARCH}"
--release
--out-dir dist
)

if [ "${{ steps.macos_signing_mode.outputs.enabled }}" = "true" ]; then
package_args+=(
--codesign-identity "${MACOS_SIGNING_IDENTITY}"
--codesign-keychain "${{ steps.macos_signing.outputs.keychain_path }}"
)
else
echo "Building unsigned macOS artifacts because signing is not configured."
fi

scripts/package-macos.sh "${package_args[@]}"

- name: Notarize and verify macOS artifacts
if: ${{ steps.macos_signing_mode.outputs.enabled == 'true' }}
run: |
set -euo pipefail
scripts/notarize-macos.sh \
--version "${VERSION}" \
--arch "${ARCH}" \
--out-dir dist \
--api-key "${{ steps.macos_signing.outputs.api_key_path }}" \
--key-id "${MACOS_NOTARY_KEY_ID}" \
--issuer "${MACOS_NOTARY_ISSUER_ID}"

- name: Cleanup macOS signing keychain
if: ${{ always() && steps.macos_signing_mode.outputs.enabled == 'true' }}
env:
KEYCHAIN_PATH: ${{ steps.macos_signing.outputs.keychain_path }}
DEFAULT_KEYCHAIN_PATH: ${{ steps.macos_signing.outputs.default_keychain }}
API_KEY_PATH: ${{ steps.macos_signing.outputs.api_key_path }}
run: |
set -euo pipefail
if [ -n "${DEFAULT_KEYCHAIN_PATH:-}" ]; then
security default-keychain -d user -s "$DEFAULT_KEYCHAIN_PATH" || true
fi
if [ -n "${KEYCHAIN_PATH:-}" ] && [ -f "$KEYCHAIN_PATH" ]; then
security delete-keychain "$KEYCHAIN_PATH" || true
fi
if [ -n "${API_KEY_PATH:-}" ] && [ -f "$API_KEY_PATH" ]; then
rm -f "$API_KEY_PATH"
fi

- name: Upload macOS artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: macos-release-artifacts-${{ matrix.target_platform }}
path: |
dist/*.tar.gz
dist/*.dmg
if-no-files-found: error
retention-days: 7

publish_release_assets:
name: Attach assets and checksums to GitHub release
runs-on: ubuntu-22.04
timeout-minutes: 30
needs: [prepare, build_windows, build_linux, build_macos]
needs: [prepare, build_windows, build_linux]
env:
TAG: ${{ needs.prepare.outputs.tag }}
VERSION: ${{ needs.prepare.outputs.version }}
Expand All @@ -752,19 +550,12 @@ jobs:
path: dist/linux
merge-multiple: true

- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
pattern: macos-release-artifacts-*
path: dist/macos
merge-multiple: true

- name: Assemble release payload
run: |
set -euo pipefail
mkdir -p dist/release
find dist/windows -maxdepth 1 -type f -exec cp -f {} dist/release/ \;
find dist/linux -maxdepth 1 -type f -exec cp -f {} dist/release/ \;
find dist/macos -maxdepth 1 -type f -exec cp -f {} dist/release/ \;
file_count="$(find dist/release -maxdepth 1 -type f | wc -l | tr -d '[:space:]')"
if [ "${file_count}" = "0" ]; then
echo "::error title=No release artifacts::No files were assembled into dist/release."
Expand All @@ -777,23 +568,17 @@ jobs:
set -euo pipefail
linux_arm_appimage="gitcomet-v${VERSION}-linux-arm64.AppImage"
linux_intel_appimage="gitcomet-v${VERSION}-linux-x86_64.AppImage"
arm_dmg="gitcomet-v${VERSION}-macos-arm64.dmg"
intel_dmg="gitcomet-v${VERSION}-macos-x86_64.dmg"
linux_arm_appimage_path="dist/release/${linux_arm_appimage}"
linux_intel_appimage_path="dist/release/${linux_intel_appimage}"
arm_dmg_path="dist/release/${arm_dmg}"
intel_dmg_path="dist/release/${intel_dmg}"

if [ ! -f "${linux_arm_appimage_path}" ] || [ ! -f "${linux_intel_appimage_path}" ] || [ ! -f "${arm_dmg_path}" ] || [ ! -f "${intel_dmg_path}" ]; then
echo "::error title=Missing release assets::Expected ${linux_arm_appimage}, ${linux_intel_appimage}, ${arm_dmg}, and ${intel_dmg} in dist/release."
if [ ! -f "${linux_arm_appimage_path}" ] || [ ! -f "${linux_intel_appimage_path}" ]; then
echo "::error title=Missing release assets::Expected ${linux_arm_appimage} and ${linux_intel_appimage} in dist/release."
exit 1
fi

scripts/generate-homebrew-cask.sh \
--version "${VERSION}" \
--github-repo "${GITHUB_REPOSITORY}" \
--arm-dmg "${arm_dmg_path}" \
--intel-dmg "${intel_dmg_path}" \
--linux-arm-appimage "${linux_arm_appimage_path}" \
--linux-intel-appimage "${linux_intel_appimage_path}" \
--output "dist/release/gitcomet.rb"
Expand Down
56 changes: 0 additions & 56 deletions .github/workflows/cross-platform-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -172,62 +172,6 @@ jobs:
- name: Run UI smoke test under selected profile
run: cargo test -p gitcomet-ui-gpui smoke_tests::smoke_view_renders_without_panicking -- --exact

macos-tests:
name: macOS Tests (${{ matrix.name }})
runs-on: ${{ matrix.runs_on }}
timeout-minutes: 60
strategy:
fail-fast: false
matrix:
include:
- target_platform: aarch64-darwin
name: macbook-m1 / macos-15
runs_on: macos-15
- target_platform: aarch64-darwin
name: latest-macos / macos-26
runs_on: macos-26
- target_platform: x86_64-darwin
name: intel (macos-15-intel)
runs_on: macos-15-intel
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Show Git version
run: git --version
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
- name: Cache Rust artifacts
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
- name: Show host target
run: rustc -vV
- name: Assert Apple Silicon runner
if: matrix.target_platform == 'aarch64-darwin'
run: |
set -euo pipefail
test "$(uname -m)" = "arm64"
rust_host="$(rustc -vV | sed -n 's/^host: //p')"
test "$rust_host" = "aarch64-apple-darwin"
- name: Run headless test suite
run: |
cargo test --workspace \
--exclude gitcomet-ui-gpui \
$APP_FEATURES \
--locked \
--verbose
- name: Gatekeeper and code-signing check (informational)
run: |
set -euo pipefail
cargo_config_output="$(scripts/macos-cargo-config.sh "$(uname -m)" release)"
set --
if [[ -n "$cargo_config_output" ]]; then
while IFS= read -r arg; do
set -- "$@" "$arg"
done <<<"$cargo_config_output"
fi
set -- "$@" -p gitcomet $APP_FEATURES --release --locked
cargo build "$@"
codesign --verify --verbose target/release/gitcomet || true
spctl --assess --type execute --verbose target/release/gitcomet || true

windows-tests:
name: Windows Tests (${{ matrix.target_platform }})
runs-on: ${{ matrix.runs_on }}
Expand Down
Loading
Loading