Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
135 commits
Select commit Hold shift + click to select a range
ce56e34
fix(mobile): recover stale relay sessions (#4372)
brow Aug 3, 2026
e1f6da7
ci: add guarded desktop release cache prewarm (#4575)
wesbillman Aug 3, 2026
5c98932
feat(desktop): make onboarding model defaults skippable (#3968)
tellaho Aug 3, 2026
d4a4570
fix(desktop): clarify inherited agent parallelism (#4010)
wesbillman Aug 3, 2026
7981597
fix(reactions): wrap long popover names (#3834)
tellaho Aug 3, 2026
027a74a
Polish Share Compute settings (#3735)
klopez4212 Aug 3, 2026
985cdcc
feat(agents): model-tuning parity in global Agent Defaults editor (#4…
wpfleger96 Aug 3, 2026
ede8d22
feat(mobile): bring channel menus to desktop parity (#3940)
tellaho Aug 3, 2026
b29c8cd
feat(desktop): redesign the Huddle experience (#4281)
klopez4212 Aug 4, 2026
d5da74e
feat(mobile): add channel scroll navigation (#4239)
tellaho Aug 4, 2026
b42b093
feat(mobile): sync per-group channel sorting (#4231)
tellaho Aug 4, 2026
631b05c
feat: ship Buzz Term (#4347)
tlongwell-block Aug 4, 2026
feccf4e
Polish mobile inbox and media flows (#4512)
klopez4212 Aug 4, 2026
ddcf0ae
fix(desktop): stop clipping focus ring on channel intro action cards …
iroiro147 Aug 4, 2026
f18a9cb
Defer desktop media uploads until send (#4522)
klopez4212 Aug 4, 2026
a5bf3c5
Refine desktop timeline activity presentation (#4582)
klopez4212 Aug 4, 2026
d0af845
Remove blur from Welcome composer guidance (#4691)
klopez4212 Aug 4, 2026
0542bc8
docs(nip-am): normative amendment — cache SHOULD/MUST + pricingIdenti…
wpfleger96 Aug 4, 2026
56003eb
docs(acp): explain per-channel session model in base prompt (#4729)
wpfleger96 Aug 4, 2026
d0d4acd
fix(desktop): show cached display names on startup (#3317)
TheSentinel454 Aug 4, 2026
540b589
Polish sidebar unread hierarchy (#4573)
klopez4212 Aug 4, 2026
f86dfc5
feat(desktop): surface config diff in restart-required badge (#3637)
wpfleger96 Aug 4, 2026
0afeac8
feat(desktop): persist sidebar observed-unread across webview reload …
wpfleger96 Aug 4, 2026
e1287c9
Refine community invite links (#4734)
klopez4212 Aug 4, 2026
0c33a8a
fix(agents): canonicalize stale persona harness pins (#4631)
wpfleger96 Aug 4, 2026
bc9e652
perf(relay): index channel-id lookups and skip trace-only reads (#4647)
jemiahw Aug 4, 2026
cb4a73e
Dock Buzz Term within channel workspace (#4724)
wesbillman Aug 4, 2026
e5efd04
fix(desktop): close reconnect gaps that previously required CMD+R (#4…
wesbillman Aug 4, 2026
7bee84d
fix(mobile): stop oversized read-state retry loop (#4595)
wesbillman Aug 4, 2026
5179726
fix(local-archive): default both archive settings to enabled (#4750)
wpfleger96 Aug 4, 2026
ce3cf3c
Polish Huddle voice controls (#4694)
klopez4212 Aug 4, 2026
8b8d86c
fix(desktop): integer-align custom reaction emoji (#4779)
kalvinnchau Aug 4, 2026
65f7a10
fix(desktop): wait for terminal frame before splash (#4781)
wesbillman Aug 4, 2026
7bcfe7e
fix(desktop): widen post-Enter timeouts in empty-edit-delete spec (#4…
wpfleger96 Aug 4, 2026
383d9e1
fix(ci): make desktop cache test version agnostic (#4791)
wesbillman Aug 4, 2026
e30db70
feat(projects): support multiple repositories (#4671)
thomaspblock Aug 4, 2026
b948c54
chore(release): release Buzz Desktop version 0.5.5 (#4788)
wesbillman Aug 4, 2026
4c665ae
fix(desktop): serialize tray channel actions for frontend (#4762)
kalvinnchau Aug 4, 2026
a1d78f2
feat: Buzz entity links — rich preview cards + in-app navigation for …
thomaspblock Aug 4, 2026
8faf09f
Revert "chore(release): release Buzz Desktop version 0.5.5" (#4797)
wesbillman Aug 4, 2026
4a23051
fix: reauthenticate databricks model discovery (#4008)
kalvinnchau Aug 4, 2026
a0ed13d
chore(release): release Buzz Desktop version 0.5.5 (#4800)
wesbillman Aug 4, 2026
79c5216
Revert "chore(release): release Buzz Desktop version 0.5.5" (#4808)
wesbillman Aug 4, 2026
25a9cf1
feat: paste composer text without formatting (#4801)
kalvinnchau Aug 4, 2026
8342dfc
chore(release): release Buzz Desktop version 0.5.5 (#4809)
wesbillman Aug 4, 2026
6dbc946
fix(desktop): make missing-command error actionable for released buil…
wpfleger96 Aug 5, 2026
dc17965
fix(mobile): serialize channel sections sync (#3165)
brow Aug 5, 2026
067c085
Define private managed agent wire protocol (#4593)
wesbillman Aug 5, 2026
8a7eb8d
fix(agent): recover from unsupported image input instead of poisoning…
tlongwell-block Aug 5, 2026
997b8ca
fix(git): revoke access for banned relay members (#4608)
jmecom Aug 5, 2026
885bed3
fix(workflow): bind trigger author to the signed event (#4607)
jmecom Aug 5, 2026
ad538bf
fix(acp): reject unattended permission requests (#4609)
jmecom Aug 5, 2026
efe1893
fix(channels): restrict private-channel invitations (#4612)
jmecom Aug 5, 2026
4674750
fix(release): tag immutable desktop candidates (#4811)
wesbillman Aug 5, 2026
ff0b798
Polish mobile top navigation (#4778)
klopez4212 Aug 5, 2026
014562c
fix(desktop): allow shared agent mentions (#4913)
wesbillman Aug 5, 2026
2034e69
fix(desktop): remove join API token control (#4897)
klopez4212 Aug 5, 2026
f2ce575
Fix media attachment actions (#4849)
klopez4212 Aug 5, 2026
27b5114
Polish mobile bottom sheets and profile cards (#4911)
klopez4212 Aug 5, 2026
0c68429
Fix mobile message timeline bounce (#4862)
klopez4212 Aug 5, 2026
6df7eba
fix(buzz-agent): scope handoff cap per turn, not per session lifetime…
wpfleger96 Aug 5, 2026
6c40ce3
feat(desktop): cap OpenClaw agent parallelism at 5 (#4019)
wpfleger96 Aug 5, 2026
43cced3
feat(desktop): sync themes per community (#3653)
tellaho Aug 5, 2026
05150c1
feat(mobile): sync themes per community (#3767)
tellaho Aug 5, 2026
7334ad1
fix(desktop): route macos notification clicks (#4799)
kalvinnchau Aug 5, 2026
ccdaa16
docs(persona-pack): fix stale desktop import instructions (#4500)
SomSamantray Aug 5, 2026
ed4b3e7
fix(buzz-agent): recover from context-window 400s instead of sticking…
wpfleger96 Aug 5, 2026
719f973
feat(desktop): allow leaving your final community (#3621)
tellaho Aug 5, 2026
2ea9385
fix(reactions): support max-length custom emoji (#3833)
tellaho Aug 5, 2026
d42d60d
fix(desktop): rename generic attachment action from 'Attach image' to…
iroiro147 Aug 5, 2026
cda3397
style(messages): increase username contrast (#4948)
tellaho Aug 5, 2026
24c7995
fix(desktop): clamp thread panel to channel surface (#4965)
tellaho Aug 5, 2026
005fe54
fix(desktop): outline the selected community (#4969)
tellaho Aug 5, 2026
e14fff7
relay: fuzz WebSocket 1012 restart-close timing on graceful drain (BU…
bradseiler Aug 5, 2026
eb6a375
fix(desktop): enable message editing in Inbox (#2198)
brow Aug 5, 2026
06b60e6
fix(mobile): merge relay recounts with locally seen thread replies (#…
brow Aug 5, 2026
a7ea86c
fix(desktop): enable the content security policy (#4614)
jmecom Aug 5, 2026
4da7264
fix(acp): pace observer telemetry at 1/s with per-channel batch envel…
tlongwell-block Aug 6, 2026
5677e4c
test(desktop): match attachment button label (#4993)
tellaho Aug 6, 2026
16cc3de
fix(desktop): enforce owner-only access in internal builds (#4053)
brow Aug 6, 2026
e2796d4
fix(desktop): virtualize channel member lists (#4991)
wesbillman Aug 6, 2026
38bf642
ci: prove the relay-driven mesh lifecycle — discover, join, infer, de…
michaelneale Aug 6, 2026
96ae141
fix(desktop): skip native notifications outside app bundles (#5004)
wesbillman Aug 6, 2026
19b41e9
fix(desktop): stop rate-limited reconnect backfill from tearing down …
wesbillman Aug 6, 2026
5babb97
feat(desktop): show selected community in rail (#5000)
wesbillman Aug 6, 2026
480c41e
Improve desktop mobile pairing flow (#5024)
klopez4212 Aug 6, 2026
9213090
test(desktop): await thread scroll anchor (#3174)
cameronhotchkies Aug 6, 2026
6ca9641
Refine agent runtime controls (#5026)
klopez4212 Aug 6, 2026
bd2fdf4
fix(buzz-agent): classify read timeouts distinctly in LLM error messa…
wpfleger96 Aug 6, 2026
6eb6591
feat(identity): recover desktop identity from a signed-in phone (#4845)
tellaho Aug 6, 2026
c777d4f
chore(hooks): run desktop typecheck in pre-push (#5110)
wpfleger96 Aug 6, 2026
b08c8b1
fix(desktop): prevent sidebar prefs from reverting on stale-localStor…
wpfleger96 Aug 6, 2026
1399ec1
Alert community owners and admins when a new key joins (#4900)
tlongwell-block Aug 6, 2026
67b7734
fix(desktop): next/back navigation during key creation onboarding (#4…
tellaho Aug 7, 2026
f03de21
fix(desktop): preserve authoritative agent avatars (#4984)
tellaho Aug 7, 2026
769ac70
fix(media): require authenticated reads (#4610)
jmecom Aug 7, 2026
ad92335
feat(relay): accept kind:30179 private managed-agent events at ingest…
tlongwell-block Aug 7, 2026
f53bbd1
fix(bench): mention the orchestrator by pubkey when posting the task …
tlongwell-block Aug 7, 2026
ee9690a
fix(cli): emit structured JSON warning when archive/unarchive owner-a…
wpfleger96 Aug 7, 2026
c71f658
Polish advanced agent setup and Welcome composer (#4926)
klopez4212 Aug 7, 2026
cd2125c
Improve video review readiness and controls (#5161)
klopez4212 Aug 7, 2026
c293b3c
fix(agent): resolve oauth cache home cross-platform (#5151)
kalvinnchau Aug 7, 2026
346ae8c
fix(buzz-agent): escalate LLM timeouts per retry and log per-call lat…
wpfleger96 Aug 7, 2026
c8743b2
Remove agent creation success modal (#5063)
klopez4212 Aug 7, 2026
626e2c3
feat(mobile): add bee pull-to-refresh (#5059)
klopez4212 Aug 7, 2026
8476ea0
Mobile: add anchored reaction popover (#5025)
klopez4212 Aug 7, 2026
daa8877
Make public starter channels best effort (#5192)
wesbillman Aug 7, 2026
60ae74b
fix(desktop): use WEBKIT_DMABUF_RENDERER_FORCE_SHM for NVIDIA/AppImag…
Chessing234 Aug 7, 2026
cc9a2f7
fix(desktop): make terminal output selectable (#4980)
wesbillman Aug 7, 2026
8630e58
fix(desktop): fence localStorage SecurityError from killing the React…
iroiro147 Aug 7, 2026
e47894a
fix(desktop): drop unhandled rejection from throwing window.Notificat…
iroiro147 Aug 7, 2026
b2ac66c
refactor(cli): replace probe/decider/detail split with single typed e…
wpfleger96 Aug 7, 2026
fb73561
feat(desktop): Projects follow-ups — access restrictions, fast loadin…
thomaspblock Aug 7, 2026
ef2ecaf
fix(desktop): defer channel visibility change to Save (#5203)
kchung Aug 7, 2026
e9925db
fix(desktop): retain distinct agent instances in autocomplete (#5202)
atishpatel Aug 7, 2026
742e8d1
fix(buzz-agent): Responses reasoning summary, Anthropic display:summa…
wpfleger96 Aug 7, 2026
1922d49
feat(desktop): adding rich link previews to messages (#3818)
tellaho Aug 7, 2026
c3c39cc
bump @tauri-apps/cli to ~2.11.4 to fix linux app icon issue (#4858)
johan456789 Aug 7, 2026
78c87ae
fix(sdk): preserve self-mention p tags in message and forum event bui…
BradGroux Aug 7, 2026
0799942
fix(mobile): keep latest messages above composer (#4981)
tellaho Aug 7, 2026
3855687
chore(release): release Buzz Desktop version 0.5.6 (#5214)
wesbillman Aug 7, 2026
2b873cf
Recover from max-token response truncation (#5223)
tlongwell-block Aug 7, 2026
a5a9240
fix(desktop): let imported and recovered identities finish onboarding…
tellaho Aug 7, 2026
dcc1231
fix(desktop): externalize boot <style> to prevent Tauri CSP nonce ove…
wpfleger96 Aug 7, 2026
74b913c
fix(desktop): isolate relay admission tests (#5221)
wesbillman Aug 7, 2026
13c9e90
chore(release): release Buzz Desktop version 0.5.7 (#5252)
wesbillman Aug 7, 2026
65834d6
infra: bind development services to loopback (#4871)
Karniej Aug 7, 2026
c7b6636
fix(buzz-agent): budget summarizer reasoning separately so it cannot …
tlongwell-block Aug 7, 2026
02f640b
feat(desktop): unify add agent flows (#5015)
tellaho Aug 7, 2026
6a17d03
Revert "fix(acp): reject unattended permission requests" (#5323)
wesbillman Aug 8, 2026
261c460
fix(buzz-agent): recover from 400-shaped image rejections; unbound be…
tlongwell-block Aug 8, 2026
c815a9c
chore(release): release Buzz Desktop version 0.5.8 (#5326)
wesbillman Aug 8, 2026
6e5c462
chore(release): release Buzz Relay version 0.2.1 (#2856)
wpfleger96 Aug 8, 2026
08d0c36
Merge upstream relay-v0.2.1 (Desktop v0.5.8)
dekanbro Aug 10, 2026
650eb10
ci(security): allow retired relay pool advisory (#5404)
wesbillman Aug 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
9 changes: 4 additions & 5 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -102,11 +102,10 @@ BUZZ_S3_ADDRESSING_STYLE=path
# BUZZ_MEDIA_MAX_CONCURRENT_UPLOADS=8
# BUZZ_MEDIA_MAX_CONCURRENT_UPLOADS_PER_PUBKEY=2
# BUZZ_MEDIA_UPLOADS_PER_MINUTE=30
# Require Blossom t=get auth and relay membership for GET/HEAD /media/*.
# Keep off until desktop/mobile/CLI clients that attach media read auth are deployed.
# BUZZ_REQUIRE_MEDIA_GET_AUTH=false
# Legacy alias accepted by the relay while rollout docs catch up:
# BUZZ_REQUIRE_MEDIA_READ_AUTH=false
# GET/HEAD /media/* always require Blossom t=get auth and relay membership.
# BUZZ_REQUIRE_MEDIA_GET_AUTH and BUZZ_REQUIRE_MEDIA_READ_AUTH are no longer
# read; setting either (including to false) changes nothing and the relay warns
# about it at startup.

# -----------------------------------------------------------------------------
# Ephemeral Channels (TTL testing)
Expand Down
17 changes: 14 additions & 3 deletions .github/workflows/auto-tag-on-release-pr-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,7 @@ jobs:
echo "enabled=true"
echo "tag=${TAG_PREFIX}${VERSION}"
if [[ "$TAG_PREFIX" == desktop-v ]]; then
echo "target_sha=${{ github.event.pull_request.merge_commit_sha }}"
echo "target_sha=${{ github.event.pull_request.head.sha }}"
echo "desktop=true"
else
echo "target_sha=$GITHUB_SHA"
Expand All @@ -113,6 +113,7 @@ jobs:
PR_BASE_REF: ${{ github.event.pull_request.base.ref }}
PR_HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }}
MERGE_SHA: ${{ github.event.pull_request.merge_commit_sha }}
MERGED_AT: ${{ github.event.pull_request.merged_at }}
run: |
VERSION="${VERSION#desktop-v}"
export VERSION
Expand Down Expand Up @@ -147,7 +148,17 @@ jobs:
exit 1
fi
fi
gh api --method POST "repos/$GITHUB_REPOSITORY/git/refs" \
if ! gh api --method POST "repos/$GITHUB_REPOSITORY/git/refs" \
-f ref="refs/tags/$TAG" \
-f sha="$TARGET_SHA" \
--silent
--silent; then
# Ref creation is atomic. A concurrent retry may have won the race;
# accept that only when it created the exact immutable ref.
EXISTING_SHA="$(gh api "repos/$GITHUB_REPOSITORY/commits/$TAG" --jq .sha)"
if [ "$EXISTING_SHA" = "$TARGET_SHA" ]; then
echo "Tag $TAG was concurrently created at $TARGET_SHA"
exit 0
fi
echo "::error::Tag creation failed and $TAG resolves to $EXISTING_SHA (expected $TARGET_SHA)"
exit 1
fi
15 changes: 14 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -768,6 +768,19 @@ jobs:
env:
RELAY_URL: ws://localhost:3000
GIT_CREDENTIAL_NOSTR_BIN: ${{ github.workspace }}/target/ci/git-credential-nostr
- name: Media read-auth e2e
# Reads require kind:24242 `t=get` auth, so these binaries are the only
# coverage that a real relay rejects bare reads and honours host- and
# hash-scoped tokens. They were #[ignore]d and selected by no CI job, so
# the lane never ran; select it here, where MinIO and the seeded
# 'localhost:3000' community already exist.
# --no-fail-fast: without it cargo stops after the first failing binary,
# so one broken case hides every later binary's result.
run: |
cargo test -p buzz-test-client --no-fail-fast --test e2e_media --test e2e_media_extended --test e2e_media_video -- --ignored --nocapture
env:
RELAY_URL: ws://localhost:3000
RELAY_HTTP_URL: http://localhost:3000
- name: Upload relay logs
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
Expand Down Expand Up @@ -1023,7 +1036,7 @@ jobs:
git log -1 --format=%s | grep -qx smoke
echo "Host bash resolved and functional; git commit round-trip passed"
- name: Check (Tauri crate)
run: cargo check --manifest-path desktop/src-tauri/Cargo.toml --target $env:TARGET
run: cargo check --manifest-path desktop/src-tauri/Cargo.toml --workspace --all-targets --target $env:TARGET
env:
CMAKE_POLICY_VERSION_MINIMUM: "3.5"
- name: Test (Tauri crate)
Expand Down
164 changes: 164 additions & 0 deletions .github/workflows/desktop-release-cache-proof.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,164 @@
name: Desktop release cache tag-scope proof

# Dispatch from a cache-proof-* tag at the same trusted-main SHA warmed by all
# four canaries. Every job restores only and requires an exact cache hit.
on:
workflow_dispatch:

permissions:
contents: read

jobs:
macos:
name: Prove macOS ${{ matrix.target }} cache visibility
if: github.repository == 'block/buzz'
runs-on: macos-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
include:
- target: aarch64-apple-darwin
features: mesh-llm
- target: x86_64-apple-darwin
features: default
steps:
- name: Require cache proof tag
run: '[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }'
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Patch proof dependency graph
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh macos)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
env:
CACHE_TARGET: ${{ matrix.target }}
CACHE_FEATURES: ${{ matrix.features }}
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target "$CACHE_TARGET" --features "$CACHE_FEATURES" --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'

linux:
name: Prove Linux cache visibility
if: github.repository == 'block/buzz'
runs-on: ubuntu-latest
container: ubuntu:24.04@sha256:4fbb8e6a8395de5a7550b33509421a2bafbc0aab6c06ba2cef9ebffbc7092d90
timeout-minutes: 15
defaults:
run:
shell: bash
steps:
- name: Require cache proof tag and install release native tools
run: |
[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }
apt-get update
apt-get install -y --no-install-recommends build-essential ca-certificates curl git libasound2-dev libayatana-appindicator3-dev libgtk-3-dev librsvg2-dev libssl-dev libwebkit2gtk-4.1-dev libxdo-dev patchelf pkg-config
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- run: git config --global --add safe.directory "$GITHUB_WORKSPACE"
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Patch proof dependency graph
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh linux)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target x86_64-unknown-linux-gnu --features mesh-llm --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'

windows:
name: Prove Windows cache visibility
if: github.repository == 'block/buzz'
runs-on: windows-latest
timeout-minutes: 15
steps:
- name: Require cache proof tag
shell: bash
run: '[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }'
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Patch proof dependency graph
shell: bash
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
shell: bash
run: echo "id=$(scripts/desktop-native-toolchain-id.sh windows)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
shell: bash
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target x86_64-pc-windows-msvc --features default --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
shell: bash
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'
2 changes: 2 additions & 0 deletions .github/workflows/desktop-release-candidate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ on:

permissions:
contents: read
pull-requests: read

jobs:
validate:
Expand All @@ -20,6 +21,7 @@ jobs:
- name: Validate immutable desktop candidate
if: startsWith(github.event.pull_request.head.ref, 'version-bump/')
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ github.event.pull_request.head.ref }}
run: |
VERSION="${VERSION#version-bump/}"
Expand Down
66 changes: 52 additions & 14 deletions .github/workflows/linux-canary.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@ name: Linux Canary
# Design notes vs. signed-macos-canary.yml:
# - fix-appimage.sh is run without signing env vars; the script detects
# their absence and skips re-signing, repacking only (documented inline).
# - mold linker added (rui314/setup-mold) to reduce link time, matching
# the Linux Rust CI jobs in ci.yml.
# - Build tools match release.yml; cache keys derive the concrete linker and
# native library identity rather than assuming the moving runner image.
# - pnpm store restore/save pattern mirrors ci.yml:149-196.
on:
workflow_dispatch:
Expand Down Expand Up @@ -83,18 +83,6 @@ jobs:

- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1

- uses: rui314/setup-mold@9c9c13bf4c3f1adef0cc596abc155580bcb04444 # v1

# Rust cache covering both the workspace sidecar build and the Tauri
# crate build. shared-key scoped to linux-canary-release so canary runs
# warm each other without colliding with CI's debug-profile keys.
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
workspaces: |
.
desktop/src-tauri
shared-key: linux-canary-release

- name: Install appimagetool
run: |
case "$(uname -m)" in
Expand Down Expand Up @@ -154,6 +142,38 @@ jobs:
cd desktop && node scripts/set-version-from-tag.mjs "$VERSION"
cd src-tauri && cargo update --workspace

- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh linux)" >> "$GITHUB_OUTPUT"

# Compute this after cargo update so the key describes the graph that is
# actually compiled. The helper normalizes only Buzz Desktop's release
# version, allowing a canary to warm an otherwise identical tag build.
- name: Compute exact release cache key
id: rust_cache_key
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py \
--platform "$RUNNER_OS" \
--target x86_64-unknown-linux-gnu \
--features mesh-llm \
--native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
echo "Release cache key: $KEY"

- name: Restore exact release Cargo cache
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}

- name: Generate non-updating bundle config
run: |
cat > desktop/src-tauri/tauri.canary.conf.json <<'JSON'
Expand Down Expand Up @@ -190,6 +210,24 @@ jobs:
fi
bash desktop/scripts/fix-appimage.sh "${APPIMAGES[0]}"

- name: Measure release Cargo cache inputs
if: always()
run: du -sh ~/.cargo/registry ~/.cargo/git target desktop/src-tauri/target 2>/dev/null || true

# Only this trusted, main-bound canary writes the cache. Excluding bundle
# output prevents installers from entering it.
- name: Save exact release Cargo cache
if: steps.rust_cache.outputs.cache-hit != 'true'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}

- name: Save pnpm store cache
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
Expand Down
Loading
Loading