fix(desktop): green Windows smoke + Linux AppImage PG packaging checks (#2138)
## Summary - **Windows CI:** run the embedded Postgres smoke as non-admin `fusion-pg` (with profile prewarm) so elevated `windows-latest` runners stop failing with PostgreSQL’s admin-token refusal. Packaging still runs as the job user. - **Linux AppImage:** add a packaging content verifier for `main-bootstrap`, `@embedded-postgres` natives, and `omp-runtime` dist entrypoints; wire it into `release.yml`, `test-release.yml`, and the advisory **Desktop packaging** PR lane (after `electron-builder --dir`). - Fix eslint `no-undef` on bare `URL` in the verifier script (was red on #2131). ## Context Desktop packaging on Ubuntu was mostly green; Windows desktop builds and the AppImage packaging PR (#2131 lint) were the remaining red paths. The win-pg-diag pivot (run smoke as non-admin) proved green on CI; this ports that approach without removing main’s elevated-token product path for end-user “Run as administrator” cases (smoke simply does not take that path when the process is non-admin). ## Test plan - [x] `pnpm --filter @fusion/desktop exec vitest run src/__tests__/release-workflow.test.ts` - [x] `pnpm exec eslint scripts/verify-desktop-linux-pg-packaging.mjs` - [ ] Desktop packaging workflow on this PR - [ ] Desktop Windows Build (workflow_dispatch) - [ ] Confirm #2131 supersession if this lands the same AppImage checks <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Strengthened Linux desktop AppImage validation to confirm embedded PostgreSQL artifacts, required binaries, symlink hydration, and the expected app entrypoints are present after packaging. * Improved Windows embedded PostgreSQL smoke testing by running under a non-administrator helper user with a prewarmed profile environment. * **Tests** * Added automated packaging/release workflow verification steps (Linux and Windows) to catch embedded PostgreSQL content regressions earlier, including during artifact build and release verification. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
8
.github/workflows/desktop-packaging.yml
vendored
8
.github/workflows/desktop-packaging.yml
vendored
@@ -84,3 +84,11 @@ jobs:
|
||||
- name: Validate packageable closure (electron-builder --dir)
|
||||
if: steps.changes.outputs.relevant == 'true'
|
||||
run: pnpm --filter @fusion/desktop exec electron-builder --projectDir deploy --dir --publish never
|
||||
|
||||
# FNXC:DesktopEmbeddedPostgres 2026-07-15-10:45:
|
||||
# electron-builder --dir leaves linux-*-unpacked trees; assert embedded Postgres
|
||||
# packaging content (main-bootstrap, natives, omp-runtime) so AppImage regressions
|
||||
# fail on the advisory packaging PR lane, not only at release.
|
||||
- name: Verify Linux AppImage embedded Postgres packaging
|
||||
if: steps.changes.outputs.relevant == 'true'
|
||||
run: node scripts/verify-desktop-linux-pg-packaging.mjs
|
||||
78
.github/workflows/desktop-windows.yml
vendored
78
.github/workflows/desktop-windows.yml
vendored
@@ -22,11 +22,87 @@ jobs:
|
||||
- name: Install dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
# FNXC:WindowsDesktopPackaging 2026-07-15-00:55:
|
||||
# The embedded-PG smoke boots postgres under a non-admin helper user
|
||||
# (fusion-pg). The FIRST Start-Process -Credential for that user loads its
|
||||
# Windows profile hive (~10-20s), which would blow a test's 15s budget.
|
||||
# Create the user and warm its profile once here, outside any test window;
|
||||
# the launcher resets the user's password before each run, but the warmed
|
||||
# profile persists, so every later launch is ~0.5s.
|
||||
- name: Prewarm embedded-PG helper user profile
|
||||
shell: pwsh
|
||||
run: |
|
||||
$user = "fusion-pg"
|
||||
# Throwaway password for the ephemeral helper user (the launcher resets
|
||||
# it before each run); generated at runtime to avoid a hardcoded literal.
|
||||
$pass = "Fx9!" + ([guid]::NewGuid().ToString("N")) + "#kP"
|
||||
net user $user $pass /add /y 2>&1 | Out-Null
|
||||
$sec = ConvertTo-SecureString $pass -AsPlainText -Force
|
||||
$cred = New-Object System.Management.Automation.PSCredential("$env:COMPUTERNAME\$user", $sec)
|
||||
[void](Start-Process -FilePath cmd.exe -ArgumentList '/c','exit' -Credential $cred -Wait -WindowStyle Hidden)
|
||||
Write-Host "prewarmed $user profile"
|
||||
|
||||
# FNXC:DesktopEmbeddedPostgres 2026-07-14-09:39:
|
||||
# The manual Windows installer path must boot the same embedded database
|
||||
# payload used by Local mode before it can publish an installer artifact.
|
||||
# FNXC:WindowsDesktopPackaging 2026-07-15-02:40:
|
||||
# The runner executes jobs elevated, and PostgreSQL refuses an elevated
|
||||
# (admin) token. Run the WHOLE smoke AS the non-admin helper user
|
||||
# (fusion-pg): the test process, its tmpdir() data dirs, AND postgres all
|
||||
# run as fusion-pg, so postgres inherits a non-admin token and boots via
|
||||
# the normal embedded-postgres path — no in-launcher Start-Process
|
||||
# -Credential / staging / process-kill races.
|
||||
- name: Smoke embedded Postgres on Windows
|
||||
run: pnpm --filter @fusion/core test:embedded-postgres
|
||||
shell: pwsh
|
||||
run: |
|
||||
$user = "fusion-pg"
|
||||
$pass = "Fx9!" + ([guid]::NewGuid().ToString("N")) + "#kP"
|
||||
net user $user $pass /y 2>&1 | Out-Null
|
||||
# FNXC:WindowsDesktopPackaging 2026-07-15-11:25:
|
||||
# Full recursive grants on the workspace + pnpm store (proven green on
|
||||
# win-pg-diag). Narrow grants miss pnpm resolution targets and exit 1
|
||||
# with no useful signal. Capture the bat log so failures surface.
|
||||
Write-Host "granting ACL (workspace + tooling) for $user..."
|
||||
icacls $env:GITHUB_WORKSPACE /grant "*S-1-5-32-545:(OI)(CI)M" /T /C 2>&1 | Out-Null
|
||||
if (Test-Path D:\.pnpm-store) {
|
||||
icacls D:\.pnpm-store /grant "*S-1-5-32-545:(OI)(CI)RX" /T /C 2>&1 | Out-Null
|
||||
}
|
||||
icacls C:\Users\runneradmin /grant "*S-1-5-32-545:RX" /C 2>&1 | Out-Null
|
||||
if (Test-Path C:\Users\runneradmin\setup-pnpm) {
|
||||
icacls C:\Users\runneradmin\setup-pnpm /grant "*S-1-5-32-545:(OI)(CI)RX" /T /C 2>&1 | Out-Null
|
||||
}
|
||||
$nodeDir = Split-Path (Get-Command node).Source -Parent
|
||||
icacls $nodeDir /grant "*S-1-5-32-545:(OI)(CI)RX" /T /C 2>&1 | Out-Null
|
||||
# Traversable HOME/TEMP for the helper user (its tmpdir() lands here).
|
||||
$h = "C:\fusionpg-home"
|
||||
New-Item -ItemType Directory -Force -Path "$h\tmp" | Out-Null
|
||||
icacls $h /grant "*S-1-5-32-545:(OI)(CI)F" /T /C 2>&1 | Out-Null
|
||||
$pnpmDir = Split-Path (Get-Command pnpm).Source -Parent
|
||||
$bat = Join-Path $h "smoke.bat"
|
||||
$log = Join-Path $h "smoke.log"
|
||||
Set-Content -Path $bat -Encoding ASCII -Value @(
|
||||
"@echo off",
|
||||
"set `"USERPROFILE=$h`"",
|
||||
"set `"APPDATA=$h\AppData\Roaming`"",
|
||||
"set `"LOCALAPPDATA=$h\AppData\Local`"",
|
||||
"set `"TEMP=$h\tmp`"",
|
||||
"set `"TMP=$h\tmp`"",
|
||||
"set `"PATH=$nodeDir;$pnpmDir;%PATH%`"",
|
||||
"cd /d $env:GITHUB_WORKSPACE",
|
||||
"call pnpm --filter @fusion/core test:embedded-postgres > `"$log`" 2>&1",
|
||||
"exit /b %ERRORLEVEL%"
|
||||
)
|
||||
Write-Host "running embedded-PG smoke as $user..."
|
||||
$sec = ConvertTo-SecureString $pass -AsPlainText -Force
|
||||
$cred = New-Object System.Management.Automation.PSCredential("$env:COMPUTERNAME\$user", $sec)
|
||||
$p = Start-Process -FilePath "cmd.exe" -ArgumentList '/c',$bat -Credential $cred -Wait -PassThru -WindowStyle Hidden
|
||||
if (Test-Path $log) {
|
||||
Write-Host "----- smoke.log (tail) -----"
|
||||
Get-Content $log -Tail 200
|
||||
} else {
|
||||
Write-Host "smoke.log missing (bat may not have started)"
|
||||
}
|
||||
if ($p.ExitCode -ne 0) { Write-Error "embedded-PG smoke failed (exit $($p.ExitCode))"; exit 1 }
|
||||
|
||||
# FNXC:WindowsDesktopPackaging 2026-07-01-19:45:
|
||||
# Mirror release.yml: build every workspace package's tsc dist (incl.
|
||||
|
||||
7
.github/workflows/release.yml
vendored
7
.github/workflows/release.yml
vendored
@@ -333,6 +333,13 @@ jobs:
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# FNXC:DesktopEmbeddedPostgres 2026-07-15-00:20:
|
||||
# AppImage filename presence is not enough — v0.60.0 shipped without
|
||||
# embedded-postgres / main-bootstrap / omp-runtime. Inspect the linux-*-unpacked
|
||||
# trees electron-builder leaves beside the AppImage.
|
||||
- name: Verify Linux AppImage embedded Postgres packaging
|
||||
run: node scripts/verify-desktop-linux-pg-packaging.mjs
|
||||
|
||||
- name: Sign Linux desktop artifacts
|
||||
if: ${{ env.LINUX_GPG_PRIVATE_KEY != '' }}
|
||||
env:
|
||||
|
||||
7
.github/workflows/test-release.yml
vendored
7
.github/workflows/test-release.yml
vendored
@@ -315,6 +315,13 @@ jobs:
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# FNXC:DesktopEmbeddedPostgres 2026-07-15-00:20:
|
||||
# AppImage filename presence is not enough — v0.60.0 shipped without
|
||||
# embedded-postgres / main-bootstrap / omp-runtime. Inspect the linux-*-unpacked
|
||||
# trees electron-builder leaves beside the AppImage.
|
||||
- name: Verify Linux AppImage embedded Postgres packaging
|
||||
run: node scripts/verify-desktop-linux-pg-packaging.mjs
|
||||
|
||||
- name: Sign Linux desktop artifacts
|
||||
if: ${{ env.LINUX_GPG_PRIVATE_KEY != '' }}
|
||||
env:
|
||||
|
||||
Reference in New Issue
Block a user