Skip to content

ci(build-tauri): verify aw-awatcher and aw-sync staged for Linux bundle - #1511

Open
TimeToBuildBob wants to merge 1 commit into
ActivityWatch:masterfrom
TimeToBuildBob:ci/verify-tauri-linux-bundle-watchers
Open

TimeToBuildBob wants to merge 1 commit into
ActivityWatch:masterfrom
TimeToBuildBob:ci/verify-tauri-linux-bundle-watchers

Conversation

@TimeToBuildBob

Copy link
Copy Markdown
Contributor

Summary

After #1499 the Makefile stages aw-awatcher and aw-sync into aw-tauri/src-tauri/modules/ before the Tauri bundle step on Linux. Without a CI gate, a regression in the staging step would ship AppImage/deb bundles silently missing their watcher processes.

This PR adds a lightweight Linux-only step after make build that verifies both binaries are present and executable before the build continues to packaging.

  • Fails fast if either binary is missing, with a clear error message naming the absent binary.
  • Only runs on Linux legs (where staging is expected); macOS/Windows are unaffected.
  • Mirrors the existing macOS bundle-watcher check at line ~1601.

No functional change to the build output.

Test plan

  • Linux CI legs (ubuntu-24.04, ubuntu-24.04-arm) pass with the step green
  • Verify step output shows ✓ aw-awatcher and aw-sync staged for Linux Tauri bundle

After PR ActivityWatch#1499 the Makefile stages both binaries into
aw-tauri/src-tauri/modules/ before the Tauri bundle step.
Add a regression gate that fails the Linux CI leg if either
binary is absent post-build, preventing a silent regression
where the AppImage/deb ships without its watcher processes.

Git-Session-Id: 983c
@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Adds a verification step to the release build workflow.

The PR appears safe to merge; the new check matches the existing Linux staging paths.

What we checked:

  • Valid Linux builds fail: Makefile copies both helpers to the exact paths checked and marks them executable. The Linux build rows do not skip the Rust helper.

Summary

Adds a Linux-only check after make build that requires aw-awatcher and aw-sync to be executable in the Tauri staging directory.

  • Reports each missing or non-executable file and stops the job.
  • Matches the paths created by Makefile.
  • Leaves macOS and Windows unchanged.

Reviews (1) · Last reviewed commit: "ci(build-tauri): verify aw-awatcher and ..." · Reviewed by Greptile

@TimeToBuildBob

TimeToBuildBob commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 AI code review

Adds a Linux-only CI step to the build-tauri job that checks aw-awatcher and aw-sync are present and executable in aw-tauri/src-tauri/modules/ after make build, failing the job if either is missing. The step is placed between the Build step and the Run tests step.

Safe to merge — no P0/P1 findings

Confidence 5/5

✅ No thread-worthy findings. Advisory notes follow; they are retained without opening review threads.

1 advisory finding (summary-only, not scored)

These P2 guard, heuristic, trade-off, or documentation claims are retained for judgment without opening review threads.

⚠️ P2 medium — .github/workflows/release.yml:1444

The new verification step runs after the 'Build' step but before the 'Run tests' step, and it checks the path aw-tauri/src-tauri/modules/${binary}. However, the actual staging of aw-awatcher and aw-sync into that directory is performed by the Makefile during the 'Build' step (make build). The step's placement is correct relative to the build, but the check only verifies the file exists and is executable; it does not verify that the staged binaries are the freshly built ones rather than stale artifacts from a previous run. On a clean CI runner this is fine, but the step does not guard against the case where the Makefile staging step silently fails to overwrite an existing binary, leaving an old version in place. The observable consequence is that a regression in the staging logic that leaves a stale binary would not be caught, and the bundle could ship an outdated watcher. This is a low-severity gap because the primary failure mode (missing binary) is caught, but the check's name and comment claim it verifies the bundle includes the watchers, which it only partially does.

Consider using `[ ! -f "$path" ]` instead of `[ ! -x "$path" ]` if the staging step does not guarantee the executable bit, or verify the final bundle contents after packaging.

How this was verified: Checked the step's run block: it only tests -x on the path, not freshness or content. The Makefile staging is not part of this diff, so I cannot confirm whether it overwrites or skips existing files.

Consensus: 2/3 passes agreed — pass 3 looked and disagreed
Distinct keys: 1 (general)

Files changed (1) — the diff as I read it
  • .github/workflows/release.yml — Adds a 'Verify Linux Tauri bundle includes awatcher and aw-sync' step that checks for the two binaries and exits non-zero if either is missing.
Previous review passes
commit score findings engine when
8e9c7d180869 5/5 0 llm 2026-10-07 13:55 UTC

Reviewed 8e9c7d180869 · openrouter/deepseek/deepseek-v4-flash-0731 · llm engine · 14s · about this reviewer

Maintainer commands

@TimeToBuildBob review (own line) — fresh review · @TimeToBuildBob fix — a worker acts on the findings. Once per comment; 👀 = received.

@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

The advisory's suggestion to move this check after packaging is unnecessary: the top-level Makefile clears aw-tauri/src-tauri/modules/, copies both helpers, and marks them executable during make build, before building aw-tauri. Keeping the gate immediately after Build is correct.

The Linux x86-64 and ARM64 jobs are still running; the x86-64 staging check has not run yet. No failing check is reported, so no rerun or code change is needed. Leaving this open for the Linux CI results and maintainer merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant