Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
110 commits
Select commit Hold shift + click to select a range
89bf03c
fix(nip-oa): accept raw Nostr tag form in parse_json_array (#4203)
amanning3390 Aug 2, 2026
28ae6cd
docs: formal spec for remote agents and their management (#3748)
tlongwell-block Aug 2, 2026
b7bb151
feat(projects): add buzz projects CLI commands (NIP-MP kind:30621) (#…
wpfleger96 Aug 2, 2026
fc598f5
fix(git): allow deleting the default branch (#4297)
MajorTal Aug 2, 2026
6530b58
feat(k8s): Kubernetes backend plugin + desktop deploy path (#4289)
tlongwell-block Aug 2, 2026
f86cfc7
fix(desktop): back/forward via keyboard chords, mouse X1/X2 buttons, …
matheuskiser Aug 2, 2026
318fbf8
fix(security): bump nostr crates for RUSTSEC-2026-0225..0232 + defaul…
tlongwell-block Aug 2, 2026
7ff5fc3
feat(acp): deliver system prompt via _meta.systemPrompt for claude-ag…
wpfleger96 Aug 2, 2026
a5dbdf5
fix(mobile): recover and pace live subscriptions (#3053)
brow Aug 3, 2026
2c0ac24
fix(desktop): stop the create-agent provider config probe from erasin…
tlongwell-block Aug 3, 2026
83a285f
ci(linux): enable mesh-llm feature in Linux release and canary builds…
tlongwell-block Aug 3, 2026
857e63c
Polish mobile composer and messaging UI (#3918)
klopez4212 Aug 3, 2026
be95a8a
fix(config-bridge): add harness-definition env tier and fix equal-val…
wpfleger96 Aug 3, 2026
f810a2f
fix(desktop): make OpenAI key re-enterable after first save in card m…
wpfleger96 Aug 3, 2026
5e0efb0
fix(desktop): disambiguate provider API key labels and annotate mint …
wpfleger96 Aug 3, 2026
f865c00
feat(desktop): show saved Run on settings when editing an agent (#4539)
tlongwell-block Aug 3, 2026
b0c6d6f
Add channel activity hover menu (#3935)
klopez4212 Aug 3, 2026
01c80aa
fix(desktop): save key backups to authorized path (#4022)
tellaho Aug 3, 2026
c1b88af
feat(desktop): improve channel template discovery (#4549)
wesbillman Aug 3, 2026
80315ac
fix(desktop): harden Windows installs against Defender block and orph…
wpfleger96 Aug 3, 2026
09c86c5
fix: report agent usage per provider round, not once per turn (#4545)
atishpatel Aug 3, 2026
44fa1e8
docs(release): align desktop handoff instructions (#3988)
wesbillman Aug 3, 2026
6de85fe
test(mobile): assert follow boundary semantics (#4559)
wesbillman Aug 3, 2026
651f637
chore(release): release Buzz Desktop version 0.5.4 (#4562)
wesbillman Aug 3, 2026
ce56e34
fix(mobile): recover stale relay sessions (#4372)
brow Aug 3, 2026
e1f6da7
ci: add guarded desktop release cache prewarm (#4575)
wesbillman Aug 3, 2026
5c98932
feat(desktop): make onboarding model defaults skippable (#3968)
tellaho Aug 3, 2026
d4a4570
fix(desktop): clarify inherited agent parallelism (#4010)
wesbillman Aug 3, 2026
7981597
fix(reactions): wrap long popover names (#3834)
tellaho Aug 3, 2026
027a74a
Polish Share Compute settings (#3735)
klopez4212 Aug 3, 2026
985cdcc
feat(agents): model-tuning parity in global Agent Defaults editor (#4…
wpfleger96 Aug 3, 2026
ede8d22
feat(mobile): bring channel menus to desktop parity (#3940)
tellaho Aug 3, 2026
b29c8cd
feat(desktop): redesign the Huddle experience (#4281)
klopez4212 Aug 4, 2026
d5da74e
feat(mobile): add channel scroll navigation (#4239)
tellaho Aug 4, 2026
b42b093
feat(mobile): sync per-group channel sorting (#4231)
tellaho Aug 4, 2026
631b05c
feat: ship Buzz Term (#4347)
tlongwell-block Aug 4, 2026
feccf4e
Polish mobile inbox and media flows (#4512)
klopez4212 Aug 4, 2026
ddcf0ae
fix(desktop): stop clipping focus ring on channel intro action cards …
iroiro147 Aug 4, 2026
f18a9cb
Defer desktop media uploads until send (#4522)
klopez4212 Aug 4, 2026
a5bf3c5
Refine desktop timeline activity presentation (#4582)
klopez4212 Aug 4, 2026
d0af845
Remove blur from Welcome composer guidance (#4691)
klopez4212 Aug 4, 2026
0542bc8
docs(nip-am): normative amendment — cache SHOULD/MUST + pricingIdenti…
wpfleger96 Aug 4, 2026
56003eb
docs(acp): explain per-channel session model in base prompt (#4729)
wpfleger96 Aug 4, 2026
d0d4acd
fix(desktop): show cached display names on startup (#3317)
TheSentinel454 Aug 4, 2026
540b589
Polish sidebar unread hierarchy (#4573)
klopez4212 Aug 4, 2026
f86dfc5
feat(desktop): surface config diff in restart-required badge (#3637)
wpfleger96 Aug 4, 2026
0afeac8
feat(desktop): persist sidebar observed-unread across webview reload …
wpfleger96 Aug 4, 2026
e1287c9
Refine community invite links (#4734)
klopez4212 Aug 4, 2026
0c33a8a
fix(agents): canonicalize stale persona harness pins (#4631)
wpfleger96 Aug 4, 2026
bc9e652
perf(relay): index channel-id lookups and skip trace-only reads (#4647)
jemiahw Aug 4, 2026
cb4a73e
Dock Buzz Term within channel workspace (#4724)
wesbillman Aug 4, 2026
e5efd04
fix(desktop): close reconnect gaps that previously required CMD+R (#4…
wesbillman Aug 4, 2026
7bee84d
fix(mobile): stop oversized read-state retry loop (#4595)
wesbillman Aug 4, 2026
5179726
fix(local-archive): default both archive settings to enabled (#4750)
wpfleger96 Aug 4, 2026
ce3cf3c
Polish Huddle voice controls (#4694)
klopez4212 Aug 4, 2026
8b8d86c
fix(desktop): integer-align custom reaction emoji (#4779)
kalvinnchau Aug 4, 2026
65f7a10
fix(desktop): wait for terminal frame before splash (#4781)
wesbillman Aug 4, 2026
7bcfe7e
fix(desktop): widen post-Enter timeouts in empty-edit-delete spec (#4…
wpfleger96 Aug 4, 2026
383d9e1
fix(ci): make desktop cache test version agnostic (#4791)
wesbillman Aug 4, 2026
e30db70
feat(projects): support multiple repositories (#4671)
thomaspblock Aug 4, 2026
b948c54
chore(release): release Buzz Desktop version 0.5.5 (#4788)
wesbillman Aug 4, 2026
4c665ae
fix(desktop): serialize tray channel actions for frontend (#4762)
kalvinnchau Aug 4, 2026
a1d78f2
feat: Buzz entity links — rich preview cards + in-app navigation for …
thomaspblock Aug 4, 2026
8faf09f
Revert "chore(release): release Buzz Desktop version 0.5.5" (#4797)
wesbillman Aug 4, 2026
4a23051
fix: reauthenticate databricks model discovery (#4008)
kalvinnchau Aug 4, 2026
a0ed13d
chore(release): release Buzz Desktop version 0.5.5 (#4800)
wesbillman Aug 4, 2026
79c5216
Revert "chore(release): release Buzz Desktop version 0.5.5" (#4808)
wesbillman Aug 4, 2026
25a9cf1
feat: paste composer text without formatting (#4801)
kalvinnchau Aug 4, 2026
8342dfc
chore(release): release Buzz Desktop version 0.5.5 (#4809)
wesbillman Aug 4, 2026
6dbc946
fix(desktop): make missing-command error actionable for released buil…
wpfleger96 Aug 5, 2026
dc17965
fix(mobile): serialize channel sections sync (#3165)
brow Aug 5, 2026
067c085
Define private managed agent wire protocol (#4593)
wesbillman Aug 5, 2026
8a7eb8d
fix(agent): recover from unsupported image input instead of poisoning…
tlongwell-block Aug 5, 2026
997b8ca
fix(git): revoke access for banned relay members (#4608)
jmecom Aug 5, 2026
885bed3
fix(workflow): bind trigger author to the signed event (#4607)
jmecom Aug 5, 2026
ad538bf
fix(acp): reject unattended permission requests (#4609)
jmecom Aug 5, 2026
efe1893
fix(channels): restrict private-channel invitations (#4612)
jmecom Aug 5, 2026
4674750
fix(release): tag immutable desktop candidates (#4811)
wesbillman Aug 5, 2026
ff0b798
Polish mobile top navigation (#4778)
klopez4212 Aug 5, 2026
014562c
fix(desktop): allow shared agent mentions (#4913)
wesbillman Aug 5, 2026
2034e69
fix(desktop): remove join API token control (#4897)
klopez4212 Aug 5, 2026
f2ce575
Fix media attachment actions (#4849)
klopez4212 Aug 5, 2026
27b5114
Polish mobile bottom sheets and profile cards (#4911)
klopez4212 Aug 5, 2026
0c68429
Fix mobile message timeline bounce (#4862)
klopez4212 Aug 5, 2026
6df7eba
fix(buzz-agent): scope handoff cap per turn, not per session lifetime…
wpfleger96 Aug 5, 2026
6c40ce3
feat(desktop): cap OpenClaw agent parallelism at 5 (#4019)
wpfleger96 Aug 5, 2026
43cced3
feat(desktop): sync themes per community (#3653)
tellaho Aug 5, 2026
05150c1
feat(mobile): sync themes per community (#3767)
tellaho Aug 5, 2026
7334ad1
fix(desktop): route macos notification clicks (#4799)
kalvinnchau Aug 5, 2026
ccdaa16
docs(persona-pack): fix stale desktop import instructions (#4500)
SomSamantray Aug 5, 2026
ed4b3e7
fix(buzz-agent): recover from context-window 400s instead of sticking…
wpfleger96 Aug 5, 2026
719f973
feat(desktop): allow leaving your final community (#3621)
tellaho Aug 5, 2026
2ea9385
fix(reactions): support max-length custom emoji (#3833)
tellaho Aug 5, 2026
d42d60d
fix(desktop): rename generic attachment action from 'Attach image' to…
iroiro147 Aug 5, 2026
cda3397
style(messages): increase username contrast (#4948)
tellaho Aug 5, 2026
24c7995
fix(desktop): clamp thread panel to channel surface (#4965)
tellaho Aug 5, 2026
005fe54
fix(desktop): outline the selected community (#4969)
tellaho Aug 5, 2026
e14fff7
relay: fuzz WebSocket 1012 restart-close timing on graceful drain (BU…
bradseiler Aug 5, 2026
eb6a375
fix(desktop): enable message editing in Inbox (#2198)
brow Aug 5, 2026
06b60e6
fix(mobile): merge relay recounts with locally seen thread replies (#…
brow Aug 5, 2026
a7ea86c
fix(desktop): enable the content security policy (#4614)
jmecom Aug 5, 2026
4da7264
fix(acp): pace observer telemetry at 1/s with per-channel batch envel…
tlongwell-block Aug 6, 2026
5677e4c
test(desktop): match attachment button label (#4993)
tellaho Aug 6, 2026
16cc3de
fix(desktop): enforce owner-only access in internal builds (#4053)
brow Aug 6, 2026
e2796d4
fix(desktop): virtualize channel member lists (#4991)
wesbillman Aug 6, 2026
38bf642
ci: prove the relay-driven mesh lifecycle — discover, join, infer, de…
michaelneale Aug 6, 2026
96ae141
fix(desktop): skip native notifications outside app bundles (#5004)
wesbillman Aug 6, 2026
8fdc58b
Merge upstream/main into fork (107 commits, 2026-08-06)
Cvv9 Aug 6, 2026
3a9f9a7
fix(desktop): keep hosted agent mentions community-scoped
Cvv9 Aug 6, 2026
669a986
test: make agent and badge specs pass on Windows
Cvv9 Aug 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
19 changes: 15 additions & 4 deletions .github/workflows/auto-tag-on-release-pr-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ jobs:
github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 0
Expand Down Expand Up @@ -91,7 +91,7 @@ jobs:
echo "enabled=true"
echo "tag=${TAG_PREFIX}${VERSION}"
if [[ "$TAG_PREFIX" == desktop-v ]]; then
echo "target_sha=${{ github.event.pull_request.merge_commit_sha }}"
echo "target_sha=${{ github.event.pull_request.head.sha }}"
echo "desktop=true"
else
echo "target_sha=$GITHUB_SHA"
Expand All @@ -112,6 +112,7 @@ jobs:
PR_BASE_REF: ${{ github.event.pull_request.base.ref }}
PR_HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }}
MERGE_SHA: ${{ github.event.pull_request.merge_commit_sha }}
MERGED_AT: ${{ github.event.pull_request.merged_at }}
run: |
VERSION="${VERSION#desktop-v}"
export VERSION
Expand Down Expand Up @@ -146,7 +147,17 @@ jobs:
exit 1
fi
fi
gh api --method POST "repos/$GITHUB_REPOSITORY/git/refs" \
if ! gh api --method POST "repos/$GITHUB_REPOSITORY/git/refs" \
-f ref="refs/tags/$TAG" \
-f sha="$TARGET_SHA" \
--silent
--silent; then
# Ref creation is atomic. A concurrent retry may have won the race;
# accept that only when it created the exact immutable ref.
EXISTING_SHA="$(gh api "repos/$GITHUB_REPOSITORY/commits/$TAG" --jq .sha)"
if [ "$EXISTING_SHA" = "$TARGET_SHA" ]; then
echo "Tag $TAG was concurrently created at $TARGET_SHA"
exit 0
fi
echo "::error::Tag creation failed and $TAG resolves to $EXISTING_SHA (expected $TARGET_SHA)"
exit 1
fi
2 changes: 1 addition & 1 deletion .github/workflows/benchmark-harbor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: "3.12"
Expand Down
35 changes: 18 additions & 17 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ jobs:
web: ${{ steps.filter.outputs.web }}
mobile: ${{ steps.filter.outputs.mobile }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 2
- uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
Expand Down Expand Up @@ -98,7 +98,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand All @@ -119,7 +119,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- uses: rui314/setup-mold@9c9c13bf4c3f1adef0cc596abc155580bcb04444 # v1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
Expand All @@ -141,7 +141,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 2
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
Expand Down Expand Up @@ -237,7 +237,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Get pnpm store directory
id: pnpm-cache
Expand Down Expand Up @@ -320,7 +320,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
# Reuse the relay binaries and backend test archive when none of their
# inputs changed (desktop-only PRs hit this every time). The key covers
Expand Down Expand Up @@ -393,7 +393,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Start integration services
run: |
Expand Down Expand Up @@ -584,7 +584,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Install cargo-nextest
uses: taiki-e/install-action@0fd46367812ee04360509b4169d9f659d6892bb2 # v2.79.15
Expand Down Expand Up @@ -749,7 +749,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand Down Expand Up @@ -790,7 +790,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 2
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
Expand Down Expand Up @@ -837,7 +837,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 2
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
Expand Down Expand Up @@ -898,7 +898,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Dependency policy
run: cargo-deny check
Expand All @@ -910,7 +910,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Check for dead API token references in client code
run: |
# Fail if dead API token patterns reappear in desktop, mobile, docs, or config.
Expand Down Expand Up @@ -939,7 +939,7 @@ jobs:
- x86_64-unknown-linux-musl
- aarch64-unknown-linux-musl
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand Down Expand Up @@ -976,7 +976,7 @@ jobs:
env:
TARGET: x86_64-pc-windows-msvc
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
# MSVC needs windows.h (aws-lc-sys et al.), so this runs on a real Windows
# runner — hermit, used by the Linux jobs, does not provide MSVC. The
# toolchain (1.95.0 + clippy via profile = default) comes from the
Expand Down Expand Up @@ -1040,7 +1040,7 @@ jobs:
git log -1 --format=%s | grep -qx smoke
echo "Host bash resolved and functional; git commit round-trip passed"
- name: Check (Tauri crate)
run: cargo check --manifest-path desktop/src-tauri/Cargo.toml --target $env:TARGET
run: cargo check --manifest-path desktop/src-tauri/Cargo.toml --workspace --all-targets --target $env:TARGET
env:
CMAKE_POLICY_VERSION_MINIMUM: "3.5"
- name: Test (Tauri crate)
Expand All @@ -1057,7 +1057,7 @@ jobs:
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand All @@ -1071,6 +1071,7 @@ jobs:
mkdir -p desktop/src-tauri/binaries
touch "desktop/src-tauri/binaries/buzz-acp-$TARGET"
touch "desktop/src-tauri/binaries/buzz-agent-$TARGET"
touch "desktop/src-tauri/binaries/buzz-backend-kubernetes-$TARGET"
touch "desktop/src-tauri/binaries/buzz-dev-mcp-$TARGET"
touch "desktop/src-tauri/binaries/git-credential-nostr-$TARGET"
touch "desktop/src-tauri/binaries/buzz-$TARGET"
Expand Down
164 changes: 164 additions & 0 deletions .github/workflows/desktop-release-cache-proof.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,164 @@
name: Desktop release cache tag-scope proof

# Dispatch from a cache-proof-* tag at the same trusted-main SHA warmed by all
# four canaries. Every job restores only and requires an exact cache hit.
on:
workflow_dispatch:

permissions:
contents: read

jobs:
macos:
name: Prove macOS ${{ matrix.target }} cache visibility
if: github.repository == 'block/buzz'
runs-on: macos-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
include:
- target: aarch64-apple-darwin
features: mesh-llm
- target: x86_64-apple-darwin
features: default
steps:
- name: Require cache proof tag
run: '[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }'
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Patch proof dependency graph
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh macos)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
env:
CACHE_TARGET: ${{ matrix.target }}
CACHE_FEATURES: ${{ matrix.features }}
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target "$CACHE_TARGET" --features "$CACHE_FEATURES" --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'

linux:
name: Prove Linux cache visibility
if: github.repository == 'block/buzz'
runs-on: ubuntu-latest
container: ubuntu:24.04@sha256:4fbb8e6a8395de5a7550b33509421a2bafbc0aab6c06ba2cef9ebffbc7092d90
timeout-minutes: 15
defaults:
run:
shell: bash
steps:
- name: Require cache proof tag and install release native tools
run: |
[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }
apt-get update
apt-get install -y --no-install-recommends build-essential ca-certificates curl git libasound2-dev libayatana-appindicator3-dev libgtk-3-dev librsvg2-dev libssl-dev libwebkit2gtk-4.1-dev libxdo-dev patchelf pkg-config
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- run: git config --global --add safe.directory "$GITHUB_WORKSPACE"
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Patch proof dependency graph
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh linux)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target x86_64-unknown-linux-gnu --features mesh-llm --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'

windows:
name: Prove Windows cache visibility
if: github.repository == 'block/buzz'
runs-on: windows-latest
timeout-minutes: 15
steps:
- name: Require cache proof tag
shell: bash
run: '[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }'
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Patch proof dependency graph
shell: bash
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
shell: bash
run: echo "id=$(scripts/desktop-native-toolchain-id.sh windows)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
shell: bash
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target x86_64-pc-windows-msvc --features default --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
shell: bash
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'
2 changes: 2 additions & 0 deletions .github/workflows/desktop-release-candidate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ on:

permissions:
contents: read
pull-requests: read

jobs:
validate:
Expand All @@ -20,6 +21,7 @@ jobs:
- name: Validate immutable desktop candidate
if: startsWith(github.event.pull_request.head.ref, 'version-bump/')
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ github.event.pull_request.head.ref }}
run: |
VERSION="${VERSION#version-bump/}"
Expand Down
Loading
Loading