Skip to content

Rye/gha - #405

Merged
RyeMutt merged 7 commits into
developfrom
rye/gha
Oct 5, 2026
Merged

RyeMutt merged 7 commits into
developfrom
rye/gha

Conversation

@RyeMutt

@RyeMutt RyeMutt commented Oct 5, 2026

Copy link
Copy Markdown
Member

Description

Related Issues

  • Please link to a relevant GitHub issue for additional context.
    • Bug Fix: Link to an issue that includes reproduction steps and testing guidance.
    • Feature/Enhancement: Link to an issue with a write-up, rationale, and requirements.

Issue Link:


Checklist

Please ensure the following before requesting review:

  • I have provided a clear title and detailed description for this pull request.
  • If useful, I have included media such as screenshots and video to show off my changes.
  • I have tested the changes locally and verified they work as intended.
  • All new and existing tests pass.
  • Code follows the project's style guidelines.
  • Documentation has been updated if needed.
  • Any dependent changes have been merged and published in downstream modules
  • I have reviewed the contributing guidelines.

Additional Notes

RyeMutt and others added 7 commits October 4, 2026 21:13
…branch

For a tag build it asks for the branches whose tip the commit is, in one
call where which-branch compared the commit with every branch in turn,
and finds the branch's pull request by owner:branch: given a bare branch
name GitHub ignores the filter and lists every open pull request, and
which-branch took whichever matched first. The release notes are passed
under a delimiter they cannot contain, where a line reading EOF ended
them. No Python, and no PyGithub to install.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… own, as Windows is

The hosted build signed nothing on macOS: the install rules left signing
to a packaging job that was never enabled, so the disk image carried an
unsealed bundle. Now the build job archives the stripped bundle beside
its package.env, and sign-and-package-mac signs it inside out with
ViewerCodeSign.cmake, has vpk add its updater, seal, notarize and staple
it, and builds the disk image from that bundle with dmgbuild, so a viewer
installed from the image updates itself; then signs, notarizes and
staples the image. The Windows job signs every binary, Setup.exe and
Update.exe through AzureSignTool and a certificate in Azure Key Vault,
in place of viewer-build-util's sign-pkg-windows. Pull requests, and
builds without the secrets, are packaged unsigned.

The install step signs on the hosted build too, ad-hoc, and the package
step seals the bundle again once it has stripped the executable, which
left every local disk image with a broken signature. Data files are no
longer signed: their signatures live in extended attributes that update
packages drop. VLC's plugins.dat is not shipped on macOS, being the one
data file in a code directory, and stale once the plugins are signed.

The disk image is APFS, ULMO: HFS+ decomposed the names of the font
stand-ins with Japanese names and broke the seal. Linden's Second Life
background and layout, the altool notarization script and the AppleScript
helpers go. AL_ENABLE_SIGNING, which nothing read, is retired; the
identity alone decides, and AL_NOTARY_PROFILE notarizes the velopack
target's package. package.env has one set of keys for both platforms,
and macOS has its Velopack channel, osx-arm64 or osx-x64.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…se them

scripts/signing/macos_signing_secrets.py takes the Developer ID
Application .p12 exported from Keychain Access and the App Store Connect
API key's .p8. It imports the certificate into a keychain of its own, as
the build does, and wants one private key and one identity macOS trusts
for code signing; it encrypts it again under a password it makes, in the
format the build's `security import` reads, which LibreSSL's AES output is
not; and it tries the API key against the notary service. Then it stores
the secrets with `gh secret set`, or writes them to private files. No
password goes on a command line: openssl reads them through pipes, and gh
reads each value on its standard input.

An individual API key must be given no issuer ID, so the build passes one
only when MACOS_NOTARY_ISSUER_ID is set, and the script removes a stale
one when it stores an individual key.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ves its disk to the viewer

vcpkg builds the ports with the CMake on the path and hashes its version
into every package ABI. Linux pinned it; macOS and Windows took whatever
PyPI had, so CMake 4.4.4 turned every package into a cache miss there:
macOS built 154 ports from source (37 minutes, and the disk the viewer's
macOS row then ran out of), Windows spent 86 minutes on what took one the
day before. CMake and Ninja are pinned on every runner now, 4.4.3 where
Linux's floor will not do, which is what the cache holds.

What the jobs keep on disk shrinks too: no local binary cache, which
nothing on a one-job runner reads again; each port's sources, build tree
and staged package removed once installed; CPack's copy of the tree
removed once archived; and on macOS the Xcodes the build does not use and
the Android SDK removed in the background while the ports build. Every row
reports the disk it finished with.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…chives

The symbol setup was made for a crash service that wanted an archive per
platform: a tarball of the viewer's PDB, a zip of the viewer's dSYM, a
tarball of the viewer's split debug file, each uploaded as an artifact and
read by nothing. Sentry was then pointed at the build tree around them,
which on macOS meant it found the dSYM twice, unpacked the zip's copy to a
temporary file, and ran the runner out of disk. Only the viewer had its
debug information kept; the plugins, the CEF hosts and every library
shipped without it.

The `symbols` target now makes a store from the staged tree, using the
staging install's manifest as the list of what ships (the viewer itself,
which the install finds already in place and so leaves out of it, is
named separately). Every binary goes in, with its debug information
beside it where it has any:

  Windows  the executables and DLLs, each with the PDB its CodeView record
           names, or the vcpkg PDB of that name for a prebuilt library
  macOS    the Mach-O files, each with a dSYM where it has a debug map
  Linux    filed by build ID, as gdb, debuginfod and distribution debug
           packages lay one out: the binary without its debug information
           and its .debug, with the sections compressed with zstd (zlib
           where objcopy has no zstd)

Binaries are hard links on Windows and macOS, so the store costs only the
debug files. The hosted build makes the store and uploads it, and nothing
else, to Sentry; the archives, their artifacts and the dSYM step after
every macOS link are gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… job

The Windows rows configure with the ninja presets instead of Visual Studio,
naming cl as the compiler. The build tree already supports a Developer
Command Prompt: the triplet guess reads VSCMD_ARG_TGT_ARCH and the target
architecture is the compiler's.

scripts/ci/msvc_environment.py gives the job that prompt's environment: it
runs vcvarsall.bat for the runner's architecture under Visual Studio 2026,
the one the generator used, and passes on what it changed through
GITHUB_ENV and GITHUB_PATH. It leaves out Visual Studio's own CMake and
Ninja, which would shadow the pinned ones every vcpkg package ABI hashes,
and VCPKG_ROOT, which names Visual Studio's vcpkg rather than the
submodule. setup-build runs it when asked; CodeQL's Windows row stays on
the Visual Studio generator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added cmake github_actions Pull requests that update GitHub Actions code python viewer labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2faece8a-116d-4945-adae-e21993da832f
📥 Commits

Reviewing files that changed from the base of the PR and between 68f991d and 30861e3.

⛔ Files ignored due to path filters (1)
  • indra/newview/installers/darwin/release-dmg/background.jpg is excluded by !**/*.jpg
📒 Files selected for processing (27)
  • .github/actions/setup-build/action.yaml
  • .github/workflows/build.yaml
  • .github/workflows/codeql.yaml
  • doc/BUILD.md
  • dotnet-tools.json
  • indra/CMakeLists.txt
  • indra/cmake/00-Common.cmake
  • indra/cmake/ConfigurationReport.cmake
  • indra/cmake/Linking.cmake
  • indra/cmake/RetiredOptions.cmake
  • indra/cmake/ViewerCodeSign.cmake
  • indra/cmake/ViewerInstall.cmake
  • indra/cmake/ViewerPackage.cmake
  • indra/cmake/ViewerStrip.cmake
  • indra/cmake/ViewerSymbols.cmake
  • indra/newview/CMakeLists.txt
  • indra/newview/installers/darwin/apple-notarize.sh
  • indra/newview/installers/darwin/dmg-cleanup.applescript
  • indra/newview/installers/darwin/dmg_settings.py
  • indra/newview/installers/darwin/fix_application_icon_position.sh
  • indra/newview/installers/darwin/release-dmg/Applications-alias.r
  • indra/newview/installers/darwin/release-dmg/_DS_Store
  • indra/newview/installers/darwin/release-dmg/_VolumeIcon.icns
  • indra/vcpkg-configuration.json
  • scripts/ci/msvc_environment.py
  • scripts/ci/test_msvc_environment.py
  • scripts/signing/macos_signing_secrets.py
 ______________________________________________________________________________________________________
< Fools ignore complexity. Pragmatists suffer it. Some can avoid it. Geniuses remove it. - Alan Perlis >
 ------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@RyeMutt
RyeMutt merged commit 67a4376 into develop Oct 5, 2026
8 of 21 checks passed
@RyeMutt
RyeMutt deleted the rye/gha branch October 5, 2026 01:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cmake github_actions Pull requests that update GitHub Actions code python viewer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant