feat(desktop): add Aliyun OSS release mirror - #8976
Conversation
|
Thanks for the PR! Template looks good ✓
Stopping here for the maintainer decision. ⏸️ 中文说明感谢贡献! 模板完整 ✓
在此停下,等待维护者决定。⏸️ — Qwen Code · qwen3.8-max Reviewed at |
Code Coverage Summary
CLI Package - Full Text ReportCore Package - Full Text ReportFor detailed HTML reports, please see the 'coverage-reports-22.x-ubuntu-latest' artifact from the main CI run. |
qwen-code-ci-bot
left a comment
There was a problem hiding this comment.
Reviewed. Suggestions are inline.
Not explored to full depth (tool budget reached): PR #8976 mirrors published Qwen Code Desktop stable relea...: none — all checks I started were completed within budget.; PR #8976 mirrors published Qwen Code Desktop stable relea...: I didn't read the middle section of desktop-release.yml (lines 100-455, the build matrix details) as continuous text — I only checked the artifact/upload/permis…; PR #8976 mirrors published Qwen Code Desktop stable relea...: did not read desktop-release.yml lines 100–455 (build matrix internals) as continuous text; inspected its artifact-upload, permissions, and gating surfaces via …; PR #8976 mirrors published Qwen Code Desktop stable relea...: did not run cargo check on main.rs; verified by reading and against the exact cached plugin source instead.; PR #8976 mirrors published Qwen Code Desktop stable relea...: did not inspect the three pre-existing workflows sharing the ossutil blocks (R1-1 already covers that duplication/drift)..
Not linted (tool limitation, not a blocker): the executable-script lint — .github/workflows/desktop-release.yml: actionlint embedded-shell source mapping is not yet supported — not linted; the executable-script lint — .github/workflows/sync-desktop-to-oss.yml: actionlint embedded-shell source mapping is not yet supported — not linted.
Test Plan (not a blocker): desktop/latest/desktop-latest.json — no such file or directory.
中文说明
已审查。 建议见行内评论。
未探索到全部深度(达到工具调用预算):PR #8976 mirrors published Qwen Code Desktop stable relea...:none — all checks I started were completed within budget.;PR #8976 mirrors published Qwen Code Desktop stable relea...:I didn't read the middle section of desktop-release.yml (lines 100-455, the build matrix details) as continuous text — I only checked the artifact/upload/permis…;PR #8976 mirrors published Qwen Code Desktop stable relea...:did not read desktop-release.yml lines 100–455 (build matrix internals) as continuous text; inspected its artifact-upload, permissions, and gating surfaces via …;PR #8976 mirrors published Qwen Code Desktop stable relea...:did not run cargo check on main.rs; verified by reading and against the exact cached plugin source instead.;PR #8976 mirrors published Qwen Code Desktop stable relea...:did not inspect the three pre-existing workflows sharing the ossutil blocks (R1-1 already covers that duplication/drift).。
未检查(工具限制,非阻断):the executable-script lint — .github/workflows/desktop-release.yml: actionlint embedded-shell source mapping is not yet supported — not linted; the executable-script lint — .github/workflows/sync-desktop-to-oss.yml: actionlint embedded-shell source mapping is not yet supported — not linted。
Test Plan(非阻断):desktop/latest/desktop-latest.json — no such file or directory。
— qwen3.8-max via Qwen Code /review (v0.21.10)
- Add ref guard to sync-desktop-to-oss.yml (dispatch only from main) - Add diagnostic error messages for missing Windows/Linux installers - Harden test: pin verify-index > 0 before ordering comparison - Harden test: pin confirm-before-publish ordering and source comparison - Add test: stable-only release validation in reusable sync job
Closeout summaryCode changes (1292025)
Deferred / Follow-up
|
qwen-code-ci-bot
left a comment
There was a problem hiding this comment.
Reviewed. Suggestions are inline.
Not explored to full depth (tool budget reached): PR #8976 mirrors published stable Qwen Code Desktop relea...: did not run cargo check on the Rust change (API verified line-by-line against the exact pinned crate source instead; the change is three lines of builder call…; PR #8976 mirrors published stable Qwen Code Desktop relea...: did not execute the workflows end-to-end (requires the production-release environment and Aliyun secrets).; You are review agent reverse-audit — Reverse audit agen...: none — all checks above completed within budget..
Not linted (tool limitation, not a blocker): the executable-script lint — .github/workflows/desktop-release.yml: actionlint embedded-shell source mapping is not yet supported — not linted; the executable-script lint — .github/workflows/sync-desktop-to-oss.yml: actionlint embedded-shell source mapping is not yet supported — not linted.
Test Plan (not a blocker): desktop/latest/desktop-latest.json — no such file or directory.
中文说明
已审查。 建议见行内评论。
未探索到全部深度(达到工具调用预算):PR #8976 mirrors published stable Qwen Code Desktop relea...:did not run cargo check on the Rust change (API verified line-by-line against the exact pinned crate source instead; the change is three lines of builder call…;PR #8976 mirrors published stable Qwen Code Desktop relea...:did not execute the workflows end-to-end (requires the production-release environment and Aliyun secrets).;You are review agent reverse-audit — Reverse audit agen...:none — all checks above completed within budget.。
未检查(工具限制,非阻断):the executable-script lint — .github/workflows/desktop-release.yml: actionlint embedded-shell source mapping is not yet supported — not linted; the executable-script lint — .github/workflows/sync-desktop-to-oss.yml: actionlint embedded-shell source mapping is not yet supported — not linted。
Test Plan(非阻断):desktop/latest/desktop-latest.json — no such file or directory。
— qwen3.8-max via Qwen Code /review (v0.21.10)
…d non-latest repair - Remove workflow-level actions:read; grant it only to the sync-oss caller job - Reject suffixed versions for published stable releases in prepare - Turn latest-feed comparison into a non-fatal check; condition publish/verify on match - Assert both check_for_update call sites in release test - Add jq stable-only guard assertion and endpoint default alignment test Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
|
Refreshed this branch onto latest |
|
@qwen-code-review-bot review this pr and approve if no blockers |
doudouOUC
left a comment
There was a problem hiding this comment.
Not reviewed: the entire diff, the linked-issue fidelity pass, the whole-diff test-coverage check, the removed-behavior audit, the cross-file consistency pass, the build-and-test check — its prompt was built, but no agent on record was launched with it.
Not reviewed: verification and reverse audit — both prompts were built, but no agent was launched with either — the posted findings cannot be counted as verified, and the pass that hunts what the rest of the review missed cannot be certified.
Not linted (tool limitation, not a blocker): the executable-script lint — .github/workflows/desktop-release.yml: actionlint embedded-shell source mapping is not yet supported — not linted; the executable-script lint — .github/workflows/sync-desktop-to-oss.yml: actionlint embedded-shell source mapping is not yet supported — not linted.
Test Plan (not a blocker): desktop/latest/desktop-latest.json — no such file or directory.
中文说明
未审查:整个 diff、关联 issue 一致性检查、全 diff 测试覆盖检查、删除行为审计、跨文件一致性检查、构建与测试验证——它的 prompt 已构建,但没有任何 agent 有记录用它启动过。
未审查:验证与反向审计——两份 prompt 都已构建,但都没有 agent 用它们启动——发布的发现不能算作已验证,搜寻评审遗漏问题的工序也无法作证。
未检查(工具限制,非阻断):the executable-script lint — .github/workflows/desktop-release.yml: actionlint embedded-shell source mapping is not yet supported — not linted; the executable-script lint — .github/workflows/sync-desktop-to-oss.yml: actionlint embedded-shell source mapping is not yet supported — not linted。
Test Plan(非阻断):desktop/latest/desktop-latest.json — no such file or directory。
— deepseek-v4-flash via Qwen Code /review (v0.21.10)
| --version "$VERSION" \ | ||
| --base-url "${ALIYUN_OSS_PUBLIC_BASE_URL}/desktop/v${VERSION}" \ | ||
| --output desktop-latest.json | ||
| sha256sum -- * > SHA256SUMS.txt |
There was a problem hiding this comment.
[Suggestion] sha256sum glob with * may produce malformed checksums with filenames containing spaces
Failure scenario: If a future CI build change produces an artifact with a space in its filename, sha256sum -- * writes hash Qwen Code Desktop.exe into SHA256SUMS.txt. The verification loop while read -r _ asset would read asset="Qwen" — the truncated first word — and curl would fail with a 404. Versioned assets would already be on OSS but verification fails.
| sha256sum -- * > SHA256SUMS.txt | |
| find . -maxdepth 1 -type f -exec sha256sum {} + > SHA256SUMS.txt |
— deepseek-v4-flash via Qwen Code /review (v0.21.10)
中文说明
Failure scenario: 如果未来 CI 构建产物的文件名包含空格,sha256sum -- * 会在 SHA256SUMS.txt 中写入 hash Qwen Code Desktop.exe。后续的 while read -r _ asset 验证循环会错误地将 asset 截断为 "Qwen",导致 curl 请求 404。此时版本化资源已上传到 OSS,但验证失败,导致 OSS 处于不一致状态。
建议修复:将 sha256sum -- * > SHA256SUMS.txt 替换为 find . -maxdepth 1 -type f -exec sha256sum {} + > SHA256SUMS.txt,可以正确处理任意文件名。
— deepseek-v4-flash via Qwen Code /review (v0.21.10)
| gh release download 'desktop-latest' --dir "$directory" --pattern 'desktop-latest.json' | ||
| expected="$(jq -r '.version' dist/desktop/desktop-latest.json)" |
There was a problem hiding this comment.
[Suggestion] desktop-latest release check fails on first-ever run or after release deletion
Failure scenario: When triggered via workflow_dispatch directly on sync-desktop-to-oss.yml, the desktop-latest release may not exist (first-ever run) or may have been deleted. gh release download 'desktop-latest' exits non-zero, and set -euo pipefail causes the entire step to fail. The versioned assets have already been uploaded to OSS by this point, so the job fails on a non-essential check.
| gh release download 'desktop-latest' --dir "$directory" --pattern 'desktop-latest.json' | |
| expected="$(jq -r '.version' dist/desktop/desktop-latest.json)" | |
| - name: Check whether release matches GitHub stable feed | |
| id: latest | |
| run: | | |
| set -euo pipefail | |
| directory="$(mktemp -d)" | |
| gh release view 'desktop-latest' >/dev/null 2>&1 || { echo 'matches=false' >> "$GITHUB_OUTPUT"; exit 0; } | |
| gh release download 'desktop-latest' --dir "$directory" --pattern 'desktop-latest.json' | |
| expected="$(jq -r '.version' dist/desktop/desktop-latest.json)" | |
| actual="$(jq -r '.version' "$directory/desktop-latest.json")" | |
| if [ "$expected" = "$actual" ]; then | |
| echo 'matches=true' >> "$GITHUB_OUTPUT" | |
| else | |
| echo 'matches=false' >> "$GITHUB_OUTPUT" | |
| fi |
— deepseek-v4-flash via Qwen Code /review (v0.21.10)
中文说明
Failure scenario: 当通过 workflow_dispatch 直接触发 sync-desktop-to-oss.yml 时,desktop-latest 发布可能不存在(首次运行)或已被删除。gh release download 'desktop-latest' 会非零退出,set -euo pipefail 导致整个步骤失败。此时版本化资源已上传到 OSS,但任务因非必需的检查而失败。
建议修复:在下载前先检查 desktop-latest 发布是否存在,如果不存在则设置 matches=false 并正常退出。
— deepseek-v4-flash via Qwen Code /review (v0.21.10)
|
Released in v0.21.11. |
What this PR does
This PR mirrors every published stable Qwen Code Desktop release to Aliyun OSS and configures the Tauri updater to try the OSS feed first, with the existing GitHub feed as a fallback. The release workflow uploads the same signed installers and updater artifacts to a versioned OSS path, verifies every mirrored file by SHA-256, and only then advances the OSS latest manifest.
The updater feed request has a three-second timeout so an unreachable OSS endpoint does not delay startup or manual update checks. Tauri still performs the existing signature verification before installing an update.
Why it's needed
Desktop installers are large enough that GitHub Releases can be slow or unreliable for some users, especially on networks where Aliyun OSS is substantially closer. Keeping GitHub as the canonical release while adding a verified OSS mirror improves update availability without introducing a custom updater or changing the signing model.
Reviewer Test Plan
How to verify
node packages/desktop-shell/scripts/test-release.jsand confirm the Desktop release helper checks pass, including endpoint order and OSS manifest URLs.vitest run --config ./scripts/tests/vitest.config.ts scripts/tests/desktop-oss-workflow.test.jsand confirm the stable-only, credential, upload-order, and feed-version gates pass.cargo test --manifest-path packages/desktop-shell/src-tauri/Cargo.tomland confirm the Desktop shell tests pass.actionlint .github/workflows/desktop-release.yml .github/workflows/sync-desktop-to-oss.ymland confirm both workflows are valid.desktop/latest/desktop-latest.jsonare publicly readable and checksum-valid.Evidence (Before & After)
N/A — release infrastructure and updater source selection only; there is no UI change.
Tested on
Environment (optional)
macOS local helper tests, workflow contract tests, Rust tests, ESLint, Prettier, and actionlint. Windows and Linux packaged installers were not built locally; their artifact requirements are validated by the mirror workflow and remain covered by release CI.
Risk & Scope
Linked Issues
Follow-up to #8896.
中文说明
本 PR 做了什么
这个 PR 会把每一个正式发布的 Qwen Code Desktop 稳定版本同步到阿里云 OSS,并配置 Tauri updater 优先尝试 OSS 更新清单,原有 GitHub 更新清单作为回退。发布工作流会把同一批已签名安装包和 updater 产物上传到按版本隔离的 OSS 路径,逐个使用 SHA-256 校验镜像文件,全部验证成功后才更新 OSS 的 latest 清单。
更新清单请求设置了三秒超时,因此 OSS 不可访问时不会长时间拖慢启动或手动更新检查。安装更新前仍由 Tauri 执行现有的签名校验。
为什么需要
Desktop 安装包较大,部分用户的网络访问 GitHub Releases 会很慢或不稳定,特别是在阿里云 OSS 明显更近的网络环境中。保留 GitHub 作为权威发布源,同时增加经过校验的 OSS 镜像,可以提升更新可用性,又不需要自研 updater,也不改变现有签名模型。
Reviewer 测试计划
如何验证
node packages/desktop-shell/scripts/test-release.js,确认 Desktop 发布辅助检查通过,包括更新端点顺序和 OSS 清单 URL。vitest run --config ./scripts/tests/vitest.config.ts scripts/tests/desktop-oss-workflow.test.js,确认仅稳定版、凭据、上传顺序和 feed 版本门禁全部通过。cargo test --manifest-path packages/desktop-shell/src-tauri/Cargo.toml,确认 Desktop shell 测试通过。actionlint .github/workflows/desktop-release.yml .github/workflows/sync-desktop-to-oss.yml,确认两个工作流都合法。desktop/latest/desktop-latest.json可以公开访问且校验和正确。证据(Before & After)
N/A——只涉及发布基础设施和 updater 源选择,没有 UI 变化。
已测试平台
环境(可选)
在 macOS 本地运行了发布辅助测试、工作流契约测试、Rust 测试、ESLint、Prettier 和 actionlint。Windows 和 Linux 安装包没有在本地构建;镜像工作流会验证对应产物要求,发布 CI 继续覆盖这些平台。
风险与范围
关联问题
#8896 的后续改进。