Repository navigation
Build universal binary in stable release workflow - #2287
Conversation
Match the nightly workflow's universal build approach so stable releases support both Apple Silicon and Intel Macs. Adds -destination, ARCHS, ONLY_ACTIVE_ARCH=NO flags and a post-build architecture verification step. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryThis PR updates the stable release workflow to build universal (arm64 + x86_64) binaries by adding the same xcodebuild flags already used in the nightly workflow, introduces a post-build architecture verification step, and mechanically renames all
Confidence Score: 5/5Safe to merge — changes are a mechanical port of the nightly universal-build approach, with no logic divergence and a new verification gate. All remaining findings are P2 style suggestions (improving error messages in assertion failures). There are no logic errors, missing path updates, or regressions relative to the nightly workflow. The PR correctly and completely aligns the stable release with the universal-binary pattern. No files require special attention; Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A([push tag / workflow_dispatch]) --> B[Guard immutable release assets]
B -- skip_all=true --> Z([End])
B -- skip_all=false --> C[Select Xcode + Install deps]
C --> D[Download pre-built GhosttyKit.xcframework]
D --> E["xcodebuild universal build\n-destination generic/platform=macOS\nARCHS=arm64 x86_64\nONLY_ACTIVE_ARCH=NO"]
E --> F["✅ NEW: Verify binary architectures\nlipo -archs app / CLI / ghostty\nassert arm64 + x86_64"]
F --> G[Build remote daemon assets + inject manifest]
G --> H[Run CLI version memory guard]
H --> I[Verify bundled Ghostty helper]
I --> J[Inject Sparkle keys into Info.plist]
J --> K[Import signing cert]
K --> L[Codesign app]
L --> M[Notarize app + create DMG]
M --> N[Upload dSYMs to Sentry]
N --> O[Generate Sparkle appcast]
O --> P[Attest + Upload release assets]
P --> Q[Cleanup keychain]
Reviews (1): Last reviewed commit: "Build universal binary (arm64 + x86_64) ..." | Re-trigger Greptile |
| [[ "$APP_ARCHS" == *arm64* && "$APP_ARCHS" == *x86_64* ]] | ||
| [[ "$CLI_ARCHS" == *arm64* && "$CLI_ARCHS" == *x86_64* ]] | ||
| [[ "$HELPER_ARCHS" == *arm64* && "$HELPER_ARCHS" == *x86_64* ]] |
There was a problem hiding this comment.
Silent assertion failures are hard to diagnose
The bare [[ ... ]] assertions will cause the step to exit with code 1 when a check fails, but they print no message to stderr explaining which binary failed and what architectures were actually found. A reader would have to scroll up through the echo output to correlate. Adding an explicit failure message makes CI logs immediately actionable:
| [[ "$APP_ARCHS" == *arm64* && "$APP_ARCHS" == *x86_64* ]] | |
| [[ "$CLI_ARCHS" == *arm64* && "$CLI_ARCHS" == *x86_64* ]] | |
| [[ "$HELPER_ARCHS" == *arm64* && "$HELPER_ARCHS" == *x86_64* ]] | |
| [[ "$APP_ARCHS" == *arm64* && "$APP_ARCHS" == *x86_64* ]] || { echo "ERROR: App binary is not universal (got: $APP_ARCHS)" >&2; exit 1; } | |
| [[ "$CLI_ARCHS" == *arm64* && "$CLI_ARCHS" == *x86_64* ]] || { echo "ERROR: CLI binary is not universal (got: $CLI_ARCHS)" >&2; exit 1; } | |
| [[ "$HELPER_ARCHS" == *arm64* && "$HELPER_ARCHS" == *x86_64* ]] || { echo "ERROR: Ghostty helper is not universal (got: $HELPER_ARCHS)" >&2; exit 1; } |
Note: nightly.yml uses the same bare-assertion pattern (lines 225–227), so the same suggestion applies there for consistency.
📝 WalkthroughWalkthroughThe release workflow build process was updated to produce universal macOS binaries spanning both arm64 and x86_64 architectures. The derived data path was changed to Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (2)
.github/workflows/release.yml (2)
162-178: Consider adding explicit failure messages for each binary check.The verification logic is correct, but if a check fails, the workflow will exit without indicating which binary failed. Adding explicit error messages would improve debuggability.
🔧 Proposed improvement for better error output
echo "App binary architectures: $APP_ARCHS" echo "CLI binary architectures: $CLI_ARCHS" echo "Ghostty helper architectures: $HELPER_ARCHS" - [[ "$APP_ARCHS" == *arm64* && "$APP_ARCHS" == *x86_64* ]] - [[ "$CLI_ARCHS" == *arm64* && "$CLI_ARCHS" == *x86_64* ]] - [[ "$HELPER_ARCHS" == *arm64* && "$HELPER_ARCHS" == *x86_64* ]] + [[ "$APP_ARCHS" == *arm64* && "$APP_ARCHS" == *x86_64* ]] || { echo "App binary is not universal: $APP_ARCHS" >&2; exit 1; } + [[ "$CLI_ARCHS" == *arm64* && "$CLI_ARCHS" == *x86_64* ]] || { echo "CLI binary is not universal: $CLI_ARCHS" >&2; exit 1; } + [[ "$HELPER_ARCHS" == *arm64* && "$HELPER_ARCHS" == *x86_64* ]] || { echo "Ghostty helper is not universal: $HELPER_ARCHS" >&2; exit 1; }🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/release.yml around lines 162 - 178, The three architecture checks currently use bare conditional expressions so if one fails the job exits with no context; update the run block that defines APP_BINARY, CLI_BINARY, HELPER_BINARY and their ARCHS (APP_ARCHS, CLI_ARCHS, HELPER_ARCHS) to test each architecture check explicitly and emit a clear error and non-zero exit when it fails (e.g., if [[ "$APP_ARCHS" != *arm64* || "$APP_ARCHS" != *x86_64* ]]; then echo "ERROR: App binary $APP_BINARY missing expected architectures: $APP_ARCHS" >&2; exit 1; fi) and do the same for CLI_ARCHS and HELPER_ARCHS so failures identify which binary and what architectures were found.
155-155: Consider aligningbuild-sign-upload.shpath with workflow'sbuild-universal/.The
scripts/build-sign-upload.shscript hardcodesbuild/as the derived data path (lines 51, 73, 214), while this workflow usesbuild-universal/. Although the workflow doesn't invoke the script, aligning paths would prevent confusion if the script is run independently.Consider updating the script to use
build-universal/or parameterizing the path.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/release.yml at line 155, The script scripts/build-sign-upload.sh hardcodes derived data path as build/ (occurrences around the file's references at the current hardcoded instances) which conflicts with the workflow using build-universal/; update the script to either (A) change those hardcoded paths to build-universal/ or (B) add a configurable variable/parameter (e.g., DERIVED_DATA_PATH) at the top of scripts/build-sign-upload.sh and replace the hardcoded occurrences (the three hardcoded locations noted) with that variable so callers (including the workflow) can pass build-universal/ when needed.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In @.github/workflows/release.yml:
- Around line 162-178: The three architecture checks currently use bare
conditional expressions so if one fails the job exits with no context; update
the run block that defines APP_BINARY, CLI_BINARY, HELPER_BINARY and their ARCHS
(APP_ARCHS, CLI_ARCHS, HELPER_ARCHS) to test each architecture check explicitly
and emit a clear error and non-zero exit when it fails (e.g., if [[ "$APP_ARCHS"
!= *arm64* || "$APP_ARCHS" != *x86_64* ]]; then echo "ERROR: App binary
$APP_BINARY missing expected architectures: $APP_ARCHS" >&2; exit 1; fi) and do
the same for CLI_ARCHS and HELPER_ARCHS so failures identify which binary and
what architectures were found.
- Line 155: The script scripts/build-sign-upload.sh hardcodes derived data path
as build/ (occurrences around the file's references at the current hardcoded
instances) which conflicts with the workflow using build-universal/; update the
script to either (A) change those hardcoded paths to build-universal/ or (B) add
a configurable variable/parameter (e.g., DERIVED_DATA_PATH) at the top of
scripts/build-sign-upload.sh and replace the hardcoded occurrences (the three
hardcoded locations noted) with that variable so callers (including the
workflow) can pass build-universal/ when needed.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: b3136908-cb89-41b8-9ff2-3ebe4272dbf5
📒 Files selected for processing (1)
.github/workflows/release.yml
…anaflow-ai#2287) Match the nightly workflow's universal build approach so stable releases support both Apple Silicon and Intel Macs. Adds -destination, ARCHS, ONLY_ACTIVE_ARCH=NO flags and a post-build architecture verification step. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Summary
-destination 'generic/platform=macOS',ARCHS="arm64 x86_64", andONLY_ACTIVE_ARCH=NOto the xcodebuild commandbuild/tobuild-universal/for consistencyTest plan
workflow_dispatchon a test tag🤖 Generated with Claude Code
Summary by cubic
Update the stable release workflow to build a universal macOS app (arm64 + x86_64), matching nightly builds, and verify architectures before signing and notarization.
xcodebuildwith-destination 'generic/platform=macOS',ARCHS="arm64 x86_64", andONLY_ACTIVE_ARCH=NO.lipo -archsfor the app binary, CLI, and Ghostty helper.build/tobuild-universal/and update downstream steps (Sparkle plist, CLI test, helper check, codesign/notarize,sentry-cliupload).Written for commit 1a3cbcf. Summary will update on new commits.
Summary by CodeRabbit