-
Notifications
You must be signed in to change notification settings - Fork 382
feat(ios): radar network discovery and squircle cards onboarding #288
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
afc0cc4
347e578
fe7c4c8
fb9201d
58e0212
22bdec1
bc39718
2587d0f
304f7cc
aac77af
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,130 @@ | ||
| --- | ||
| name: windows-release | ||
| description: Build, verify, and publish the Windows desktop build (NSIS installer + latest.yml) to the openmausbot-releases repo. Use when cutting a release, shipping a new version to Windows users, or when a Windows user reports they are stuck on an old version. Windows only — does not cover the macOS dmg/notarization flow. | ||
| --- | ||
|
|
||
| # Windows release | ||
|
|
||
| Ships `OpenMausBot-<version>-setup.exe` and its update feed to | ||
| [milind-soni/openmausbot-releases](https://github.com/milind-soni/openmausbot-releases). | ||
|
|
||
| **Scope: Windows only.** The macOS build is a separate flow (dmg + notarytool + | ||
| staple) that must run on a Mac. This skill never touches mac artifacts — but see | ||
| [Every release ships both](#every-release-ships-both) before you finish. | ||
|
|
||
| ## Preconditions | ||
|
|
||
| - **Run on Windows.** NSIS packaging from macOS needs Wine; don't. | ||
| - **Node 24+** (`package.json` `engines`). Node 23 builds fine but pnpm warns on | ||
| every step and CI runs 24 — don't debug a runtime oddity on the wrong major. | ||
| - **pnpm** via `corepack pnpm`. If `corepack enable` fails with EPERM (no admin), | ||
| drop a `pnpm.cmd` shim containing `@echo off` / `corepack pnpm %*` somewhere on | ||
| PATH — `package:win` chains `pnpm build && …` and needs bare `pnpm` to resolve. | ||
|
|
||
| ## 1. Version | ||
|
|
||
| Bump `version` in `package.json`. It must match the tag on the GitHub release you | ||
| upload to, and it becomes the version electron-updater compares against. | ||
|
|
||
| ## 2. Build | ||
|
|
||
| ```powershell | ||
| pnpm install | ||
| pnpm typecheck | ||
| pnpm package:win | ||
| ``` | ||
|
|
||
| `package:win` deliberately omits `build:speech` — the dictation helper is a signed | ||
| macOS Swift binary and has no Windows counterpart. | ||
|
|
||
| Output in `release/`: | ||
|
|
||
| | File | Purpose | | ||
| |---|---| | ||
| | `OpenMausBot-<version>-setup.exe` | the installer | | ||
| | `latest.yml` | **the update feed** — see step 4 | | ||
| | `OpenMausBot-<version>-setup.exe.blockmap` | differential updates | | ||
| | `OpenMausBot-<version>-x64.zip` | portable, not used by the updater | | ||
|
|
||
| ## 3. Verify before uploading | ||
|
|
||
| Three things silently produce a broken app if wrong. Check all three: | ||
|
|
||
| ```powershell | ||
| Test-Path release\win-unpacked\resources\server\index.js # harness server | ||
| Test-Path release\win-unpacked\resources\ui\index.html # built UI | ||
| Get-Content release\win-unpacked\resources\app-update.yml # feed config | ||
| ``` | ||
|
|
||
| - Missing `server/index.js` → `utilityProcess.fork` fails → the 🐭 "Couldn't start | ||
| the bot server" page. | ||
| - Missing `ui/index.html` → server has nothing to serve → black window. | ||
| - `app-update.yml` must point at `milind-soni/openmausbot-releases` and, while the | ||
| build is unsigned, **must not contain `publisherName`** — electron-updater would | ||
| reject every update as untrusted. | ||
|
Comment on lines
+53
to
+64
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
node - <<'NODE'
const packageJson = require('./package.json');
console.log(
packageJson.devDependencies?.['electron-builder'] ??
packageJson.dependencies?.['electron-builder'] ??
'electron-builder is not declared in package.json'
);
NODE
rg -n 'electron-builder|signtoolOptions|azureSignOptions|win\.sign' \
package.json pnpm-lock.yaml electron-builder.ymlRepository: milind-soni/OpenMausBot Length of output: 2594 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- candidate files ---'
git ls-files \
.agents/skills/windows-release/SKILL.md \
.github/workflows/package-win.yml \
.github/workflows/release.yml \
package.json \
pnpm-lock.yaml \
electron-builder.yml
printf '%s\n' '--- SKILL.md relevant sections ---'
nl -ba .agents/skills/windows-release/SKILL.md | sed -n '35,75p;115,135p'
printf '%s\n' '--- workflow references ---'
rg -n -C 6 'win-unpacked|app-update\.yml|server/index\.js|ui/index\.html|publisherName|electron-builder|package:win|release' \
.github/workflows/package-win.yml .github/workflows/release.yml
printf '%s\n' '--- builder configuration ---'
nl -ba electron-builder.yml | sed -n '90,115p'Repository: milind-soni/OpenMausBot Length of output: 414 🏁 Script executed: #!/bin/bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
import re
skill = Path(".agents/skills/windows-release/SKILL.md").read_text()
block = re.search(r"```powershell\n(.*?)\n```", skill, re.S)
if not block:
raise SystemExit("PowerShell block not found")
commands = block.group(1)
print("--- documented PowerShell block ---")
print(commands)
print("--- command behavior checks ---")
for line in commands.splitlines():
stripped = line.strip()
if stripped.startswith("Test-Path "):
print(f"{stripped}: returns a Boolean; no terminating error on a missing path")
elif stripped.startswith("Get-Content "):
print(f"{stripped}: emits file contents; a missing path is non-terminating by default unless error handling changes")
PYRepository: milind-soni/OpenMausBot Length of output: 274 🏁 Script executed: #!/bin/bash
set -euo pipefail
numbered() {
awk '{ printf "%6d %s\n", NR, $0 }' "$1"
}
printf '%s\n' '--- SKILL.md relevant sections ---'
numbered .agents/skills/windows-release/SKILL.md | sed -n '35,75p;115,135p'
printf '%s\n' '--- workflow references ---'
rg -n -C 6 'win-unpacked|app-update\.yml|server/index\.js|ui/index\.html|publisherName|electron-builder|package:win|release' \
.github/workflows/package-win.yml .github/workflows/release.yml
printf '%s\n' '--- builder configuration ---'
numbered electron-builder.yml | sed -n '90,115p'Repository: milind-soni/OpenMausBot Length of output: 30922 🏁 Script executed: #!/bin/bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
import re
skill = Path(".agents/skills/windows-release/SKILL.md").read_text()
blocks = re.findall(r"```powershell\n(.*?)\n```", skill, re.S)
for i, block in enumerate(blocks, 1):
if any(token in block for token in ("Test-Path", "app-update.yml", "publisherName")):
print(f"--- matching PowerShell block {i} ---")
print(block)
print("--- behavior ---")
for line in block.splitlines():
stripped = line.strip()
if stripped.startswith("Test-Path "):
print(f"{stripped}: returns a Boolean and does not fail for a missing path")
elif stripped.startswith("Get-Content "):
print(f"{stripped}: displays file contents; missing-file behavior depends on PowerShell error handling")
PYRepository: milind-soni/OpenMausBot Length of output: 848 Make packaged-tree verification fail before publication.
The signing guidance is correct for the pinned 🤖 Prompt for AI AgentsSource: MCP tools |
||
|
|
||
| Then smoke-test the installer itself. Run it, and confirm: | ||
|
|
||
| 1. It installs per-user with no UAC prompt and launches. | ||
| 2. The chat window renders (not the error page). Server logs land in | ||
| `%APPDATA%\OpenMausBot\logs\server.log`. | ||
| 3. The model picker lists at least one provider — this exercises the `.cmd`-shim | ||
| resolution in `server/procs.ts`, which only ever runs for real on Windows. | ||
| 4. No update popup appears on launch. Background check failures are silent by | ||
| design; a popup here means that regressed. | ||
|
|
||
| ## 4. Publish | ||
|
|
||
| Upload to the **same tag** as the macOS release for that version, so one release | ||
| carries both platforms. | ||
|
|
||
| ```powershell | ||
| Copy-Item release/OpenMausBot-<version>-setup.exe release/OpenMausBot-setup.exe | ||
| gh release upload v<version> --repo milind-soni/openmausbot-releases ` | ||
| release/OpenMausBot-<version>-setup.exe ` | ||
| release/OpenMausBot-setup.exe ` | ||
| release/OpenMausBot-<version>-setup.exe.blockmap ` | ||
| release/latest.yml | ||
| ``` | ||
|
|
||
| Both names are required, for different consumers: | ||
|
|
||
| - **`OpenMausBot-<version>-setup.exe`** is what `latest.yml` references by name and | ||
| sha512. The auto-updater downloads exactly this. | ||
| - **`OpenMausBot-setup.exe`** is a byte-identical copy that gives the README's | ||
| `/releases/latest/download/OpenMausBot-setup.exe` button a stable URL. This | ||
| mirrors `OpenMausBot.dmg` sitting beside `OpenMausBot-<version>.dmg`. | ||
|
|
||
| ### latest.yml is not optional | ||
|
|
||
| Without it every installed Windows app 404s on check and stays on its version | ||
| forever. It is generated by `package:win` even under `--publish never`. | ||
|
|
||
| **Never hand-edit it or carry one forward from a previous build.** It pins the | ||
| installer's sha512; a mismatch makes the updater download and then reject the | ||
| update, which looks like "updates silently do nothing". | ||
|
|
||
| ## Every release ships both | ||
|
|
||
| A version that exists on macOS but not on this release is a Windows user stuck on | ||
| old code with no signal that anything is wrong — the updater reports "up to date" | ||
| because `latest.yml` still describes the older build. | ||
|
|
||
| So: **whenever a new version goes out, this flow runs too.** If Windows can't ship | ||
| for some reason, don't publish the mac-only release under a new version tag either | ||
| — or accept that Windows is knowingly frozen and say so in the release notes. | ||
|
|
||
| Because the two builds must run on two machines, the tag is the join point: cut the | ||
| release, attach mac artifacts from the Mac, attach Windows artifacts from here. | ||
|
|
||
| ## Known: the build is unsigned | ||
|
|
||
| No certificate is configured, so SmartScreen shows "unknown publisher" and users | ||
| click **More info → Run anyway**. The README documents this. Auto-update still | ||
| works *because* it's unsigned (no `publisherName` to verify against). | ||
|
|
||
| If signing is added later, it goes under `win.signtoolOptions` or | ||
| `win.azureSignOptions` in `electron-builder.yml` — electron-builder 26 nests these; | ||
| there is no top-level `win.certificateFile`. Once signed, keep the certificate | ||
| subject stable forever, or list both old and new in `publisherName`; changing it | ||
| strands every already-installed user. | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
Run the unified validation gate before packaging.
This skill runs
pnpm typecheckonly. The PR introducespnpm verifyas the repository validation gate, so this Windows release path can skip required checks. Runpnpm verifybeforepnpm package:win.Proposed change
📝 Committable suggestion
🤖 Prompt for AI Agents
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Clean generated outputs before packaging.
The Windows workflows remove
dist,dist-server, andreleasebeforepnpm package:win. This manual flow does not. Stale generated files can enter the installer and produce a broken packaged server or UI.Proposed change
pnpm install pnpm typecheck +Remove-Item -Recurse -Force dist, dist-server, release -ErrorAction SilentlyContinue pnpm package:win📝 Committable suggestion
🤖 Prompt for AI Agents