feat(desktop): embed AppImage update information and publish .zsync - #7533
Conversation
Release AppImages now carry `gh-releases-zsync` update information pointing at the latest release, and ship the matching `.zsync` so AppImageUpdate and AppImage managers can delta-update them. Snapshot and PR builds embed nothing. Fixes #7153
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe AppImage build script can configure GitHub release update metadata and produce ChangesAppImage Update Assets
Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Release AppImages now include architecture-specific update metadata and publish the matching .zsync assets. No actionable merge-blocking risk remains in the reviewed change. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The update path remains tied to the release repository and architecture-specific assets, with existing build-integrity controls preserved. No introduced security bypass was established. Remaining uncertainty concerns how external updater clients authenticate executable updates and handle interrupted updates. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 7 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (7 passed)
Full details: Regression Coverage For Changed BehaviorExplanation Coverage gap: Resolution Add automated regression coverage for
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Release AppImages carry no update information, so AppImageUpdate, AppImageLauncher, AM and friends can't update them and every upgrade is a full download.
🌟 New Features
build-appimage.shembedsgh-releases-zsync|meshtastic|Meshtastic-Android|latest|Meshtastic_Desktop-*-<arch>.AppImage.zsyncwhenUPDATE_RELEASE_TAGis set, and fails if the.zsyncis missingrelease.ymlsetsUPDATE_RELEASE_TAG: latestand uploads and attests the.zsyncnext to each AppImagelatestskips prereleases, so an internal build that gets promoted points at itself and internal testers follow production.Testing Performed
Ran the script against a stub app-image in an
ubuntu:24.04arm64 container: the release path writesMeshtastic_Desktop-2.8.4-aarch64.AppImage.zsyncbeside the AppImage with the string in.upd_info, and the snapshot path writes no.zsyncand an empty.upd_info. appimagetool 1.9.1 bundleszsyncmake, so no extra package is needed. x86_64 can't run under macOS emulation, so its first run is the next release cut.Fixes #7153
Summary by CodeRabbit
.zsyncfile, enabling compatible tools to download updates more efficiently..zsyncfiles are included with desktop release artifacts and their provenance records.