Skip to content

feat(desktop): embed AppImage update information and publish .zsync - #7533

Merged
jamesarich merged 1 commit into
mainfrom
feat/appimage-zsync
Oct 3, 2026
Merged

jamesarich merged 1 commit into
mainfrom
feat/appimage-zsync

Conversation

@jamesarich

@jamesarich jamesarich commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Release AppImages carry no update information, so AppImageUpdate, AppImageLauncher, AM and friends can't update them and every upgrade is a full download.

🌟 New Features

  • build-appimage.sh embeds gh-releases-zsync|meshtastic|Meshtastic-Android|latest|Meshtastic_Desktop-*-<arch>.AppImage.zsync when UPDATE_RELEASE_TAG is set, and fails if the .zsync is missing
  • release.yml sets UPDATE_RELEASE_TAG: latest and uploads and attests the .zsync next to each AppImage
  • Snapshot and PR builds embed nothing, so snapshot testers aren't offered the older stable release

latest skips prereleases, so an internal build that gets promoted points at itself and internal testers follow production.

Testing Performed

Ran the script against a stub app-image in an ubuntu:24.04 arm64 container: the release path writes Meshtastic_Desktop-2.8.4-aarch64.AppImage.zsync beside the AppImage with the string in .upd_info, and the snapshot path writes no .zsync and an empty .upd_info. appimagetool 1.9.1 bundles zsyncmake, so no extra package is needed. x86_64 can't run under macOS emulation, so its first run is the next release cut.

Fixes #7153

Summary by CodeRabbit

  • New Features
    • Linux AppImages now include update metadata and a companion .zsync file, enabling compatible tools to download updates more efficiently.
    • The .zsync files are included with desktop release artifacts and their provenance records.

Release AppImages now carry `gh-releases-zsync` update information
pointing at the latest release, and ship the matching `.zsync` so
AppImageUpdate and AppImage managers can delta-update them. Snapshot
and PR builds embed nothing.

Fixes #7153
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: meshtastic/Meshtastic-Android/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: eae0ef43-4a46-4ee2-a3f8-c8d2e2058af9
📥 Commits

Reviewing files that changed from the base of the PR and between 26d4532 and 043c2d9.

📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • scripts/build-appimage.sh

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The AppImage build script can configure GitHub release update metadata and produce .AppImage and .zsync outputs. The release workflow sets the update tag to latest and includes .AppImage.zsync in desktop artifact uploads and provenance attestations.

Changes

AppImage Update Assets

Layer / File(s) Summary
AppImage output and update metadata
scripts/build-appimage.sh
Output filenames replace spaces in the app name with underscores. When an update tag is set, the script configures update metadata using GITHUB_REPOSITORY or the default repository, packs from the output directory, and exits with an error if the expected .zsync file is missing.
Release workflow configuration and assets
.github/workflows/release.yml
The workflow sets UPDATE_RELEASE_TAG to latest and includes .AppImage.zsync in desktop artifact uploads and provenance attestations.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 043c2

Release AppImages now include architecture-specific update metadata and publish the matching .zsync assets. No actionable merge-blocking risk remains in the reviewed change.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 043c2

The update path remains tied to the release repository and architecture-specific assets, with existing build-integrity controls preserved. No introduced security bypass was established. Remaining uncertainty concerns how external updater clients authenticate executable updates and handle interrupted updates.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The new executable-selection path affects compatible updater clients using metadata-bearing Linux AppImages. Under the configured release path, influencing future selections would require control over the embedded build configuration or matching assets in the selected repository release. No new Android update path is introduced by these changes.

Trust Boundaries and Controls

  • observed — Producer controls include checksum-verified packing dependencies, checkout of the requested release tag, and successful-build provenance attestations for both files. These controls do not themselves demonstrate that external updater clients verify provenance before installing an executable; the documented verification path is through GitHub's interface.

Hardening Proposals

  • proposed — Document and validate the supported updater clients' executable-authentication and interrupted-update recovery behavior. Treat this as validation of the new integration contract, not as evidence that existing clients are vulnerable.
🚥 Pre-merge checks | ✅ 7 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Regression Coverage For Changed Behavior ⚠️ Warning Coverage gap: scripts/build-appimage.sh now selects update metadata from UPDATE_RELEASE_TAG, writes a .zsync, and fails when the file is missing. The release workflow sets latest and adds `.Ap… Add automated regression coverage for scripts/build-appimage.sh covering both UPDATE_RELEASE_TAG branches and the missing-.zsync failure case. Add an assertion that the release workflow upload and attestation patterns select the gener…
✅ Passed checks (7 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding update information to release AppImages and publishing matching .zsync files.
Linked Issues check ✅ Passed Issue #7153 requests AppImage update information and a .zsync file for delta updates. build-appimage.sh sets gh-releases-zsync metadata when UPDATE_RELEASE_TAG is set and checks that appimaget…
Out of Scope Changes check ✅ Passed All changed code supports issue #7153: the script creates and validates update metadata and the .zsync output, while the workflow configures the release target and distributes the file. No unrelated…
Sibling Call Sites And Presence Semantics ✅ Passed The diff adds no nullable application field, zero-guard change, or new numeric field defaulting to 0. Its only presence check is for the optional UPDATE_RELEASE_TAG environment variable in `scripts/…
Tests Prove The Path, Not The End State ✅ Passed No tests were added or changed in this pull request. The diff changes only .github/workflows/release.yml and scripts/build-appimage.sh, so the custom check does not apply.
Moved Code Diffed Against Its Original ✅ Passed The check does not apply. The authoritative diff modifies the AppImage build script and release workflow, but it does not delete and relocate a type or function, or extract code into a new file or mod…
Full details: Regression Coverage For Changed Behavior

Explanation

Coverage gap: scripts/build-appimage.sh now selects update metadata from UPDATE_RELEASE_TAG, writes a .zsync, and fails when the file is missing. The release workflow sets latest and adds .AppImage.zsync to artifact upload and provenance paths. These changes affect Linux desktop release artifacts. A regression in the tag string, output name or directory, missing-file check, or workflow glob could leave users without a usable delta update. The repository has no focused automated test for these paths. The PR packaging workflow invokes only the unset-tag path and does not assert metadata or artifact collection. Add a test that exercises both tag-set and tag-unset builds with a stub appimagetool, verifies the update arguments and expected .zsync output, verifies a missing .zsync fails the tagged build, and checks that the generated path matches both release upload and provenance patterns.

Resolution

Add automated regression coverage for scripts/build-appimage.sh covering both UPDATE_RELEASE_TAG branches and the missing-.zsync failure case. Add an assertion that the release workflow upload and attestation patterns select the generated .AppImage.zsync from the AppImage output directory.

  • Fix all pre-merge checks with AI
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added desktop Desktop target enhancement New feature or request repo Repository maintenance labels Oct 3, 2026
@jamesarich
jamesarich marked this pull request as ready for review October 3, 2026 15:08
@jamesarich
jamesarich added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 708d03e Oct 3, 2026
17 checks passed
@jamesarich
jamesarich deleted the feat/appimage-zsync branch October 3, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

desktop Desktop target enhancement New feature or request repo Repository maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature Request]: Linux: Embed AppImage update information

1 participant