From a8767583da9be0b3298ed4037553067c2158c66a Mon Sep 17 00:00:00 2001 From: Thore Cimbal Date: Fri, 31 Jul 2026 12:00:00 +0000 Subject: [PATCH] ci: verbliebene GitHub-Workflow-Dateien entfernt (CFGMON-11) Vollstaendig durch .gitlab-ci.yml ersetzt (Linux verifiziert gruen, Windows in Arbeit); Gitea Actions ist fuer dieses Repo deaktiviert, auf GitHub lag das Repo nie. Die Dateien bleiben als Uebersetzungsreferenz in der Git-Historie erhalten. Co-Authored-By: Claude Fable 5 --- .github/workflows/build-and-test.yaml | 128 -------- .github/workflows/build_desktop_linux.yaml | 265 ---------------- .github/workflows/build_desktop_macos.yaml | 234 -------------- .github/workflows/build_desktop_prepare.yaml | 197 ------------ .github/workflows/build_desktop_test.yaml | 118 ------- .github/workflows/build_desktop_windows.yaml | 314 ------------------- 6 files changed, 1256 deletions(-) delete mode 100644 .github/workflows/build-and-test.yaml delete mode 100644 .github/workflows/build_desktop_linux.yaml delete mode 100644 .github/workflows/build_desktop_macos.yaml delete mode 100644 .github/workflows/build_desktop_prepare.yaml delete mode 100644 .github/workflows/build_desktop_test.yaml delete mode 100644 .github/workflows/build_desktop_windows.yaml diff --git a/.github/workflows/build-and-test.yaml b/.github/workflows/build-and-test.yaml deleted file mode 100644 index e9ad89328..000000000 --- a/.github/workflows/build-and-test.yaml +++ /dev/null @@ -1,128 +0,0 @@ -# builds Element Web -# builds Element Desktop (Linux) using the built Element Web -# -# Tries to use a matching js-sdk branch for the build. -# -# Produces a `webapp` artifact -# Produces Desktop artifacts -# -# Fork-Anpassungen (siehe docs/axion1337-fork.md): -# - runs-on-Labels auf die tatsaechlich registrierten Runner-Labels gemappt -# (builder-1 auf CFGMON: ubuntu-latest, linux-build, win-wine - KEIN -# ubuntu-24.04, kein macOS, kein natives Windows). -# - playwright_ew/downstream-modules entfernt: brauchen Docker-Zugriff im -# Job-Container (Testcontainers) und Browser-Setups, die der aktuelle -# Runner nicht bereitstellt - als Folgearbeit in Issue #2 nachgehalten. -# - build_ed_windows entfernt: build_desktop_windows.yaml ist fuer native -# Windows-Runner geschrieben (signtool-Pfade, MSVC-Targets, PowerShell). -# Das win-wine-Runner-Label existiert fuer eine kuenftige Wine-basierte -# Variante, die aber einen eigenen Workflow braucht. -# - build_ed_macos entfernt: kein macOS-Runner vorhanden. -name: Build & Test -on: - # CRON to run all Projects at 6am UTC - schedule: - - cron: "0 6 * * *" - pull_request: {} - push: - branches: [main] - # workflow_call entfernt: nichts in diesem Repo ruft build-and-test.yaml per - # workflow_call auf (verifiziert), und die Kombination push+workflow_call im - # selben on:-Block triggert auf Gitea Actions 1.27 nicht zuverlaessig bei push - # (bekannter, als "not planned" geschlossener Gitea-Bug #33238). - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -env: - # fetchdep.sh needs to know our PR number - PR_NUMBER: ${{ github.event.pull_request.number }} - NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes - -permissions: {} # No permissions required - -jobs: - build_ew: - name: "Build Element Web" - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: ${{ github.repository }} - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - node-version: "lts/*" - - # Upstream nutzt hier scripts/layered.sh, das eine zum Branch passende - # matrix-js-sdk-Version klont - fuer diesen Fork falsch: es wuerde den - # bewusst gepinnten js-sdk-Stand aus pnpm-lock.yaml (Issue #12) mit - # Upstream-develop ueberschreiben. Der Lockfile-Stand ist hier autoritativ, - # genau wie im Produktions-Docker-Build. (Nebenbei: layered.sh braucht jq, - # das im node:20-Job-Container fehlt.) - - name: Install dependencies - run: pnpm install --frozen-lockfile - - - name: Copy config - working-directory: apps/web - run: cp element.io/develop/config.json config.json - - - name: Build - env: - CI_PACKAGE: true - working-directory: apps/web - run: VERSION=$(scripts/get-version-from-git.sh) pnpm run build - - - name: Upload Artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: webapp - path: apps/web/webapp - retention-days: 1 - - prepare_ed: - name: "Prepare Element Desktop" - uses: ./.github/workflows/build_desktop_prepare.yaml - needs: build_ew - permissions: - contents: read - with: - config: element.io/release - webapp-artifact: webapp - - build_ed_linux: - needs: prepare_ed - name: "Desktop Linux" - uses: ./.github/workflows/build_desktop_linux.yaml - with: - # Wir shippen static-sqlcipher-amd64-Builds; arm64/system-Varianten - # sind auf dem einzigen x86-Runner nicht sinnvoll baubar. - sqlcipher: static - arch: amd64 - runs-on: linux-build - # Desktop-Playwright-Tests brauchen Display-/Browser-Setup, das der - # Runner (noch) nicht bietet - gleiche Folgearbeit wie playwright_ew. - test: false - - complete: - name: build-complete - needs: - - build_ew - - prepare_ed - - build_ed_linux - if: always() - runs-on: ubuntu-latest - steps: - # Explizite Einzel-Checks statt contains(needs.*.result, ...): die - # Objekt-Filter-Syntax wertete auf Gitea/act falsch aus - das Gate war - # "success", obwohl build_ew fehlgeschlagen (und der Rest geskippt) war. - - name: Check all builds succeeded - run: | - [ "${{ needs.build_ew.result }}" = "success" ] || { echo "build_ew: ${{ needs.build_ew.result }}"; exit 1; } - [ "${{ needs.prepare_ed.result }}" = "success" ] || { echo "prepare_ed: ${{ needs.prepare_ed.result }}"; exit 1; } - [ "${{ needs.build_ed_linux.result }}" = "success" ] || { echo "build_ed_linux: ${{ needs.build_ed_linux.result }}"; exit 1; } diff --git a/.github/workflows/build_desktop_linux.yaml b/.github/workflows/build_desktop_linux.yaml deleted file mode 100644 index 436a5194e..000000000 --- a/.github/workflows/build_desktop_linux.yaml +++ /dev/null @@ -1,265 +0,0 @@ -# This workflow relies on actions/cache to store the hak dependency artifacts as they take a long time to build -# Due to this extra care must be taken to only ever run all build_* scripts against the same branch to ensure -# the correct cache scoping, and additional care must be taken to not run untrusted actions on the develop branch. -on: - workflow_call: - inputs: - ref: - type: string - required: false - description: "The git ref to checkout, defaults to the default branch" - arch: - type: string - required: true - description: "The architecture to build for, one of 'amd64' | 'arm64'" - version: - type: string - required: false - description: "Version string to override the one in package.json, used for non-release builds" - sqlcipher: - type: string - required: true - description: "How to link sqlcipher, one of 'system' | 'static'" - blob_report: - type: boolean - required: false - description: "Whether to run the blob report" - prepare-artifact-name: - type: string - required: false - description: | - The name of the prepare artifact to use, defaults to 'desktop-prepare'. - The artifact must contain the following: - + webapp.asar - the asar archive of the webapp to embed in the desktop app - + electronVersion - the version of electron to use for cache keying - + hakHash - the hash of the .hak directory to use for cache keying - + changelog.Debian - the changelog file to embed in the Debian package - + variant.json - the variant configuration to use for the build - - The artifact can also contain any additional files which will be applied as overrides to the checkout root before building, - for example icons in the `build/` directory to override the app icons. - default: "desktop-prepare" - test: - type: boolean - required: false - default: true - description: "Whether to run the test stage after building" - test-args: - type: string - required: false - description: "Additional arguments to pass to playwright" - runs-on: - type: string - required: false - description: "The runner image to use, normally set for you, may be needed for running in private repos." - artifact-prefix: - type: string - required: false - description: "An optional prefix to add to the artifact name, useful for distinguishing builds in private repos." - default: "" - targets: - type: string - required: false - description: "List of targets to build" - default: "tar.gz deb" -env: - SQLCIPHER_BUNDLED: ${{ inputs.sqlcipher == 'static' && '1' || '' }} - MAX_GLIBC: 2.31 # bullseye-era glibc, used by glibc-check.sh -permissions: {} # No permissions required -jobs: - build: - name: Build Linux ${{ inputs.arch }} SQLCipher ${{ inputs.sqlcipher }} - # We build on native infrastructure as matrix-seshat fails to cross-compile properly - # https://github.com/matrix-org/seshat/issues/135 - runs-on: ${{ inputs.runs-on || (inputs.arch == 'arm64' && 'ubuntu-22.04-arm' || 'ubuntu-22.04') }} - env: - HAK_DOCKER_IMAGE: ghcr.io/element-hq/element-web/desktop-build-env:${{ case(github.event_name == 'push', inputs.ref || github.ref_name, github.event_name == 'release', 'staging', 'develop') }} - steps: - - uses: nbucic/variable-mapper@0673f6891a0619ba7c002ecfed0f9f4f39017b6f - id: config - with: - key: "${{ inputs.arch }}" - export_to: output - map: | - { - "amd64": { - "arch": "x86-64" - }, - "arm64": { - "arch": "aarch64", - "build-args": "--arm64" - } - } - - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: element-hq/element-web - ref: ${{ inputs.ref }} - persist-credentials: false - - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - name: ${{ inputs.prepare-artifact-name }} - path: apps/desktop - - - name: Cache .hak - id: cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 - with: - key: ${{ runner.os }}-${{ github.ref_name }}-${{ inputs.sqlcipher }}-${{ inputs.arch }}-${{ hashFiles('apps/desktop/hakHash', 'apps/desktop/electronVersion', 'apps/desktop/dockerbuild/*') }} - path: | - apps/desktop/.hak - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version-file: apps/desktop/.node-version - cache: "pnpm" - env: - # Workaround for https://github.com/actions/setup-node/issues/317 - FORCE_COLOR: 0 - - - name: Install Deps - working-directory: apps/desktop - run: "pnpm install --frozen-lockfile --filter element-desktop" - - - name: "Get modified files" - id: changed_files - if: steps.cache.outputs.cache-hit != 'true' && github.event_name == 'pull_request' && github.repository == 'element-hq/element-web' - uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47 - with: - files: | - apps/desktop/dockerbuild/** - - # This allows contributors to test changes to the dockerbuild image within a pull request - - name: Build docker image - uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7 - if: steps.changed_files.outputs.any_modified == 'true' - with: - file: apps/desktop/dockerbuild/Dockerfile - context: apps/desktop - load: true - platforms: linux/${{ inputs.arch }} - tags: ${{ env.HAK_DOCKER_IMAGE }} - - - name: Build Natives - if: steps.cache.outputs.cache-hit != 'true' - run: | - docker run \ - -v ${{ github.workspace }}:/work -w /work \ - -e SQLCIPHER_BUNDLED \ - -e CI=1 \ - $HAK_DOCKER_IMAGE \ - pnpm -C apps/desktop run build:native - - - name: Fix permissions - run: | - # For .hak - sudo chown -R $USER:$USER apps/desktop/.hak - # For node_modules pnpm strict security - sudo chmod +x node_modules/7zip-bin/linux/*/7za - - - name: Check native libraries in hak dependencies - working-directory: apps/desktop - run: | - shopt -s globstar - - for filename in ./.hak/hakModules/**/*.node; do - ./scripts/glibc-check.sh $filename - done - - - name: Generate debian files and arguments - working-directory: apps/desktop - run: | - if [ -f changelog.Debian ]; then - echo "ED_DEBIAN_CHANGELOG=changelog.Debian" >> $GITHUB_ENV - fi - - - name: Build App - working-directory: apps/desktop - run: pnpm run build --publish never $BUILD_ARGS -l $TARGETS - env: - VARIANT_PATH: variant.json - # Only set for Nightly builds - VERSION: ${{ inputs.version }} - # Workaround for https://github.com/electron-userland/electron-builder/issues/5721 - USE_HARD_LINKS: false - BUILD_ARGS: ${{ steps.config.outputs.build-args }} - TARGETS: ${{ inputs.targets }} - - - name: Check native libraries - working-directory: apps/desktop - run: | - set -x - shopt -s globstar - - FILES=$(file dist/**/*.node) - echo $FILES - - ! echo "$FILES" | grep -v "$ARCH" - - LIBS=$(readelf -d dist/**/*.node | grep NEEDED) - echo "$LIBS" - - set +x - assert_contains_string() { [[ "$1" == *"$2"* ]]; } - ! assert_contains_string "$LIBS" "libcrypto.so.1.1" - if [ "$SQLCIPHER_BUNDLED" == "1" ]; then - ! assert_contains_string "$LIBS" "libsqlcipher.so.0" - else - assert_contains_string "$LIBS" "libsqlcipher.so.0" - fi - - ./scripts/glibc-check.sh dist/linux-*unpacked/element-desktop* - env: - ARCH: ${{ steps.config.outputs.arch }} - - # We exclude *-unpacked as it loses permissions and the tarball contains it with correct permissions - - name: Upload Artifacts - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: ${{ inputs.artifact-prefix }}linux-${{ inputs.arch }}-sqlcipher-${{ inputs.sqlcipher }} - path: | - apps/desktop/dist - !apps/desktop/dist/*-unpacked/** - retention-days: 1 - - - name: Assert deb is present and valid - if: contains(inputs.targets, 'deb') - working-directory: apps/desktop - run: | - test -f ./dist/element-desktop*$ARCH.deb - - DEB_LISTING=$(dpkg-deb --fsys-tarfile ./dist/element-desktop*.deb | tar -tv) - echo "deb listing: " - echo "$DEB_LISTING" - ! echo "$DEB_LISTING" | grep '^h' - env: - ARCH: ${{ inputs.arch }} - - - name: Assert tar.gz is present - if: contains(inputs.targets, 'tar.gz') - working-directory: apps/desktop - run: | - test -f ./dist/element-desktop*.tar.gz - - TAR_GZ_LISTING=$(tar -tvf ./dist/element-desktop*.tar.gz) - echo "tar.gz listing: " - echo "$TAR_GZ_LISTING" - ! echo "$TAR_GZ_LISTING" | grep '^h' - - test: - name: Test Linux ${{ inputs.arch }} SQLCipher ${{ inputs.sqlcipher }} - needs: build - if: inputs.test && contains(inputs.targets, 'deb') - uses: ./.github/workflows/build_desktop_test.yaml - with: - project: linux-${{ inputs.arch }}-sqlcipher-${{ inputs.sqlcipher }} - artifact: ${{ inputs.artifact-prefix }}linux-${{ inputs.arch }}-sqlcipher-${{ inputs.sqlcipher }} - runs-on: ${{ inputs.runs-on || (inputs.arch == 'arm64' && 'ubuntu-22.04-arm' || 'ubuntu-22.04') }} - executable: /opt/Element*/element-desktop* - prepare_cmd: | - sudo apt-get -qq update - sudo apt install ./dist/*.deb - blob_report: ${{ inputs.blob_report }} - args: ${{ inputs.test-args }} diff --git a/.github/workflows/build_desktop_macos.yaml b/.github/workflows/build_desktop_macos.yaml deleted file mode 100644 index a32f674cf..000000000 --- a/.github/workflows/build_desktop_macos.yaml +++ /dev/null @@ -1,234 +0,0 @@ -# This workflow relies on actions/cache to store the hak dependency artifacts as they take a long time to build -# Due to this extra care must be taken to only ever run all build_* scripts against the same branch to ensure -# the correct cache scoping, and additional care must be taken to not run untrusted actions on the develop branch. -on: - workflow_call: - secrets: - APPLE_ID: - required: false - APPLE_ID_PASSWORD: - required: false - APPLE_CSC_KEY_PASSWORD: - required: false - APPLE_CSC_LINK: - required: false - inputs: - ref: - type: string - required: false - description: "The git ref to checkout, defaults to the default branch" - version: - type: string - required: false - description: "Version string to override the one in package.json, used for non-release builds" - sign: - type: string - required: false - description: "Whether to sign & notarise the build, requires 'Desktop Apple' environment" - base-url: - type: string - required: false - description: "The URL to which the output will be deployed." - blob_report: - type: boolean - required: false - description: "Whether to run the blob report" - prepare-artifact-name: - type: string - required: false - description: | - The name of the prepare artifact to use, defaults to 'desktop-prepare'. - The artifact must contain the following: - + webapp.asar - the asar archive of the webapp to embed in the desktop app - + electronVersion - the version of electron to use for cache keying - + hakHash - the hash of the .hak directory to use for cache keying - + variant.json - the variant configuration to use for the build - - The artifact can also contain any additional files which will be applied as overrides to the checkout root before building, - for example icons in the `build/` directory to override the app icons. - default: "desktop-prepare" - test: - type: boolean - required: false - default: true - description: "Whether to run the test stage after building" - test-args: - type: string - required: false - description: "Additional arguments to pass to playwright" - artifact-prefix: - type: string - required: false - description: "An optional prefix to add to the artifact name, useful for distinguishing builds in private repos." - default: "" - targets: - type: string - required: false - description: "List of targets to build" - default: "dmg zip" -permissions: {} # No permissions required -jobs: - build: - name: Build macOS Universal - runs-on: macos-15 # M1 - environment: ${{ inputs.sign && 'Desktop Apple' || '' }} - steps: - - uses: maxim-lobanov/setup-xcode@ed7a3b1fda3918c0306d1b724322adc0b8cc0a90 # v1 - with: - xcode-version: latest-stable - - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: element-hq/element-web - ref: ${{ inputs.ref }} - persist-credentials: false - - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - name: ${{ inputs.prepare-artifact-name }} - path: apps/desktop - - - name: Cache .hak - id: cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 - with: - key: ${{ runner.os }}-${{ hashFiles('apps/desktop/hakHash', 'apps/desktop/electronVersion') }} - path: | - apps/desktop/.hak - - - name: Install Rust - if: steps.cache.outputs.cache-hit != 'true' - run: | - rustup toolchain install stable --profile minimal --no-self-update - rustup default stable - rustup target add aarch64-apple-darwin - rustup target add x86_64-apple-darwin - - # M1 macos-14 comes without Python preinstalled - - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6 - with: - python-version: "3.13" - - # Install Quartz for DMG badges - # https://github.com/electron-userland/electron-builder/issues/9511#issuecomment-3774092888 - - run: sudo pip3 install pyobjc-framework-Quartz - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version-file: apps/desktop/.node-version - cache: "pnpm" - - - name: Install Deps - working-directory: apps/desktop - run: "pnpm install --frozen-lockfile --filter element-desktop" - - - name: Build Natives - if: steps.cache.outputs.cache-hit != 'true' - working-directory: apps/desktop - run: pnpm run build:native:universal - - # We split these because electron-builder gets upset if we set CSC_LINK even to an empty string - - name: "[Signed] Build App" - if: inputs.sign != '' - working-directory: apps/desktop - run: | - pnpm run build:universal --publish never -m ${TARGETS} - env: - APPLE_TEAM_ID: ${{ vars.APPLE_TEAM_ID }} - APPLE_ID: ${{ secrets.APPLE_ID }} - APPLE_APP_SPECIFIC_PASSWORD: ${{ secrets.APPLE_ID_PASSWORD }} - CSC_KEY_PASSWORD: ${{ secrets.APPLE_CSC_KEY_PASSWORD }} - CSC_LINK: ${{ secrets.APPLE_CSC_LINK }} - VARIANT_PATH: variant.json - # Only set for Nightly builds - VERSION: ${{ inputs.version }} - TARGETS: ${{ inputs.targets }} - - - name: Check app was signed & notarised successfully - if: inputs.sign != '' - working-directory: apps/desktop - run: | - hdiutil attach dist/*.dmg -mountpoint /Volumes/Element - codesign -dv --verbose=4 /Volumes/Element/*.app - spctl -a -vvv -t install /Volumes/Element/*.app - hdiutil detach /Volumes/Element - - - name: "[Unsigned] Build App" - if: inputs.sign == '' - working-directory: apps/desktop - run: | - pnpm run build:universal --publish never -m ${TARGETS} - env: - CSC_IDENTITY_AUTO_DISCOVERY: false - VARIANT_PATH: variant.json - TARGETS: ${{ inputs.targets }} - - - name: Generate releases.json - if: inputs.base-url - working-directory: apps/desktop - run: | - PKG_JSON_VERSION=$(cat package.json | jq -r .version) - LATEST=$(find dist -type f -iname "*-mac.zip" | xargs -0 -n1 -- basename) - # Encode spaces in the URL as Squirrel.Mac complains about bad JSON otherwise - URL="${BASE_URL}/update/macos/${LATEST// /%20}" - - jq -n --arg version "${VERSION:-$PKG_JSON_VERSION}" --arg url "$URL" ' - { - currentRelease: $version, - releases: [{ - version: $version, - updateTo: { - version: $version, - url: $url, - }, - }], - } - ' > dist/releases.json - jq -n --arg url "$URL" ' - { url: $url } - ' > dist/releases-legacy.json - env: - VERSION: ${{ inputs.version }} - BASE_URL: ${{ inputs.base-url }} - - # We exclude mac-universal as the unpacked app takes forever to upload and zip and dmg already contains it - - name: Upload Artifacts - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: ${{ inputs.artifact-prefix }}macos - path: | - apps/desktop/dist - !apps/desktop/dist/mac-universal/** - retention-days: 1 - - - name: Assert zip is present - if: contains(inputs.targets, 'zip') - working-directory: apps/desktop - run: | - test -f ./dist/Element*-mac.zip - - - name: Assert dmg is present - if: contains(inputs.targets, 'dmg') - working-directory: apps/desktop - run: | - test -f ./dist/Element*.dmg - - test: - name: Test macOS Universal - needs: build - if: inputs.test && contains(inputs.targets, 'dmg') - uses: ./.github/workflows/build_desktop_test.yaml - with: - project: macos - artifact: ${{ inputs.artifact-prefix }}macos - runs-on: macos-14 - executable: /Users/runner/Applications/Element*.app/Contents/MacOS/Element* - # We need to mount the DMG and copy the app to the Applications folder as a mounted DMG is - # read-only and thus would not allow us to override the fuses as is required for Playwright. - prepare_cmd: | - hdiutil attach ./dist/*.dmg -mountpoint /Volumes/Element && - rsync -a /Volumes/Element/Element*.app ~/Applications/ && - hdiutil detach /Volumes/Element - blob_report: ${{ inputs.blob_report }} - args: ${{ inputs.test-args }} diff --git a/.github/workflows/build_desktop_prepare.yaml b/.github/workflows/build_desktop_prepare.yaml deleted file mode 100644 index a0cc9a737..000000000 --- a/.github/workflows/build_desktop_prepare.yaml +++ /dev/null @@ -1,197 +0,0 @@ -# This action helps perform common actions before the build_* actions are started in parallel. -on: - workflow_call: - inputs: - config: - type: string - required: true - description: "The config directory to use" - version: - type: string - required: false - description: "The version tag to fetch, or 'develop', will pick automatically if not passed" - nightly: - type: boolean - required: false - default: false - description: "Whether the build is a Nightly and to calculate the version strings new builds should use" - deploy: - type: boolean - required: false - default: false - description: "Whether the build should be deployed to production" - webapp-artifact: - type: string - required: false - description: "Name of the webapp artifact that should be used, will fetch a relevant build if omitted" - secrets: - # Required if `nightly` is set - CF_R2_ACCESS_KEY_ID: - required: false - # Required if `nightly` is set - CF_R2_TOKEN: - required: false - outputs: - nightly-version: - description: "The version string the next Nightly should use, only output for nightly" - value: ${{ jobs.prepare.outputs.nightly-version }} - packages-dir: - description: "The directory non-deb packages for this run should live in within packages.element.io" - value: ${{ inputs.nightly && 'nightly' || 'desktop' }} - # This is just a simple pass-through of the input to simplify reuse of complex inline conditions - deploy: - description: "Whether the build should be deployed to production" - value: ${{ inputs.deploy }} -permissions: {} -jobs: - prepare: - name: Prepare - environment: ${{ inputs.nightly && 'packages.element.io' || '' }} - runs-on: ubuntu-latest # builder-1 hat kein ubuntu-24.04-Label - permissions: - contents: read - outputs: - nightly-version: ${{ steps.versions.outputs.nightly }} - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - repository: ${{ github.repository }} - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version-file: apps/desktop/.node-version - cache: "pnpm" - - - name: Install Deps - working-directory: apps/desktop - run: "pnpm install --frozen-lockfile --filter element-desktop" - - - name: Fetch Element Web (from artifact) - if: inputs.webapp-artifact != '' - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - name: ${{ inputs.webapp-artifact }} - path: apps/desktop/webapp - - - name: Build webapp.asar (from artifact) - if: inputs.webapp-artifact != '' - working-directory: apps/desktop - run: | - cp -f "$CONFIG_DIR/config.json" webapp/config.json - pnpm run asar-webapp - env: - CONFIG_DIR: ${{ inputs.config }} - - - name: Fetch Element Web (${{ inputs.version }}) - if: inputs.webapp-artifact == '' - working-directory: apps/desktop - run: pnpm run fetch --noverify -d ${CONFIG} ${VERSION} - env: - CONFIG: ${{ inputs.config }} - VERSION: ${{ inputs.version }} - - - name: Copy variant config - working-directory: apps/desktop - run: cp "$CONFIG_DIR/build.json" variant.json - env: - CONFIG_DIR: ${{ inputs.config }} - - # We split this out to save the build_* scripts having to do it to make use of `hashFiles` in the cache action - - name: Generate cache hash files - working-directory: apps/desktop - run: | - set -ex - # Add --no-sandbox as otherwise it fails because the helper isn't setuid root. It's only getting the version. - pnpm --silent electron --no-sandbox --version > electronVersion - cat package.json | jq -c .hakDependencies | sha1sum > hakHash - find hak -type f -print0 | xargs -0 sha1sum >> hakHash - find scripts/hak -type f -print0 | xargs -0 sha1sum >> hakHash - - - name: "[Nightly] Calculate version" - id: versions - if: inputs.nightly - working-directory: apps/desktop - run: | - set -e - - # Find all latest Nightly versions - aws s3 cp s3://$R2_BUCKET/nightly/update/macos/releases.json - --endpoint-url $R2_URL --region auto | jq -r .currentRelease >> VERSIONS - aws s3 cp s3://$R2_BUCKET/debian/dists/default/main/binary-amd64/Packages - --endpoint-url $R2_URL --region auto | grep "Package: element-nightly" -A 50 | grep Version -m1 | sed -n 's/Version: //p' >> VERSIONS - aws s3 cp s3://$R2_BUCKET/debian/dists/default/main/binary-arm64/Packages - --endpoint-url $R2_URL --region auto | grep "Package: element-nightly" -A 50 | grep Version -m1 | sed -n 's/Version: //p' >> VERSIONS - aws s3 cp s3://$R2_BUCKET/nightly/update/win32/x64/RELEASES - --endpoint-url $R2_URL --region auto | awk '{print $2}' | cut -d "-" -f 5 | cut -c 8- >> VERSIONS - aws s3 cp s3://$R2_BUCKET/nightly/update/win32/arm64/RELEASES - --endpoint-url $R2_URL --region auto | awk '{print $2}' | cut -d "-" -f 5 | cut -c 8- >> VERSIONS - - # Pick the greatest one - VERSION=$(cat VERSIONS | sort -uf | tail -n1) - echo "Found latest nightly version $VERSION" - # Increment it - echo "nightly=$(scripts/generate-nightly-version.ts --latest $VERSION)" >> $GITHUB_OUTPUT - env: - AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }} - R2_BUCKET: ${{ vars.R2_BUCKET }} - R2_URL: ${{ vars.CF_R2_S3_API }} - - - name: Check version - id: package - working-directory: apps/desktop - run: | - echo "version=$(cat package.json | jq -r .version)" >> $GITHUB_OUTPUT - - - name: "[Release] Fetch release" - id: release - if: ${{ !inputs.nightly && inputs.version != 'develop' }} - uses: cardinalby/git-get-release-action@5172c3a026600b1d459b117738c605fabc9e4e44 # 1.2.5 - env: - GITHUB_TOKEN: ${{ github.token }} - with: - tag: v${{ steps.package.outputs.version }} - - - name: "[Release] Write changelog" - if: ${{ !inputs.nightly && inputs.version != 'develop' }} - working-directory: apps/desktop - run: | - TIME=$(date -d "$PUBLISHED_AT" -R) - echo "element-desktop ($VERSION) default; urgency=medium" >> changelog.Debian - echo "$BODY" | sed 's/^##/\n */g;s/^\*/ */g' | perl -pe 's/\[.+?]\((.+?)\)/\1/g' >> changelog.Debian - echo "" >> changelog.Debian - echo " -- $ACTOR $TIME" >> changelog.Debian - env: - ACTOR: ${{ github.actor }} - VERSION: v${{ steps.package.outputs.version }} - BODY: ${{ steps.release.outputs.body }} - PUBLISHED_AT: ${{ steps.release.outputs.published_at }} - - - name: "[Nightly] Write summary" - if: inputs.nightly - working-directory: apps/desktop - run: | - set -e - - BUNDLE_HASH=$(npx asar l webapp.asar | grep /bundles/ | head -n 1 | sed 's|.*/||') - WEBAPP_VERSION=$(./scripts/get-version.ts) - WEB_VERSION=${WEBAPP_VERSION:0:12} - JS_VERSION=${WEBAPP_VERSION:16:12} - - echo "### Nightly build ${NIGHTLY_VERSION}" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "| Component | Version |" >> $GITHUB_STEP_SUMMARY - echo "| ----------- | ------- |" >> $GITHUB_STEP_SUMMARY - echo "| Bundle Hash | $BUNDLE_HASH |" >> $GITHUB_STEP_SUMMARY - echo "| Element Web | [$WEB_VERSION](https://github.com/element-hq/element-web/commit/$WEB_VERSION) |" >> $GITHUB_STEP_SUMMARY - echo "| JS SDK | [$JS_VERSION](https://github.com/matrix-org/matrix-js-sdk/commit/$JS_VERSION) |" >> $GITHUB_STEP_SUMMARY - env: - NIGHTLY_VERSION: ${{ steps.versions.outputs.nightly }} - - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: desktop-prepare - retention-days: 1 - path: | - apps/desktop/webapp.asar - apps/desktop/electronVersion - apps/desktop/hakHash - apps/desktop/changelog.Debian - apps/desktop/variant.json diff --git a/.github/workflows/build_desktop_test.yaml b/.github/workflows/build_desktop_test.yaml deleted file mode 100644 index 1ec6d7bf7..000000000 --- a/.github/workflows/build_desktop_test.yaml +++ /dev/null @@ -1,118 +0,0 @@ -# This action helps run Playwright tests within one of the build_* stages. -on: - workflow_call: - inputs: - runs-on: - type: string - required: true - description: "The runner image to use" - artifact: - type: string - required: true - description: "The name of the artifact to download" - project: - type: string - required: true - description: "The Playwright project to use for testing" - executable: - type: string - required: true - description: "Path to the executable to test" - prepare_cmd: - type: string - required: false - description: "Command to run to prepare the executable or environment for testing" - blob_report: - type: boolean - default: false - description: "Whether to upload a blob report instead of the HTML report" - args: - type: string - required: false - description: "Additional arguments to pass to playwright, for e.g. skipping specific tests" -permissions: {} -jobs: - test: - name: Test ${{ inputs.project }} - runs-on: ${{ inputs.runs-on }} - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: element-hq/element-web - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version-file: apps/desktop/.node-version - cache: "pnpm" - - - name: Install Deps - run: "pnpm install --frozen-lockfile --filter element-desktop" - - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - name: ${{ inputs.artifact }} - path: apps/desktop/dist - - - name: Prepare for tests - working-directory: apps/desktop - # This is set by the caller of the reusable workflow, they have the ability to run the command they specify - # directly without our help so this is fine. - run: ${{ inputs.prepare_cmd }} # zizmor: ignore[template-injection] - if: inputs.prepare_cmd - - - name: Expand executable path - id: executable - working-directory: apps/desktop - shell: bash - env: - EXECUTABLE: ${{ inputs.executable }} - run: | - FILES=($EXECUTABLE) - echo "path=${FILES[0]}" >> $GITHUB_OUTPUT - - # We previously disabled the `EnableNodeCliInspectArguments` fuse, but Playwright requires - # it to be enabled to test Electron apps, so turn it back on. - - name: Set EnableNodeCliInspectArguments fuse enabled - run: $RUN_AS npx @electron/fuses write --app "$EXECUTABLE" EnableNodeCliInspectArguments=on - working-directory: apps/desktop - shell: bash - env: - # We need sudo on Linux as it is installed in /opt/ - RUN_AS: ${{ runner.os == 'Linux' && 'sudo' || '' }} - EXECUTABLE: ${{ steps.executable.outputs.path }} - - - name: Run tests - timeout-minutes: 20 - shell: bash - working-directory: apps/desktop - run: | - $PREFIX pnpm playwright test \ - ${{ runner.os != 'Linux' && '--ignore-snapshots' || '' }} \ - ${{ inputs.blob_report == false && '--reporter=html' || '' }} \ - $ARGS - env: - PREFIX: ${{ runner.os == 'Linux' && 'xvfb-run' || '' }} - PW_TAG: ${{ inputs.project }} - ELEMENT_DESKTOP_EXECUTABLE: ${{ steps.executable.outputs.path }} - ARGS: ${{ inputs.args }} - DEBUG: pw:browser - - - name: Upload blob report - if: always() && inputs.blob_report - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: blob-report-${{ inputs.artifact }} - path: apps/desktop/blob-report - retention-days: 1 - if-no-files-found: error - - - name: Upload HTML report - if: always() && inputs.blob_report == false - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: ${{ inputs.artifact }}-test - path: apps/desktop/playwright-report - retention-days: 14 - if-no-files-found: error diff --git a/.github/workflows/build_desktop_windows.yaml b/.github/workflows/build_desktop_windows.yaml deleted file mode 100644 index 2cbaef9c8..000000000 --- a/.github/workflows/build_desktop_windows.yaml +++ /dev/null @@ -1,314 +0,0 @@ -# This workflow relies on actions/cache to store the hak dependency artifacts as they take a long time to build -# Due to this extra care must be taken to only ever run all build_* scripts against the same branch to ensure -# the correct cache scoping, and additional care must be taken to not run untrusted actions on the develop branch. - -# Windows GHA runner by default uses the pwsh shell which breaks codeSigningCert in the workflow -# We always sign using eSignerCKA to ensure it keeps working, but aside from release & nightlies we use demo credentials -# which do not yield trusted signatures. -defaults: - run: - shell: powershell -on: - workflow_call: - secrets: - ESIGNER_USER_NAME: - required: false - ESIGNER_USER_PASSWORD: - required: false - ESIGNER_USER_TOTP: - required: false - inputs: - ref: - type: string - required: false - description: "The git ref to checkout, defaults to the default branch" - arch: - type: string - required: true - description: "The architecture to build for, one of 'x64' | 'ia32' | 'arm64'" - version: - type: string - required: false - description: "Version string to override the one in package.json, used for non-release builds" - sign: - type: string - required: false - description: "Whether to sign & notarise the build, requires 'Desktop eSigner' environment" - blob_report: - type: boolean - required: false - description: "Whether to run the blob report" - prepare-artifact-name: - type: string - required: false - description: | - The name of the prepare artifact to use, defaults to 'desktop-prepare'. - The artifact must contain the following: - + webapp.asar - the asar archive of the webapp to embed in the desktop app - + electronVersion - the version of electron to use for cache keying - + hakHash - the hash of the .hak directory to use for cache keying - + variant.json - the variant configuration to use for the build - - - The artifact can also contain any additional files which will be applied as overrides to the checkout root before building, - for example icons in the `build/` directory to override the app icons. - default: "desktop-prepare" - test: - type: boolean - required: false - default: true - description: "Whether to run the test stage after building" - test-runs-on: - type: string - required: false - description: "The runner image to use for testing, normally set for you, may be needed for running in private repos." - test-args: - type: string - required: false - description: "Additional arguments to pass to playwright" - artifact-prefix: - type: string - required: false - description: "An optional prefix to add to the artifact name, useful for distinguishing builds in private repos." - default: "" - targets: - type: string - required: false - description: "List of targets to build" - default: "squirrel msi" -permissions: {} # No permissions required -jobs: - build: - name: Build Windows ${{ inputs.arch }} - runs-on: windows-2025 - environment: ${{ inputs.sign && 'Desktop eSigner' || '' }} - env: - SIGNTOOL_PATH: "C:/Program Files (x86)/Windows Kits/10/bin/10.0.26100.0/x86/signtool.exe" - steps: - - uses: nbucic/variable-mapper@0673f6891a0619ba7c002ecfed0f9f4f39017b6f - id: config - with: - key: "${{ inputs.arch }}" - export_to: output - map: | - { - "x64": { - "target": "x86_64-pc-windows-msvc" - }, - "arm64": { - "target": "aarch64-pc-windows-msvc", - "build-args": "--arm64", - "arch": "amd64_arm64" - }, - "ia32": { - "target": "i686-pc-windows-msvc", - "build-args": "--ia32", - "arch": "x86", - "extra_config": "{\"user_notice\": {\"title\": \"Your desktop environment is unsupported.\",\"description\": \"Support for 32-bit Windows installations has ended. Transition to the web or mobile app for continued access.\"}}" - } - } - - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: element-hq/element-web - ref: ${{ inputs.ref }} - persist-credentials: false - - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - name: ${{ inputs.prepare-artifact-name }} - path: apps/desktop/ - - - name: Cache .hak - id: cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 - with: - key: ${{ runner.os }}-${{ inputs.arch }}-${{ hashFiles('apps/desktop/hakHash', 'apps/desktop/electronVersion') }} - path: | - apps/desktop/.hak - - # ActiveTCL package on choco is from 2015, - # this one is newer but includes more than we need - - name: Choco install tclsh - if: steps.cache.outputs.cache-hit != 'true' - shell: pwsh - run: | - choco install -y magicsplat-tcl-tk --no-progress - echo "${HOME}/AppData/Local/Apps/Tcl86/bin" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - - - name: Choco install NetWide Assembler - if: steps.cache.outputs.cache-hit != 'true' - shell: pwsh - run: | - choco install -y nasm --no-progress - echo "C:/Program Files/NASM" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - - - name: Install Rust - if: steps.cache.outputs.cache-hit != 'true' - run: | - rustup toolchain install stable --profile minimal --no-self-update - rustup default stable - rustup target add $env:TARGET - env: - TARGET: ${{ steps.config.outputs.target }} - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version-file: apps/desktop/.node-version - cache: "pnpm" - - - name: Install Deps - working-directory: apps/desktop - run: "pnpm install --frozen-lockfile --filter element-desktop" - - - name: Insert config snippet - if: steps.config.outputs.extra_config != '' - working-directory: apps/desktop - shell: bash - run: | - mkdir config-edit - pnpm asar extract webapp.asar config-edit - cd config-edit - mv config.json old-config.json - echo '${{ steps.config.outputs.extra_config }}' | jq -s '.[0] * .[1]' old-config.json - > config.json - rm old-config.json - cd .. - rm webapp.asar - pnpm asar pack config-edit/ webapp.asar - - - name: Set up sqlcipher macros - if: steps.cache.outputs.cache-hit != 'true' && contains(inputs.arch, 'arm') - shell: pwsh - run: | - echo "NCC=${{ github.workspace }}\scripts\cl.bat" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - - name: Set up build tools - if: steps.cache.outputs.cache-hit != 'true' - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 - with: - arch: ${{ steps.config.outputs.arch || inputs.arch }} - - - name: Build Natives - if: steps.cache.outputs.cache-hit != 'true' - working-directory: apps/desktop - run: | - refreshenv - pnpm run build:native --target $env:TARGET - env: - TARGET: ${{ steps.config.outputs.target }} - - - name: Install and configure eSigner CKA - run: | - Set-StrictMode -Version 'Latest' - - # Download, extract, and rename - Invoke-WebRequest -OutFile eSigner_CKA.zip "$env:ESIGNER_URL" - Expand-Archive -Path eSigner_CKA.zip -DestinationPath . - Get-ChildItem -Path * -Include "*_build_*.exe" | Rename-Item -NewName eSigner_CKA.exe - - # Install - New-Item -ItemType Directory -Force -Path "$env:INSTALL_DIR" - ./eSigner_CKA.exe /CURRENTUSER /VERYSILENT /SUPPRESSMSGBOXES /DIR="${{ env.INSTALL_DIR }}" | Out-Null - - # Disable logger - $LogConfig = Get-Content -Path ${{ env.INSTALL_DIR }}/log4net.config - $LogConfig[0] = '' - $LogConfig | Set-Content -Path ${{ env.INSTALL_DIR }}/log4net.config - - # Configure - default credentials from https://www.ssl.com/guide/esigner-demo-credentials-and-certificates/ - ${{ env.INSTALL_DIR }}/eSignerCKATool.exe config ` - -mode "$env:ESIGNER_MODE" ` - -user "${{ secrets.ESIGNER_USER_NAME || 'esigner_demo' }}" ` - -pass "${{ secrets.ESIGNER_USER_PASSWORD || 'esignerDemo#1' }}" ` - -totp "${{ secrets.ESIGNER_USER_TOTP || 'RDXYgV9qju+6/7GnMf1vCbKexXVJmUVr+86Wq/8aIGg=' }}" ` - -key "${{ env.MASTER_KEY_FILE }}" -r - ${{ env.INSTALL_DIR }}/eSignerCKATool.exe unload - ${{ env.INSTALL_DIR }}/eSignerCKATool.exe load - - # Find certificate - $CodeSigningCert = Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert | Select-Object -First 1 - echo Certificate: $CodeSigningCert - - # Extract thumbprint and subject name - $Thumbprint = $CodeSigningCert.Thumbprint - $SubjectName = ($CodeSigningCert.Subject -replace ", ?", "`n" | ConvertFrom-StringData).CN - - echo "ED_SIGNTOOL_THUMBPRINT=$Thumbprint" >> $env:GITHUB_ENV - echo "ED_SIGNTOOL_SUBJECT_NAME=$SubjectName" >> $env:GITHUB_ENV - env: - ESIGNER_MODE: ${{ vars.ESIGNER_MODE || 'sandbox' }} - ESIGNER_URL: https://github.com/SSLcom/eSignerCKA/releases/download/v1.0.6/SSL.COM-eSigner-CKA_1.0.6.zip - INSTALL_DIR: C:\Users\runneradmin\eSignerCKA - MASTER_KEY_FILE: C:\Users\runneradmin\eSignerCKA\master.key - - - name: Build App - working-directory: apps/desktop - run: pnpm run build --publish never $BUILD_ARGS -w $TARGETS - shell: bash - env: - VARIANT_PATH: variant.json - # Only set for Nightly builds - # The windows packager relies on parsing this as semver, so we have to make it look like one. - # This will give our update packages really stupid names, but we probably can't change that either - # because squirrel windows parses them for the version too. We don't really care: nobody sees them. - # We just give the installer a static name, so you'll just see this in the 'about' dialog. - # Turns out if you use 0.0.0 here it makes Squirrel windows crash, so we use 0.0.1. - VERSION: ${{ inputs.version && format('0.0.1-nightly.{0}', inputs.version) || '' }} - BUILD_ARGS: ${{ steps.config.outputs.build-args }} - TARGETS: ${{ inputs.targets }} - - - name: Trust eSigner sandbox cert - if: inputs.sign == '' - run: | - Set-StrictMode -Version 'Latest' - Import-Certificate -CertStoreLocation Cert:\LocalMachine\Root -FilePath .github/SSLcom-sandbox.crt - - - name: Check app was signed successfully - working-directory: apps/desktop - run: | - Set-StrictMode -Version 'Latest' - Get-ChildItem ` - -Recurse dist ` - -Include *.exe, *.msi ` - | ForEach-Object -Process {. $env:SIGNTOOL_PATH verify /pa $_.FullName; if(!$?) { throw }} - - - name: Upload Artifacts - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: ${{ inputs.artifact-prefix }}win-${{ inputs.arch }} - path: | - apps/desktop/dist - retention-days: 1 - - - name: Assert executable is present - working-directory: apps/desktop - run: | - Test-Path './dist/win-*unpacked/Element*.exe' - - - name: Assert all Squirrel files are present - if: contains(inputs.targets, 'squirrel') - working-directory: apps/desktop - run: | - Test-Path './dist/squirrel-windows*/Element Setup*.exe' - Test-Path './dist/squirrel-windows*/element-desktop-*-full.nupkg' - Test-Path './dist/squirrel-windows*/RELEASES' - - - name: Assert MSI is present - if: contains(inputs.targets, 'msi') - working-directory: apps/desktop - run: | - Test-Path './dist/Element*.msi' - - test: - name: Test Windows ${{ inputs.arch }} - needs: build - if: inputs.test - uses: ./.github/workflows/build_desktop_test.yaml - with: - project: win-${{ inputs.arch }} - artifact: ${{ inputs.artifact-prefix }}win-${{ inputs.arch }} - runs-on: ${{ inputs.test-runs-on || (inputs.arch == 'arm64' && 'windows-11-arm' || 'windows-2022') }} - executable: ./dist/win*-unpacked/Element*.exe - blob_report: ${{ inputs.blob_report }} - args: ${{ inputs.test-args }}