Skip to content

Build, sign and publish Whiteboard for Intel Macs - #636

Open
thesiti92 wants to merge 8 commits into
mainfrom
feat/macos-intel
Open

thesiti92 wants to merge 8 commits into
mainfrom
feat/macos-intel

Conversation

@thesiti92

@thesiti92 thesiti92 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Adds a signed, notarized, auto-updating Whiteboard build for Intel Macs (darwin-x64), alongside the Apple silicon build. Closes #614.

How it builds

  • The Linux payload compile now produces curated extensions for both chips, in one darwin-payload.tar.zst.
  • The macOS build job is a matrix. darwin-arm64 runs on macos-15-xlarge with a 90-minute timeout. darwin-x64 runs natively on macos-15-large, the Intel larger runner, with a 150-minute timeout.
  • The scripts derive the target from the host arch (darwin-arch.sh, darwinTarget()) instead of hardcoding darwin-arm64.
  • R2 uploads move to a new publish-macos job, which needs the whole matrix.
    • Payloads for both chips upload first, and both latest.json files last.
    • If either chip fails, nothing publishes.
    • finalize-release and tag-preview now wait on publish-macos.
  • New live checks confirm the Intel feed (clients send plain darwin) and the Intel DMG alias.

Wrong-arch guard

  • validate-release-artifacts.mjs now runs lipo -archs on the app executable, the bundled diffr, and every native executable declared by a bundled curated extension (currently ty and ruff).
  • Codesign would accept an arm64 binary inside the Intel app. This check catches it before publishing.

Dependencies (already live)

Worth knowing

  • An Intel build under Rosetta on Apple silicon asks for darwin, so it keeps getting Intel updates. This is correct; please don't "fix" it.
  • The C# extension's darwin-x64 VSIX from upstream ships an arm64-only netcoredbg. C# debugging won't work on Intel Macs. It is not arch-asserted, on purpose.
  • GitHub keeps Intel macOS runners until about August 2027. After that, the Intel leg has to cross-build on arm64.
  • publish-linux and publish-windows now run in parallel with publish-macos. Before, they started only after the Mac publish.
  • Removed change-detector assertions (per AGENTS.md), each in curated-extensions.test.mjs, where it grepped script source text:
    • the $DARWIN_PAYLOAD_CURATED_EXTENSIONS_PATH ordering check;
    • --target=darwin-arm64 in compile-darwin-payload.sh;
    • target: "darwin-arm64" in validate-release-artifacts.mjs, and REVIEW_DESKTOP_CURATED_EXTENSION_TARGET=darwin-arm64 in compile-darwin-payload.sh.
      Tell me if any should be replaced with a behavioral test.
  • Tester artifacts: the preview dry-run tester DMG artifact is now macos-darwin-arm64 / macos-darwin-x64, instead of review-desktop-preview-<v>-dmg.

Verification

  • node --test apps/review-desktop/scripts/*.test.mjs passes, apart from the existing yazl baseline failure.
  • actionlint, root lint and format are clean.
  • All four new Intel VSIX pins were checked against Open VSX (three were re-hashed independently). Materializing them yields x86_64 binaries.
  • The Intel end-to-end proof is the dry-run preview dispatch from this branch, on real Intel hardware.

Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: e8a1eaea-7717-48b1-a143-d9adbd3f5f58
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: e8a1eaea-7717-48b1-a143-d9adbd3f5f58
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: e8a1eaea-7717-48b1-a143-d9adbd3f5f58
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: e8a1eaea-7717-48b1-a143-d9adbd3f5f58
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: e8a1eaea-7717-48b1-a143-d9adbd3f5f58
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 0b48503e-b517-4f1d-a168-e843dc788525
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: 0b48503e-b517-4f1d-a168-e843dc788525
Agent-Session: 01a0e553-25fc-7350-ab29-e046a939a2e6
@thesiti92
thesiti92 deployed to review-release-approval September 28, 2026 01:37 — with GitHub Actions Active
Agent-Session: 11e6cdc4-ebab-4f67-9499-a7e914620a86
Agent-Session: b11edf22-6b82-42e6-87c4-07c995cb9400
Agent-Session: d206e73a-3115-47e6-8c72-b8251090e94a
Agent-Session: 01a0e5ab-8d00-7bd2-9d87-a0496098a08c

This branch was successfully deployed

1 active (outdated) deployment
review-release-approval — a10dc757 Deployed Sep 28, 2026 by thesiti92 via Approve release #72
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support building on Intel Macs (darwin-x64)

1 participant