Skip to content

Release flow: signed DMG, GitHub Releases and Updates - #1

Merged
lucasdoell merged 38 commits into
mainfrom
polaris/grill-with-docs-we-ll-need-a-2c2b
Oct 3, 2026
Merged

lucasdoell merged 38 commits into
mainfrom
polaris/grill-with-docs-we-ll-need-a-2c2b

Conversation

@lucasdoell

Copy link
Copy Markdown
Member

Release flow for a distributable Polaris (ENG-252).

  • Release builds (ENG-254): package --release builds release-versioned Daemons, signs them and Betterleaks with the Developer ID and hardened runtime, notarises the app, and emits the Update zip.
  • DMG (ENG-255, ENG-258): dawn-scene installer designed in Paper, generated reproducibly by design/scripts/gen_dmg.py, built headless with dmgbuild, signed and notarised when credentials exist.
  • Release workflow (ENG-260): v* tags build a draft GitHub Release; -rc.N may be unsigned prereleases; stable tags fail closed without signing secrets.
  • Site (ENG-257, ENG-259): apps/site (Next.js on Vercel) with the update feed (/api/update/darwin-arm64/:version), /download/mac, Axiom events without IPs, and the mobile download email (BotID → SES Insights validation → SES).
  • Desktop App Updates (ENG-261, ENG-256): automatic checks with an anonymous install ID (ADR 0017), Restart to update / Quit and update, quiet "Upgraded to x.y.z" replacing the Daemon-upgraded toast.
  • Daemon: the execve upgrade hand-off no longer leaks into child processes; an invalid inherited hand-off cold-starts instead of exiting; bench and smoke fixtures strip it.
  • Glossary: Release, Update, Daemon Upgrade.

Typecheck, tests, lint and licences pass on the merged branch. Environment setup: ENG-267. First signed release: ENG-262.

Paper Updates page U1-U6 (proposed): Settings -> About with the update
row and what each check sends, Restart to update in the app menu, About
and the K menu, quiet Upgraded to x.y.z on hosts. Daemon copy moves
from update to upgrade per CONTEXT.md; the per-upgrade toast is dropped.
… and update (ENG-256)

The 2026-10-01 'Daemon upgraded' toast is superseded by the machine-bar
caption, tooltip and Hosts row; the updater task removes it from code.
Next.js 16 (App Router, Turbopack) for Vercel with root directory apps/site,
built from the Paper "Marketing site" page: S1 desktop dark, S2 light (system
appearance) and S3 mobile, on @polaris/ui's tokens plus the site palette.
Product shots, scenes, pixel icons and washes are imported from
design/assets, never copied.

The repo is public, so the "Source opens soon" notify form becomes a real
source link: "View source" buttons and a repository card with the clone
line. "Download for macOS" goes to /download/mac (ENG-259). On phones the
primary action drafts the download link to the visitor's own address.

The site joins typecheck, test, lint and turbo build. Next pulls in
caniuse-lite (CC-BY-4.0) and sharp's prebuilt libvips (LGPL-3.0), recorded
as licence exceptions with reasons; THIRD_PARTY_NOTICES.md regenerated.
AGENTS.md gains the apps/site row; DESIGN.md's Marketing site section
drops the notify form and records the mobile email draft and breakpoints.
…643b/dmg-design-design-the-dmg-installer-in-paper-eng-25
Pass filtered explicit environments to every runtime child launch, validate inherited descriptors before adoption, and replace legacy Codex servers only when idle.

Typecheck, tests, lint and spec checks pass. Leased cold-start quick runs (3 before/after) stay within tolerance of the before control. Both fail the older machine baseline under 9.3/5.7 busy cores; startup 214.7/214.6 ms and footprint 88.28/87.41 MiB. No baseline rewrite; performance evidence is load-qualified.
# Conflicts:
#	apps/site/package.json
#	bun.lock
Finder draws icon labels black over a DMG background in both
appearances, so the night art left them unreadable. Record the dawn
recipe for gen_dmg.py, the neutral ink arrow and the measured label
contrast; Paper I3/I4 replace I1/I2.
Strip POLARIS_HANDOFF after environment overrides in benchmark and Desktop smoke fixtures. Reject zero-process Daemon report windows so failed measurements cannot appear as improved counters.

Leased quick idle measured one process before and after. Comparisons are load-qualified at 6.9/10.1 background cores: baseline footprint drift appeared in both runs and after RSS varied. Baselines remain unchanged.
# Conflicts:
#	scripts/license-exceptions.json
Use Electron autoUpdater with the private site-feed contract, persisted opt-out,
About and K menu controls, and staged updates on quit. Replace upgrade success
toasts with expiring machine captions and Hosts rows.

Idle runs retain the committed baseline. Physical footprint was already above
it before the change and stays stable afterward; busy-Host RSS/CPU comparisons
are inconclusive. The six-hour timer runs only in the Desktop App and is removed
when checks are off or an update is ready. Record metrics and signed-install
verification limits in the updater README.
@lucasdoell
lucasdoell merged commit dfb4b18 into main Oct 3, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant