Files
openclaw/.github/workflows/linux-app.yml
Peter Steinberger e94796e447 fix(linux): restore the macOS build of the Tauri companion (#114243)
* fix(linux): restore the macOS build of the Tauri companion

Tauri gates `WebviewWindowBuilder::transparent` behind its `macos-private-api`
feature on macOS, so the companion stopped compiling for macOS when Quick Chat
landed in #109947: `no method named 'transparent' found for struct
'WebviewWindowBuilder'`. Enable that feature together with the matching
`app.macOSPrivateApi` config flag, which Tauri requires to agree with it or
tauri-build fails the allowlist check.

Quick Chat is built for a transparent window - quickchat.css makes html and
body transparent behind a 16px-radius translucent card with a drop shadow - so
compiling macOS by dropping `.transparent(true)` would ship an opaque rectangle
instead of the floating composer.

Also add a per-PR macOS `cargo check`. The only job that compiled the macOS
target sits behind a manual dispatch input in linux-app-release.yml, which is
why a broken macOS build survived for nine days.

* ci(linux): build the macOS companion on macos-15

tauri-plugin-notifications' Swift sources use typed throws
(`throws(FFIResult)`), which requires Swift 6. The macos-14 runner image still
ships Swift 5.x and cannot parse them, so the plugin's build script panics with
"Swift build failed for target: arm64-apple-macosx13.0".

This hit the new per-PR check immediately, and it means the release workflow's
`build_macos` job could not have produced a macOS bundle either - it compiles
the same crate on the same image, but only runs behind a manual dispatch input
so nothing surfaced it. Move both to macos-15.
2026-07-26 22:57:36 -04:00

132 lines
4.3 KiB
YAML

name: Linux App
on:
pull_request:
paths:
- "apps/linux/**"
- ".github/workflows/linux-app.yml"
workflow_dispatch:
concurrency:
group: linux-app-${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
cancel-in-progress: true
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
permissions:
contents: read
jobs:
build:
name: Build Linux companion
# Match the release build base so PR artifacts have the same glibc floor.
runs-on: ubuntu-22.04
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 1
fetch-tags: false
persist-credentials: false
submodules: false
- name: Install Tauri system dependencies
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends \
build-essential \
curl \
file \
libayatana-appindicator3-dev \
librsvg2-dev \
libssl-dev \
libwebkit2gtk-4.1-dev \
libxdo-dev \
wget
- name: Install Rust
run: rustup toolchain install stable --profile minimal --component rustfmt
- name: Cache Cargo
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry
~/.cargo/git
apps/linux/src-tauri/target
key: linux-app-${{ runner.os }}-${{ hashFiles('apps/linux/src-tauri/Cargo.lock') }}
restore-keys: |
linux-app-${{ runner.os }}-
- name: Setup Node environment
uses: ./.github/actions/setup-node-env
with:
install-bun: "false"
install-deps: "false"
- name: Check Rust formatting
working-directory: apps/linux/src-tauri
run: cargo +stable fmt --check
- name: Build Linux companion bundles
working-directory: apps/linux/src-tauri
env:
# appimagetool strips fail on CI runners; Tauri documents NO_STRIP for Actions.
NO_STRIP: "true"
# PR builds have no TAURI_SIGNING_PRIVATE_KEY, and the configured updater
# pubkey makes the bundler hard-require it. Skip updater artifacts here;
# linux-app-release.yml builds the signed updater bundles.
run: pnpm dlx @tauri-apps/cli@2.11.4 build --bundles deb,appimage --config '{"bundle":{"createUpdaterArtifacts":false}}'
- name: Upload bundles
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: openclaw-linux-companion
retention-days: 14
if-no-files-found: error
path: |
apps/linux/src-tauri/target/release/bundle/deb/*.deb
apps/linux/src-tauri/target/release/bundle/appimage/*.AppImage
check-macos:
name: Check macOS companion
# This app also ships macOS desktop-test bundles, but the only job that
# compiles them (linux-app-release.yml build_macos) runs behind a manual
# dispatch input. Without a per-PR check, a macOS-gated Tauri API can break
# the macOS target for weeks unnoticed - `WebviewWindowBuilder::transparent`
# did exactly that.
#
# macos-15, not macos-14: tauri-plugin-notifications' Swift sources use
# typed throws (`throws(FFIResult)`), which needs Swift 6. The macos-14
# image still ships Swift 5.x and fails to parse them.
runs-on: macos-15
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 1
fetch-tags: false
persist-credentials: false
submodules: false
- name: Install Rust
run: rustup toolchain install stable --profile minimal
- name: Cache Cargo
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry
~/.cargo/git
apps/linux/src-tauri/target
key: macos-app-${{ runner.os }}-${{ hashFiles('apps/linux/src-tauri/Cargo.lock') }}
restore-keys: |
macos-app-${{ runner.os }}-
- name: Check macOS companion
working-directory: apps/linux/src-tauri
run: cargo +stable check --locked --all-targets