Conversation
Stop sharing main-process chunks by building a single Vite entry and letting ?modulePath emit the session server on its own. Teach the asar inspector to strip listPackage paths, refuse extract failures, and catch missing named exports. Align unsigned GitHub releases with the macOS pipeline, raise the release-job heap, and only mark a tag latest when it is actually newest.
tanRdev
marked this pull request as ready for review
September 15, 2026 17:26
Always pass --latest=true or --latest=false so publishing an older draft cannot steal GitHub latest. Follow export * when checking named exports, compare release tags as semver, pack the Vite out tree into asar in CI, and assert the modulePath session-server file is present and referenced.
Follow named `export { local as exported } from` (including minified
forms) instead of treating brace re-exports as local. Limit named-export
checks to main-process files and skip asar `node_modules`. Pack a real
unsigned electron-builder dir in CI so afterPack inspects the shipped
asar. Paginate GitHub releases, never mark prereleases latest, and treat
a failed `codesign -dv` as unsigned.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the gaps from the post-v0.9.3 packaging review so another empty shared chunk cannot ship, and so the macOS release workflow matches what we actually publish.
What changed
Main process bundles are isolated. The second Rollup input (
agentHostSessionServer) is what createdout/main/chunks/*.jsand the v0.9.3 crash class. Main now has a singleindexentry withinlineDynamicImports: true. The session server is still emitted by electron-vite’s?modulePathimport as its own file (agent-host-session-server-entry-*.js). A local production build now has noout/main/chunks/directory.inspectAsarfails closed.@electron/asarlistPackage()returns/out/main/index.js;extractFile()expects the path without the slash. The inspector strips the prefix, throws on extract failures or zero JS files, and reports named imports whose target does not export that name.export * fromandexport { local as exported } from(including minifiedexport*from/export{ot}from) are followed instead of treated as local/universal exports.export { ot as n }no longer counts as exportingot. Named-export checks are limited to main-process files; asarnode_modulesis skipped.CI packs a real unsigned electron-builder asar. After the desktop build, CI inspects
apps/desktop/out, asserts the isolated main layout, then runspack:mac:dir(electron-builder --mac dir --arm64withCSC_IDENTITY_AUTO_DISCOVERY=false) soafterPackinspects the shipped asar. Job timeout is 45 minutes.Release pipeline matches unsigned GitHub releases.
release:macno longer requires a Developer ID. Verify always inspects the asar; signing/notarization checks run only when the app is Developer ID-signed. A failedcodesign -dvis treated as unsigned, not a hard failure. The release job gets the same 8GB Node heap CI needed. Publishing paginates GitHub releases, always sends--latest=trueor--latest=false, never marks a prerelease latest, and compares stables only to other stables.Tests
listPackagepaths, multiline missing named exports,export */ named re-export follow-through, minified forms, renderer skip, and asarnode_modulesskip.codesign -dv, latest-tag comparison, prereleases, and explicit--latest=false.gh apirelease listing and the CIpack:mac:dirstep.