feat(desktop): packaging, auto-update, CI/CD, and install scripts

- GitHub Actions: release-desktop.yaml builds macOS (arm64+amd64) + Windows
  on lite-v* tag push, creates DMG + tar.gz + zip GitHub Release assets
- Install scripts: install-lite.sh (macOS curl) + install-lite.ps1 (Windows PowerShell)
- Auto-update: internal/updater checks GitHub Releases, downloads + atomic
  app swap with path traversal guards, size limits, symlink handling
- UpdateBanner: thin notification bar with download progress + restart
- Wails bindings: CheckForUpdate, ApplyUpdate (server-cached, no URL from JS),
  RestartApp (graceful gateway shutdown before exit)
- AboutTab: dynamic version from backend via GetVersion()
- Windows build assets: icon.ico, info.json, wails.exe.manifest
- Makefile: desktop-dev, desktop-build, desktop-dmg targets
- README: Desktop Edition section with install commands + feature comparison
- .gitignore: desktop packaging artifacts, SQLite DB files, update backups

Security: HTTPS-only downloads, io.LimitReader on all extractions,
zip/tar path traversal validation, symlink target guard, no untrusted
URL from frontend (ApplyUpdate uses server-cached info).
This commit is contained in:
viettranx committed 2026-03-27 10:15:15 +07:00
1 parent 30708ae79d
commit b9c1731e31
18 files changed
+1095 -3

No files matched your search

+161
View File
@@ -0,0 +1,161 @@
name: Release Desktop
on:
push:
tags: ['lite-v*']
permissions:
contents: write
env:
GITHUB_REPO: ${{ github.repository }}
jobs:
# ── macOS builds (native runners required for Wails/WebKit) ──
build-macos:
strategy:
matrix:
include:
- runner: macos-14 # Apple Silicon (arm64)
arch: arm64
- runner: macos-13 # Intel (amd64)
arch: amd64
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
cache-dependency-path: go.sum
- name: Setup pnpm
run: corepack enable && corepack prepare pnpm@latest --activate
- name: Install Wails CLI
run: go install github.com/wailsapp/wails/v2/cmd/wails@latest
- name: Extract version from tag
id: version
run: echo "version=${GITHUB_REF_NAME#lite-v}" >> "$GITHUB_OUTPUT"
- name: Patch wails.json version
working-directory: ui/desktop
run: |
jq --arg v "${{ steps.version.outputs.version }}" \
'.info.productVersion = $v' wails.json > wails.json.tmp \
&& mv wails.json.tmp wails.json
- name: Build desktop app
working-directory: ui/desktop
run: |
wails build -tags sqliteonly \
-ldflags "-s -w -X github.com/nextlevelbuilder/goclaw/cmd.Version=${{ steps.version.outputs.version }}"
- name: Create DMG
run: |
mkdir -p dmg-staging
cp -R ui/desktop/build/bin/goclaw-lite.app dmg-staging/
ln -s /Applications dmg-staging/Applications
hdiutil create -volname "GoClaw Lite ${{ steps.version.outputs.version }}" \
-srcfolder dmg-staging -ov -format UDZO \
"goclaw-lite-${{ steps.version.outputs.version }}-darwin-${{ matrix.arch }}.dmg"
- name: Create tar.gz (for auto-update)
run: |
cd ui/desktop/build/bin
tar czf "../../../../goclaw-lite-${{ steps.version.outputs.version }}-darwin-${{ matrix.arch }}.tar.gz" \
goclaw-lite.app
# TODO: Add code signing when Apple Developer cert is available
# - name: Sign app
# run: codesign --deep --force --sign "${{ secrets.APPLE_SIGNING_IDENTITY }}" ...
- name: Upload artifacts
uses: actions/upload-artifact@v4
with:
name: macos-${{ matrix.arch }}
path: |
goclaw-lite-*.dmg
goclaw-lite-*.tar.gz
# ── Windows build ──
build-windows:
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
cache-dependency-path: go.sum
- name: Setup pnpm
run: corepack enable && corepack prepare pnpm@latest --activate
- name: Install Wails CLI
run: go install github.com/wailsapp/wails/v2/cmd/wails@latest
- name: Extract version from tag
id: version
shell: bash
run: echo "version=${GITHUB_REF_NAME#lite-v}" >> "$GITHUB_OUTPUT"
- name: Patch wails.json version
working-directory: ui/desktop
shell: pwsh
run: |
$json = Get-Content wails.json | ConvertFrom-Json
$json.info.productVersion = "${{ steps.version.outputs.version }}"
$json | ConvertTo-Json -Depth 10 | Set-Content wails.json
- name: Build desktop app
working-directory: ui/desktop
shell: bash
run: |
wails build -tags sqliteonly \
-ldflags "-s -w -X github.com/nextlevelbuilder/goclaw/cmd.Version=${{ steps.version.outputs.version }}"
- name: Create zip
shell: pwsh
run: |
Compress-Archive -Path "ui/desktop/build/bin/goclaw-lite.exe" `
-DestinationPath "goclaw-lite-${{ steps.version.outputs.version }}-windows-amd64.zip"
- name: Upload artifacts
uses: actions/upload-artifact@v4
with:
name: windows-amd64
path: goclaw-lite-*.zip
# ── Create GitHub Release ──
create-release:
needs: [build-macos, build-windows]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Extract version from tag
id: version
run: echo "version=${GITHUB_REF_NAME#lite-v}" >> "$GITHUB_OUTPUT"
- name: Download all artifacts
uses: actions/download-artifact@v4
with:
path: artifacts
merge-multiple: true
- name: List artifacts
run: ls -la artifacts/
- name: Create release
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
name: "GoClaw Lite v${{ steps.version.outputs.version }}"
draft: false
prerelease: false
generate_release_notes: true
files: artifacts/*
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}