Copies .dockerignore, .gitignore, .prettierignore, check.yml and REPO_POLICIES.md from sneak/prompts at dd4027b. The repo's own entries (dist/, release/, yarn files) are kept after the canonical content. The Dockerfile gets separate lint and test phases. Its last stage depends on both, checks the git describe version and runs make build. script/lint, test, check, cibuild and docker are the canonical models. check-censored moves into the lint phase and test-verify-build into the test phase. fmt and fmt-check fall back to the nvm-installed node. The e2e image builds are uncached. Comments that cited the old test caps now say 60 seconds, and comments that named what runs a script now name the Dockerfile phase or stage. Model: opus-5-5
5.3 KiB
Releasing AutistMask
This is the procedure that turns a green main into a tagged, packaged release.
It gathers into one place what is otherwise spread across the Makefile and
three README.md sections, so the person cutting a release does not have to
reconstruct the order from them.
There is one version, declared in three files (package.json,
manifest/chrome.json, manifest/firefox.json), and make package builds and
packages but publishes nothing. make build and make package can be run by
anyone; tagging, signing, packing a CRX and any upload need credentials only the
owner (@sneak) holds and are marked owner-only
below. Releases are tagged from main (see the Workflow section of TODO.md),
so the "release commit" throughout is the main commit the milestone PR merged.
Procedure
-
Confirm
mainis green in CI. Thecheckworkflow (.gitea/workflows/check.yml) runsscript/cibuild, which runsscript/checkand then builds the image uncached, so a greencheckrun is a greenmake check. Find the run for the exact release commit on the tracker's Actions view. Check: that commit'scheckrun succeeded; runningmake checkon a clean checkout of the commit reproduces it and exits 0. -
Confirm the version matches the intended tag.
package.json,manifest/chrome.jsonandmanifest/firefox.jsonmust all declare the sameX.Y.Z.make buildfails when they disagree, but nothing checks that they equal the tag you mean to create — that is this manual step. Check: all three files read the sameX.Y.Z, and it is the version you intend to tagvX.Y.Z. -
Build and package from a clean checkout of that commit. From a fresh clone, or a working tree with no local modifications (
git statusclean), checked out at the release commit: runmake setup, thenmake package.make packagerunsmake buildfirst, so the archives can only be made from adist/verified against that build's own receipt as a release (not debug) build. It writes three files intorelease/:autistmask-chrome-<version>.zip,autistmask-firefox-<version>.xpi, andSHA256SUMS. Check: those three files exist and<version>in the archive names is the version confirmed in step 2. The Firefox.xpiis unsigned (see step 6 and "Installing on Firefox" inREADME.md). -
Verify
SHA256SUMS. The archives are deterministic — sorted entries, fixed timestamps, fixed compression — so a secondmake packagefrom another clean checkout of the same commit produces byte-identical files. Verify the recorded digests against the files withsha256sum -c SHA256SUMS, run fromrelease/. To confirm reproducibility, runmake packageagain on a separate clean checkout and compare the digests. Check:sha256sum -creportsOKfor every file, and an independent build's digests match. -
Tag the release commit. (owner-only) Create an annotated tag
vX.Y.Zon the release commit and push it:git tag -a vX.Y.Z(with a message), thengit push origin vX.Y.Z. Check:git taglistsvX.Y.Z, andgit rev-parse vX.Y.Z^{commit}resolves to the release commit. -
Distribute per browser. (owner-only; pending the owner's choice on #386) How 1.0.0 is distributed on each browser is not yet decided; it is the open question on that issue, and the concrete steps cannot be written until the owner records a choice there. These steps need credentials only the owner holds. The options under consideration are:
- Firefox — the packaged
.xpiis unsigned, and release Firefox and ESR refuse an unsigned add-on:- (a) AMO self-distribution signing (unlisted): submit the
.xpito AMO with the owner's credentials; AMO returns a signed.xpiinstallable on every Firefox, with nothing listed publicly. - (b) AMO listed: as (a), plus a public AMO listing and review.
- (c) Ship the unsigned
.xpiand state that Firefox support means Developer Edition, Nightly, or an Unbranded build withxpinstall.signatures.requiredset tofalse.
- (a) AMO self-distribution signing (unlisted): submit the
- Chrome — the repo packs no CRX and publishes nothing; the extension id
is fixed by the
keyinmanifest/chrome.json:- (a) Chrome Web Store (unlisted): upload the
.zipwith the owner's developer account; the store delivers installs and updates. - (b) Self-hosted CRX signed with the private key the owner holds
(
chrome --pack-extension=dist/chrome --pack-extension-key=<path to the .pem>), installable only via enterprise policy on Windows and macOS, so realistically Linux-only. - (c) "Load unpacked" from
dist/chrome/only, as today.
- (a) Chrome Web Store (unlisted): upload the
Once the owner decides, the chosen steps — including which credentials they need and who holds them — are written into this section and
README.md's installation sections are updated to match, which is part of the definition of done of #386. Check: for a store or AMO route, the artifact installs from the store or AMO on a clean browser profile; for the CRX or unpacked route, the documented load succeeds and Chrome reports the extension idgipbhkogfopeahplcjhipkgpcimdpkip. - Firefox — the packaged