Commit Graph
215 Commits
Author SHA1 Message Date
Steven EnamakelandGitHub 1d28f2c8e3 ci(release): ship Linux openhuman-core tarballs and push GHCR image (#1442) 2026-05-09 16:09:04 -07:00
Steven EnamakelandGitHub 0cefbe6d8f fix(ci): switch rabbit-retrigger to a PAT in Review environment (#1430) 2026-05-09 14:38:00 -07:00
Steven EnamakelandGitHub 3faa47bca1 Fix/rabbit 3 (#1428) 2026-05-09 14:31:40 -07:00
Steven EnamakelandGitHub bf6532b11f fix(ci): scope rabbit-retrigger to Production environment (#1427) 2026-05-09 14:26:25 -07:00
Steven EnamakelandGitHub 29fabb234a fix(rabbit): handle CR action acks + edited rate-limit comments; schedule via GH Action (#1425) 2026-05-09 14:18:13 -07:00
Steven EnamakelandGitHub 3f86bcd69d fix(sentry): restore OS context + guard source-map upload (#1403) (#1405) 2026-05-09 13:06:37 -07:00
Steven EnamakelandGitHub 6b044a9456 docs: rewrite README + gitbooks around current product, add Developing section (#1384) 2026-05-08 21:18:20 -07:00
YellowSnnowmannandGitHub dcd4f97f00 fix(ci): staging builds resolve to prod API URL — bake VITE vars into build.yml (#1371) 2026-05-08 19:04:00 -07:00
CodeGhost21andGitHub 5189ca95ef feat(deploy): one-click cloud deployment for OpenHuman Core (closes #1280) (#1304) 2026-05-06 13:11:20 -07:00
13fa917d96 fix(windows): align install.ps1 MSI with per-machine scope (#913) (#1187)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-04 10:49:43 -07:00
CodeGhost21andGitHub b574256f75 chore(sentry): rename OPENHUMAN_SENTRY_DSN → OPENHUMAN_CORE_SENTRY_DSN (#1186) 2026-05-04 22:57:43 +05:30
Steven EnamakelandGitHub da410e9d7f docs: surface 80% coverage gate and scripts/debug runners (#1108) 2026-05-02 14:53:35 -07:00
Steven EnamakelandGitHub b94e25958e ci: pull pnpm into CI image, drop redundant setup steps (#1107) 2026-05-02 13:47:55 -07:00
Steven EnamakelandGitHub f8cfe85ee7 ci: add diff-aware 80% coverage gate (Vitest + cargo-llvm-cov) (#1104) 2026-05-02 13:33:02 -07:00
Steven EnamakelandGitHub 7d8910f157 ci(staging): cut staging from main; add act local-debug helper (#1099) 2026-05-02 06:29:22 -07:00
Steven EnamakelandGitHub 45b055f122 Update release-staging.yml (#1097) 2026-05-02 06:04:30 -07:00
Steven EnamakelandGitHub f0654261a7 ci(release): split staging vs production workflows; promote staging tags (#1094) 2026-05-02 05:53:32 -07:00
a084ebf45c fix(sentry): auto-send React events; collapse core→tauri for desktop (#1086)
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-01 15:11:42 -07:00
CodeGhost21andGitHub cd7a56581c fix(sentry): Rust source context + per-release deploy marker (#405) (#1067) 2026-05-01 17:06:31 +05:30
Cyrus GrayandGitHub 6ac7885cfe ci: add dedicated staging release workflow (#1066) 2026-05-01 14:19:24 +05:30
Steven EnamakelandGitHub 016ad78086 fix(core,cef): run core in-process and stop orphaning CEF helpers on Cmd+Q (#1061) 2026-04-30 23:22:18 -07:00
Mega MindandGitHub 4997a239ec Build staging desktop artifacts in debug profile (#1044) 2026-04-30 16:41:46 +05:30
e943a1ad1b feat(sentry): split errors into per-surface projects (react, core, tauri) (#1032)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 15:57:41 -07:00
obchainandGitHub b2cfcd50e3 ci(weekly-review): aggregator + workflow + runbook for #459 (#914) 2026-04-29 11:38:58 -07:00
b56e846988 feat(config): runtime RPC URL configuration bootstrap (Issue #933) (#948)
Co-authored-by: Steven Enamakel <31011319+senamakel@users.noreply.github.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-04-29 11:33:35 -07:00
a09222b4ec feat(ci): tighten PR template + add soft-fail quality gates (#965) (#1001)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 11:09:54 -07:00
Steven EnamakelandGitHub 1f4e151e59 fix(release): sign CEF inner dylibs so macOS notarization passes (#951) 2026-04-26 13:07:21 -07:00
9f76b62757 docs: add changelog entry for issue #867 loading overlay verification (#944)
Co-authored-by: MiniMax Agent <minimax-agent@users.noreply.github.com>
2026-04-26 10:30:28 -07:00
Steven EnamakelandGitHub 7867496d86 feat(home): banners, welcome typewriter, conversation gating (#936) 2026-04-26 01:15:57 -07:00
Steven EnamakelandGitHub b21f64e275 chore(release): remove updater pubkey/endpoint override + gate signed artifacts (#912) 2026-04-24 22:37:33 -07:00
Steven EnamakelandGitHub a472bee17f feat(app-update): wire up tauri shell auto-updater (#909) 2026-04-24 21:10:55 -07:00
Mega MindandGitHub 1d864efbeb feat(notifications): unify notification slices, dismiss action, stats panel, unified Notifications page (#876) 2026-04-24 11:58:11 -07:00
Steven EnamakelandGitHub 7bd8f9d4c1 ci: parallelize rust tests, dedupe typecheck/clippy/sentry across workflows (#895) 2026-04-24 11:10:27 -07:00
VectorJetandGitHub a96d9da3a4 chore: migrate from yarn to pnpm (#886) 2026-04-24 10:52:16 -07:00
9b1f4cdf71 fix(devops): upload Rust debug symbols to Sentry during Tauri build (closes #627) (#890)
- Add Sentry debug symbol upload step to the CI pipeline for production builds.
- Implement a helper script for manual symbol uploads with OS and architecture detection.
- Configure automatic Sentry release creation and commit association on main branch pushes.
- Refine Sentry CLI parameters to correctly handle shallow clones and debug ID indexing.
- Initialize CHANGELOG.md to track project changes and infrastructure updates.
- Update workflow permissions to allow Sentry to read action metadata for commit mapping.

Closes #627

Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-04-24 10:20:58 -07:00
obchainandGitHub 1d0c820a3b fix(install.sh): dry-run exits 0 when platform asset missing (#877) 2026-04-24 09:35:51 -07:00
e0eb3c47be ci: enable sccache and disable incremental in rust test job (#866)
Co-authored-by: Jwalin Shah <jshah1331@gmail.com>
2026-04-23 17:08:50 -07:00
Steven EnamakelandGitHub 3e6ca41d7b ci(release): drop duplicate vite build and raise node heap to 8GB (#865) 2026-04-23 16:06:54 -07:00
YellowSnnowmannandGitHub 06b6890e2a chore(release): increase Node.js memory limit for builds (#838) 2026-04-23 21:41:38 +05:30
9a6f9cd110 fix(onboarding): show onboarding immediately after bootstrap (#777)
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-04-22 14:48:40 -07:00
7961a328ca ci(e2e): add Linux workflow for agent-review spec (#763)
Dedicated narrow workflow that runs only agent-review.spec.ts under
tauri-driver + Xvfb and uploads app/test/e2e/artifacts/**. Gates on
spec presence so it can land before the spec itself. Intentionally does
not re-enable the broader commented E2E matrix in test.yml.

Co-authored-by: Jwalin Shah <jshah1331@gmail.com>
2026-04-22 14:31:59 -07:00
Steven EnamakelandGitHub 758958bfd5 feat(webview): zero-injection CDP migration for 5 providers (#751)
* feat(webview): zero-injection CDP migration for 5 providers

Moves the per-provider webview scraping path off injected JS and onto
CDP for the cef runtime. The 5 migrated providers (whatsapp, telegram,
slack, discord, browserscan) now load with zero initialization_script;
their UA fingerprint, DOM chat-list scraping, and multi-account target
matching all run through the Chrome DevTools Protocol.

Shared infrastructure in new `cdp/` module: CdpConn, Snapshot walker
(generic DOMSnapshot.captureSnapshot), UaSpec + setUserAgentOverride
helper, per-account session opener that keeps a long-lived CDP session
attached so the UA override stays resident for the lifetime of the
webview. Webview opens at a data:text/html placeholder, CDP applies UA
override, then Page.navigate drives it to the real provider URL with a
`#openhuman-account-{id}` fragment used by all scanners for
multi-account disambiguation (replaces Telegram's title-marker JS).

Per-provider dom_snapshot.rs files for telegram/slack/discord replicate
the WhatsApp scraper pattern. Emit the same `webview:event` ingest
envelope the old recipes used so the frontend is unchanged.

Deferred (kept JS-injected, separate PRs):
- gmail/linkedin: no Rust scanner yet
- google-meet: 535-line lifecycle + captions recipe
- idb.rs `Runtime.callFunctionOn` serializer: audit listed as future work

Also removes the unused `webview_account_eval` Tauri command.

Wry builds retain the legacy ua_spoof.js + runtime.js + recipe.js path
where those files still exist (no wry-specific regressions introduced).

* fix(release): enable Ubuntu 22.04 platform support in release workflow

Uncommented and configured the Ubuntu 22.04 platform in the release workflow to support the x86_64-unknown-linux-gnu target. This change enhances cross-platform compatibility for the release process.

* fix(webview): address CodeRabbit review comments

- session.rs: boundary-check the `starts_with(real_url)` match so
  `https://discord.com` can't accidentally match `https://discord.com.evil/…`
  when deciding whether to skip Page.navigate.
- session.rs: drop unused `_app: AppHandle<R>` parameter from spawn_session
  (and its generic R); update the webview_accounts call site accordingly.
- session.rs: document the non-graceful shutdown path (cancellation token
  left as a follow-up).
- discord/slack/telegram scanners: import CDP_HOST/CDP_PORT from the shared
  `cdp` module instead of redeclaring them. (whatsapp_scanner keeps its
  locals — the module isn't cef-gated so it can't pull from cef-only cdp::.)
- webview_accounts/mod.rs: collapse the duplicate provider_is_supported
  check with provider_url into one early-return.
- emulation.rs: add a TODO documenting when/how to refresh the hardcoded
  Chrome UA fingerprint fields.
- discord/slack/telegram dom_snapshot: hash every row for change detection
  (was capped at first 5–8 — a reorder past that limit wouldn't invalidate
  the cache).
- discord_scanner/dom_snapshot: simplify is_channel_row (single
  attr lookup); tighten the pure-unread-marker comment (dropped the
  obsolete recipe.js cross-reference).
- slack_scanner/dom_snapshot: align find_badge with the Discord behavior
  (empty badge text → Some(0), matching the marker-present-but-no-count
  semantics).

Deferred (explicitly called out in the PR): shared CdpConn dedup across
scanners, shared DomScan/ChannelRow types across provider dom_snapshot
files, graceful session shutdown, table-driven scanner startup macro.

* fix(webview): CR round-2 — session teardown, exact target match, real-url validation

- cdp/session.rs: use exact equality for the per-account target match
  (`t.title == marker || t.url.ends_with(&fragment)`), so
  `…account-abc` can't be mistaken for `…account-abcdef`. Scanners
  (whatsapp/telegram/slack/discord) also switched from `url.contains` to
  `url.ends_with` on the fragment for the same reason.
- cdp/session.rs: `spawn_session` now returns `JoinHandle<()>`.
- webview_accounts: store the CDP session handle keyed by account_id in
  `WebviewAccountsState.cdp_sessions`, abort any prior handle before
  spawning a new one on re-open, and abort on close/purge so reopen
  cycles don't stack live CDP loops.
- webview_accounts: validate `real_url_str` as a `Url` up front (was
  only validating the placeholder), so a malformed `args.url` fails the
  command instead of crashing the async session loop later.
- webview_accounts: `provider_is_supported` now derives from
  `provider_url` (single canonical registry, no drift).
- telegram_scanner/dom_snapshot: row ids now always include `idx`, so
  two chats with the same display name don't collide into one id.

* fix(webview): CR round-3 — scanner prefix, empty-rows emit, wry UA fallback

- DOM poll: drop `!scan.rows.is_empty()` guard in discord/slack/telegram
  fast-ticks so the zero-unread transition (last chat read) still emits a
  hash-change snapshot. Consumers lose the "clearing" state otherwise.
- webview_accounts: derive `scanner_url_prefix` from the validated
  `real_url`'s origin (via `Url::origin().ascii_serialization()`), not
  the static `provider_url(...)`. Debug `args.url` overrides and
  alternate hosts now drive the scanner target match correctly.
- webview_accounts: cfg-split `build_init_script`. Under cef, migrated
  providers return an empty script (zero injection, unchanged). Under
  wry, migrated providers that fingerprint on `navigator.*` still ship
  `ua_spoof.js` even though their recipe is gone — the previous early
  return dropped the UA shim, which would regress Slack/Google login
  gates on wry dev builds.
2026-04-21 23:15:31 -07:00
CodeGhost21andGitHub bdbb83772e feat(observability): Sentry release tracking, source maps, and end-to-end DSN plumbing (#734)
* ci(release): bake Sentry DSN into shipped tauri bundle

Released builds weren't reporting anything to Sentry. Root cause: the
tauri.conf.json `beforeBuildCommand` re-runs `vite build` inside
`cargo tauri build`. The prior `yarn build` step set `VITE_SENTRY_DSN`
for its own run, but the tauri step did not — so the rebuild produced
a DSN-less `dist/` that overwrote the good one, and the shipped web UI
initialized Sentry with an empty DSN (`initSentry` returns early when
`!SENTRY_DSN`).

Fix:

- `release.yml` / `build-desktop` — declare `VITE_SENTRY_DSN` and
  `VITE_DEBUG` on the tauri-build step so the `beforeBuildCommand`
  rebuild bakes them into the final bundle.
- `release-packages.yml` / `build-cli-linux-arm64` — guard against a
  missing `vars.OPENHUMAN_SENTRY_DSN` so the Linux arm64 CLI tarball
  cannot ship without error reporting baked in via `option_env!`.

The core sidecar's `option_env!("OPENHUMAN_SENTRY_DSN")` already gets
the value from the dedicated "Build sidecar core binary" step; the
tauri shell doesn't rebuild it (separate crate, not a workspace dep),
so the baked DSN survives into the bundled installer.

* feat(observability): Sentry release tracking + source maps (#405)

Tags every Sentry event with a canonical release identifier shared by
the frontend and Rust core, uploads source maps so stack traces are
symbolicated in the dashboard, and adds a CLI probe for repeatable
verification of any future release.

Release identifier

  openhuman@<semver>[+<short_git_sha>]

- Frontend (`app/src/utils/config.ts::SENTRY_RELEASE`) builds the tag
  from `VITE_BUILD_SHA`.
- Core sidecar (`src/main.rs::build_release_tag`) builds the same tag
  from `option_env!("OPENHUMAN_BUILD_SHA")`, so events from both
  surfaces group under one release. Cargo's fingerprint already tracks
  `option_env!` changes.

Environment separation

- Frontend: new `APP_ENVIRONMENT` export (`development` | `staging` |
  `production`) derived from `VITE_OPENHUMAN_APP_ENV`, passed to
  `Sentry.init`.
- Core: `resolve_environment` honors `OPENHUMAN_APP_ENV` at runtime,
  falling back to `debug_assertions` detection.

Source-map upload

- `@sentry/vite-plugin` added as an app devDependency.
- `vite.config.ts` emits source maps unconditionally and registers the
  plugin only when `SENTRY_AUTH_TOKEN` is present, so local dev skips
  silently. The plugin uploads `dist/**/*.js{,.map}` under the
  canonical release name and then deletes the on-disk `.map` files so
  they never ship to end users.

CI wiring (`release.yml` + `release-packages.yml`)

- `Build frontend` and `Build and package Tauri app` both receive
  `VITE_BUILD_SHA`, `SENTRY_RELEASE`, `SENTRY_AUTH_TOKEN`, `SENTRY_ORG`,
  `SENTRY_PROJECT_FRONTEND`. The tauri step needs the same env because
  its `beforeBuildCommand` re-runs `vite build`.
- `Build sidecar core binary` receives `OPENHUMAN_BUILD_SHA` so
  `option_env!` bakes the short SHA into the release tag.
- `build-cli-linux-arm64` mirrors `OPENHUMAN_BUILD_SHA` and
  `OPENHUMAN_APP_ENV` for the arm64 CLI tarball.

Verification support

- New `openhuman sentry-test` CLI subcommand captures an `Error`-level
  event against the currently-initialized client, flushes, and prints
  the event UUID. Optional `--panic` flag exercises the panic
  integration. Requires a DSN resolvable at runtime or baked in at
  compile time; exits non-zero otherwise so misconfiguration is loud.
- `src/main.rs` now loads `.env` before `sentry::init`, so a DSN
  defined only in the repo-local dotenv file (common dev case) is
  honored by the startup-time Sentry client.

Docs

- `docs/sentry.md` covers the release identifier, environment table,
  source-map pipeline, required CI variables, and a verification
  runbook with troubleshooting tips.
- `.env.example` + `app/.env.example` document the new build-time vars.
2026-04-21 22:48:20 -07:00
Steven Enamakel 3131b3829d feat(release): enhance macOS artifact upload and signing process
- Updated the release workflow to include signing of macOS .app tarballs with the Tauri updater key, ensuring integrity for installed clients.
- Modified the upload script to handle the signing process and added error handling for missing signing keys.
- Removed Linux x86_64 asset handling from the updater manifest to streamline the release process.

These changes improve the security and reliability of macOS artifact uploads in the release workflow.
2026-04-18 09:46:45 -07:00
Steven Enamakel a23f2373fd chore(release): comment out Ubuntu platform configuration in release workflow
- Commented out the Ubuntu 22.04 platform configuration in the release.yml file to streamline the workflow and focus on active platforms.
- This change helps maintain clarity in the release process by reducing clutter from unused configurations.
2026-04-18 06:25:51 -07:00
Steven Enamakel 420adc2326 feat: enhance Tauri CLI caching and installation process
- Updated the release workflow to include caching for the vendored `tauri-cli` binary and its installation metadata, improving build efficiency across platforms.
- Modified the `ensure-tauri-cli.sh` script to restore the cached binary if available, reducing installation time and ensuring the correct version is used.
- Changed the build script to utilize `cargo tauri build` instead of `npx tauri build`, aligning with the new CLI setup for better integration with the CEF-aware environment.

These changes streamline the development workflow and enhance the reliability of the Tauri setup.
2026-04-18 06:00:27 -07:00
Steven Enamakel be7576c17e feat(release): re-enable Ubuntu and Windows platform configurations in release workflow
- Added back the previously commented-out configurations for Ubuntu 22.04 and Windows in the release.yml file, allowing builds for these platforms to be included in the release process.
- Updated the arguments, targets, and artifact suffixes for both platforms to ensure proper handling during the release workflow.

These changes enhance the cross-platform support in the release process, ensuring that builds for Ubuntu and Windows are correctly generated and published.
2026-04-18 01:31:42 -07:00
Steven Enamakel 480ba9f746 chore(release): update release workflow to improve readability and organization
- Commented out unused platform configurations for Ubuntu and Windows in the release.yml file to streamline the workflow.
- Reformatted the `needs` section in the `Publish draft release` and `Remove release and tag if build failed` jobs for better clarity and consistency.

These changes enhance the maintainability of the release workflow by improving its structure and readability.
2026-04-17 21:23:17 -07:00
Steven Enamakel e98f537fb7 feat(release): publish latest.json for Tauri auto-updater on production
The updater was wired client-side (prepareTauriConfig.js sets
plugins.updater.endpoints to
https://github.com/tinyhumansai/openhuman/releases/latest/download/latest.json
and embeds UPDATER_PUBLIC_KEY) but the manifest itself was never
generated after we moved off tauri-action — so installed apps would
fetch 404 and believe they were up to date forever.

Add scripts/release/publish-updater-manifest.sh which:
- Lists the release's assets via gh CLI
- Finds the updater bundles produced by createUpdaterArtifacts=true
  (.app.tar.gz for macOS, .AppImage.tar.gz for Linux, -setup.nsis.zip
  for Windows) for each of darwin-aarch64 / darwin-x86_64 /
  linux-x86_64 / windows-x86_64
- Reads the matching .sig files (minisign base64 payloads)
- Composes latest.json per the Tauri v2 static-manifest schema with
  version, pub_date, notes, and a platforms map
- Uploads it to the release via gh release upload --clobber

Wired as a new production-only job `publish-updater-manifest` that runs
after the build-desktop matrix. publish-release now waits on it, and
the asset-validation step requires /^latest\.json$/ so releases can't
ship without the manifest. cleanup-failed-release also tears down
if the manifest step fails.

Staging builds are deliberately skipped — they shouldn't poison the
public updater endpoint.
2026-04-17 21:12:47 -07:00
Steven EnamakelandGitHub 93e85c2df3 feat(build): make CEF the default webview runtime across builds, tests, and releases (#641)
- Flip `app/src-tauri/Cargo.toml` `default = ["cef"]` (wry is now opt-in via
  `--no-default-features --features wry`). `cef-dll-sys` auto-downloads the
  Chromium runtime per-target at compile time.
- Update dev scripts: `dev:app` now uses CEF + keychain safe-storage setup;
  `dev:cef` aliased to it; new `dev:wry` for opt-out; `macos:build:*` and
  `tauri:build:ui` switched to `cargo tauri` so the CEF-aware bundler runs.
- Replace `tauri-apps/tauri-action@v0.6.2` / `yarn tauri build` with
  `cargo tauri build` in `build.yml`, `build-windows.yml`, and `release.yml`.
  The upstream `@tauri-apps/cli` binary does not bundle CEF framework files
  into the produced installer — only the fork at `vendor/tauri-cef` does, so
  workflows must use the fork's CLI or the shipped apps fail to launch.
- Bake the CEF-aware `cargo-tauri` into `ghcr.io/tinyhumansai/openhuman_ci`
  by compiling it from the submodule during Docker image build, plus CEF
  runtime libs (libnss3, libgbm1, libxshmfence1, …). Skips the per-run
  cargo-install in the container-based `build.yml`.
- Cache CEF downloads per-OS in matrix jobs (~400MB/platform) and cache the
  compiled `cargo-tauri` binary on raw GH runners (build-windows, release).
- Explicit `gh release upload` step for Linux + Windows installers since the
  tauri-action upload path was removed; macOS keeps its existing re-sign +
  notarize + re-upload flow.
2026-04-17 19:59:12 -07:00