feat(updater): in-app update on desktop, releases link on Android

Anyone who installed an AppImage or ran the Windows installer was frozen
on that version forever. Nothing in the app ever mentioned a new release
existed, and the release notes were the only announcement.

Desktop now checks a signed manifest, shows the version and its notes in
Settings, and installs and relaunches on request. The signature check is
the whole point: it is what stops a substituted download from being
installed by the app itself. Windows binaries stay unsigned for
SmartScreen purposes -- that is a code-signing certificate, a separate
problem -- but the update payload is verified against our own key.

Android is deliberately not wired to the updater. An app may not replace
its own APK; that is the package installer's job, and the plugin has no
Android implementation. It gets a link to the releases page instead of a
button that would throw.

The plugins are gated with a target-triple cfg rather than
cfg(desktop). Cargo only evaluates target cfgs in a [target.'cfg(..)']
table, so cfg(desktop) matches nothing, silently drops the dependency,
and fails much later with "Permission updater:default not found" -- which
is exactly what the first attempt here did.

Where the manifest lives took some finding. This Gitea serves
/releases/download/<tag>/<asset> but 404s on
/releases/latest/download/<asset> (verified against a real asset), so
there is no stable latest-release URL. The gitea-pages branch is
force-pushed wholesale by publish-docs.yml, so it cannot host the file
either. latest.json therefore gets its own orphan branch, read over the
raw-file URL, and is published from a scratch repo in RUNNER_TEMP rather
than by switching branches in the checkout -- doing that would have left
the following steps standing on a one-commit history, and the next step
but one runs release:notes against the real commit range.

Also fixed, all of it release-integrity:

  - "appimage" is in bundle.targets. The release notes have advertised an
    AppImage for months; tauri.conf.json never built one, the artifact
    step globbed for *.AppImage, found nothing, and said nothing. The
    step now fails instead.
  - The .AppImage.tar.gz/.sig pair and the NSIS .sig are collected. A
    manifest referencing a signature that was never uploaded fails only
    on the user's machine, so the manifest step also refuses to write an
    entry with an empty signature.
  - Release notes are generated by release:notes from the traceability
    graph, which is what CLAUDE.md has asked for all along, instead of a
    fixed heredoc that said "see CHANGELOG.md for detailed changes" and
    linked "GitHub Issues" on a Gitea-hosted project.
  - The notes tell users how to verify a download with SHA256SUMS.

Requirements UR-077 / DR-217, tests UT-208 (12 cases over the version
comparison and the platform decision, including that a pre-release does
not offer itself as an upgrade to the matching release).

Verified: 1070 frontend tests, cargo check for both the host and
aarch64-linux-android (confirming the plugins are absent there), clippy
-D warnings, svelte-check 0 errors.
This commit is contained in:
2026-08-21 18:41:50 +02:00
parent 96abc3afef
commit 3211c96ecf
14 changed files with 832 additions and 56 deletions
+97
View File
@@ -0,0 +1,97 @@
/**
* Tests for the update decision logic.
*
* TRACES: | DR-217 | UT-208
*
* The pure half is tested here; `checkForUpdate`/`installUpdate` talk to the
* plugin and are exercised by actually cutting a release (see the Phase 3
* verification steps in docs/build/ci-operations.md).
*/
import { describe, it, expect } from "vitest";
import { decideUpdateAction, isNewerVersion, updateCapability, RELEASES_URL } from "./updateCheck";
describe("isNewerVersion", () => {
it("compares each numeric field in order", () => {
expect(isNewerVersion("0.9.2", "0.9.1")).toBe(true);
expect(isNewerVersion("0.10.0", "0.9.9")).toBe(true);
expect(isNewerVersion("1.0.0", "0.99.99")).toBe(true);
expect(isNewerVersion("0.9.1", "0.9.2")).toBe(false);
});
it("does not offer the version already installed", () => {
expect(isNewerVersion("0.9.1", "0.9.1")).toBe(false);
});
it("tolerates a leading v, which is how the tags are written", () => {
// build-release.yml derives VERSION from refs/tags/v0.9.1.
expect(isNewerVersion("v0.9.2", "0.9.1")).toBe(true);
expect(isNewerVersion("0.9.2", "v0.9.1")).toBe(true);
});
it("sorts a pre-release below the release of the same number", () => {
// Otherwise everyone on 0.9.2 gets offered 0.9.2-rc1 as an "upgrade" —
// build-release.yml marks exactly these suffixes as prereleases.
expect(isNewerVersion("0.9.2-rc1", "0.9.2")).toBe(false);
expect(isNewerVersion("0.9.2", "0.9.2-rc1")).toBe(true);
expect(isNewerVersion("0.9.2-rc1", "0.9.1")).toBe(true);
});
it("treats a missing patch field as zero rather than NaN", () => {
expect(isNewerVersion("1.0", "0.9.9")).toBe(true);
expect(isNewerVersion("0.9", "0.9.1")).toBe(false);
});
});
describe("updateCapability", () => {
it("reports install for the desktop platforms", () => {
expect(updateCapability("linux")).toBe("install");
expect(updateCapability("windows")).toBe("install");
expect(updateCapability("macos")).toBe("install");
});
it("reports link-only for mobile", () => {
// tauri-plugin-updater is not compiled for Android at all: an app cannot
// overwrite its own APK. Calling it there would throw, not degrade.
expect(updateCapability("android")).toBe("link-only");
expect(updateCapability("ios")).toBe("link-only");
});
});
describe("decideUpdateAction", () => {
it("offers nothing when the endpoint reported nothing", () => {
expect(decideUpdateAction("linux", null)).toEqual({ kind: "none" });
expect(decideUpdateAction("android", null)).toEqual({ kind: "none" });
});
it("offers a real install on desktop", () => {
expect(decideUpdateAction("linux", { version: "0.9.2", notes: "fixes" })).toEqual({
kind: "install",
version: "0.9.2",
notes: "fixes",
});
});
it("normalises absent notes to null rather than undefined", () => {
// The Svelte side renders `{#if notes}`; undefined vs null is the kind of
// difference that only shows up as a blank panel in front of a user.
expect(decideUpdateAction("windows", { version: "0.9.2" })).toEqual({
kind: "install",
version: "0.9.2",
notes: null,
});
});
it("offers the releases page on Android instead of an install", () => {
expect(decideUpdateAction("android", { version: "0.9.2" })).toEqual({
kind: "open-releases",
version: "0.9.2",
url: RELEASES_URL,
});
});
it("points at Gitea, not GitHub", () => {
// The release body used to link "GitHub Issues" on a Gitea-hosted project.
expect(RELEASES_URL).toContain("gitea.tourolle.paris");
});
});