Skip to content

linux ci: contents: write for nightly release publish#90

Merged
mdheller merged 3 commits into
mainfrom
fix-linux-publish-perms
Jul 23, 2026
Merged

linux ci: contents: write for nightly release publish#90
mdheller merged 3 commits into
mainfrom
fix-linux-publish-perms

Conversation

@mdheller

Copy link
Copy Markdown
Contributor

The ubuntu leg now builds + packages + AppImages successfully — the swap + mach-package fixes worked. It failed only at the final Publish nightly release step because the workflow lacked permissions: contents: write (unlike nightly-dmg/nightly-windows): the read-only token made gh release upload --clobber 403 (hidden by 2>/dev/null), and the fallback gh release create errored on the nightly-<date> tag a sibling lane already made. One-line fix, identical to the other two lanes. Last step before the first-ever green Linux nightly.

mdheller added 3 commits July 23, 2026 12:29
…a week

The GitHub-hosted nightly-linux has failed every day for 8+ days, across many
commits predating any recent work — all exit 143 (SIGTERM/OOM). Firefox is too
big for the 16GB standard runner without swap. Same fix that got the Windows
lane past its OOM wall: 24G swapfile (ubuntu leg; fedora runs in a container
where swapon isn't available) + cap mach at -j2 so concurrent heavy TUs don't
exhaust RAM. The sovereign builder (32c/128GB) stays at full parallelism.
With the OOM fix, the ubuntu build finally SUCCEEDED for the first time — and
immediately exposed a latent packaging bug: the tarball step tarred a
dist/bearbrowser/ dir that only 'mach package' creates, but the workflow only
ran 'mach build' (which leaves dist/bin). Never surfaced before because the
build always OOM'd first. Now run 'mach package' (proven on the sovereign Linux
builder) and ship its real dist/bearbrowser-*.tar.xz (with omni.ja).

Also mark the fedora leg continue-on-error: it builds in a container where
swapon isn't available (so no OOM headroom) and hits a mirror-recipe cfg-copy
quirk. Ubuntu is the primary Linux artifact and stays blocking.
The ubuntu leg now BUILDS + PACKAGES + makes the AppImage successfully (the
swap+mach-package fixes worked) — it failed only at the final 'Publish nightly
release' step: the default GITHUB_TOKEN is read-only, so 'gh release upload
--clobber' 403'd (hidden by 2>/dev/null) and the fallback 'gh release create'
errored on the nightly-<date> tag a sibling lane had already created. Same
one-line permissions fix already on nightly-dmg + nightly-windows. This is the
last step before the first green Linux nightly.
@mdheller
mdheller merged commit 22d9c08 into main Jul 23, 2026
@mdheller
mdheller deleted the fix-linux-publish-perms branch July 23, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant