# The build, on rickub. GitLab CI next door reads source and no more — # check-common on every push, the flake.lock nightly — and deliberately builds # nothing. This is the other half: the desktop bundle, actually assembled. # # It is not assembled *here*, though it nearly could be now. The job hands the # work to Modal exactly as a person at a terminal would, and the Sandbox does # it against the `devshell` volume. What a runner contributes is a checkout, a # python, and somewhere to put the result afterwards. # # It used to be `nix build .#appimage`, which a rickub runner could not have # done at all — a container against libjoltcosmic's dependency tree is the # laptop-shaped death CLAUDE.md warns about. That is no longer what the # container runs: jolt, the backends and libmoq_ffi all arrive pinned and # prebuilt, so the Modal side fetches and copies rather than compiling. The # reason it still goes to Modal is the volume the toolchain is cached on, not # the size of the build. # # Lives in .rickub/workflows/ rather than .github/workflows/ because rickub # reads one or the other and never both: with this directory present, a # .github/workflows/ added later would be silently ignored. There is none # today, so nothing is being shadowed — see # https://rickub.com/docs/actions and https://rickub.com/docs/migrating-from-github name: build on: push: workflow_dispatch: jobs: # The same read-only check GitLab runs, for the same reason: common/ compiles # twice and only the jolt half is on the way to anything anyone runs, so a # JVM call in shared code breaks the phone at a namespace nobody touched. # Seconds, no toolchain. Worth having on both hosts rather than depending on # which one a given push reaches. check-common: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - run: python3 tools/check-common.py common desktop: runs-on: ubuntu-latest needs: check-common # Minutes now, not an hour. The Modal side compiles one .c file; what it # spends its time on is fetching the pinned pieces on a cold toolchain and # the upload of the tree from here. timeout-minutes: 30 steps: # The container copies `.` — the whole working tree, uncommitted edits # included. On a runner that is whatever the checkout left, so it wants # to be the commit and not a shallow surprise. - uses: actions/checkout@v4 - uses: actions/setup-python@v5 with: python-version: "3.12" - run: pip install --disable-pip-version-check modal # Two secrets, set under Settings -> Secrets and variables. A Modal # token is the whole of this job's configuration: no nix, no builder, # no cache of its own. - name: Assemble the desktop bundle, on Modal env: MODAL_TOKEN_ID: ${{ secrets.MODAL_TOKEN_ID }} MODAL_TOKEN_SECRET: ${{ secrets.MODAL_TOKEN_SECRET }} # Unpiped on purpose. The image build streams to this client and # nowhere else, and `modal app logs` cannot reach an ephemeral run — # so this terminal is the only place the build is visible. tee, not # tail: a run killed mid-pipe through tail takes its output with it. run: modal run .modal/frq/container.py 2>&1 | tee /tmp/frq-build.log # The Sandbox leaves the tarball on the devshell volume rather than # anywhere a runner can see, so fetch it back out. One file, already a # squashed tree — nothing to import on the other end, and nothing to # unpack before it can be uploaded. - name: Fetch the bundle out of the volume env: MODAL_TOKEN_ID: ${{ secrets.MODAL_TOKEN_ID }} MODAL_TOKEN_SECRET: ${{ secrets.MODAL_TOKEN_SECRET }} run: | modal volume get --force devshell \ artifacts/frq-desktop-x86_64-linux.tar.gz \ frq-desktop-x86_64-linux.tar.gz - uses: actions/upload-artifact@v4 with: name: frq-desktop-${{ github.sha }} path: frq-desktop-x86_64-linux.tar.gz if-no-files-found: error # Kept whether or not the build succeeded: a failed run's log is the # one most worth reading, and it is gone with the runner otherwise. - uses: actions/upload-artifact@v4 if: always() with: name: build-log path: /tmp/frq-build.log if-no-files-found: ignore