Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
39 commits
Select commit Hold shift + click to select a range
977c1f9
fix(site) Keep port docs in their own language
tony Sep 29, 2026
d5cffbd
fix(site) Resolve native guide and API links
tony Sep 29, 2026
802c2a1
docs(workspace) Teach native CLI tasks in each port
tony Sep 29, 2026
39f8e0e
fix(ci) Wait for the final shell publication
tony Sep 29, 2026
1539597
docs(workspace) Complete native task guides
tony Sep 29, 2026
c7bdbc4
fix(publish) Surface manifest read failures
tony Sep 29, 2026
f2997cb
fix(docs) Preserve code while staging guide links
tony Sep 29, 2026
e7f041c
fix(site) Remove the homepage article toolbar
tony Sep 29, 2026
949f8c3
fix(search) Start with the current port selected
tony Sep 29, 2026
125fccd
fix(site) Integrate older native references
tony Sep 29, 2026
915a0cf
fix(docs[api]) restore the drawer after navigation
tony Sep 29, 2026
84f3772
fix(publish) Dispatch each reviewed port caller
tony Sep 29, 2026
e1c3640
fix(site[native]) Render navigation before first paint
tony Sep 29, 2026
6127b74
fix(scripts[checks]) Stage guides from pinned commits
tony Sep 29, 2026
843278f
feat(ci[publication]) Verify build bytes before publishing
tony Sep 29, 2026
76a14f4
fix(site[native]) Keep tablet navigation compact
tony Sep 29, 2026
b8d8012
fix(site[links]) Open wrapper source directories
tony Sep 29, 2026
5ca071b
test(site[links]) Check wrapper source directories
tony Sep 29, 2026
a2b0043
fix(scripts[mcp]) Capture selected source contracts
tony Sep 29, 2026
50bdf9c
fix(site[mcp]) Include contracts in agent exports
tony Sep 29, 2026
42dd5b7
fix(scripts[provenance]) Record native exporters
tony Sep 29, 2026
0977134
perf(ci[preview]) Reuse the audited site tree
tony Sep 30, 2026
767da8f
fix(docs[Go]) Correct the transport example
tony Sep 30, 2026
e34ebbe
docs(site[wrappers]) Provide complete starter programs
tony Sep 30, 2026
8893bab
fix(scripts[staging]) Keep links on the guide revision
tony Sep 30, 2026
99532a7
fix(scripts[MCP]) Own the Ruby discovery daemon
tony Sep 30, 2026
9a85524
refactor(docs) Integrate port-owned content
tony Sep 30, 2026
509eb1f
test(site[footer]) Handle preview paths
tony Sep 30, 2026
6e2f2a1
docs(writing) Require complete runnable examples
tony Sep 30, 2026
2c4fb70
fix(staging) Defer selected guides to fresh export
tony Sep 30, 2026
11c465a
test(site[footer]) Handle preview paths
tony Sep 30, 2026
84dbdf1
docs(examples) Publish complete capture programs
tony Sep 30, 2026
94f3606
test(prose) Check API links in routine gates
tony Sep 30, 2026
258c360
fix(examples) Clean up partial session startup
tony Sep 30, 2026
0c830a1
Merge complete examples into publishing proof
tony Sep 30, 2026
a0864f0
test(products) Accept Java Gradle settings
tony Sep 30, 2026
1abc30b
test(products) Accept Java Gradle settings
tony Sep 30, 2026
0151f79
docs(products) Publish complete native examples
tony Sep 30, 2026
60ed8f6
Merge complete product examples into publishing
tony Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
153 changes: 3 additions & 150 deletions .github/workflows/deploy-shell.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,6 @@ on:
push:
branches: [main]
tags: ['v*']
pull_request:
# Four chances an hour, off the busy top of the hour. GitHub runs a
# schedule best-effort and drops slots under load: at one an hour, three
# of five slots in a row never ran while a new release waited. A run whose
Expand All @@ -32,14 +31,9 @@ permissions:
contents: read

concurrency:
group: ${{ github.event_name == 'pull_request' && format('deploy-shell-pr-{0}', github.event.pull_request.number) || 'deploy-shell' }}
# A preview of a superseded commit is worth nothing, so a new push replaces
# the run it obsoletes. Queueing them instead made six runs pile up behind
# one another in twenty minutes, each waiting out the one before it.
#
# Never for a push to trunk: that job syncs S3 and invalidates CloudFront,
# and a deploy cancelled halfway through leaves the site inconsistent.
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
group: deploy-shell
# Let each production sync finish before the next one starts.
cancel-in-progress: false

jobs:
# The locale list comes from site/src/i18n/locales.ts, the same module the
Expand Down Expand Up @@ -233,147 +227,6 @@ jobs:
skip-unchanged.mjs
retention-days: 1

build-preview:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version: '26'
cache: pnpm
- name: Install audit tools
run: |
sudo apt-get update
sudo apt-get install --no-install-recommends -y ripgrep
- run: pnpm install --frozen-lockfile

- name: Resolve integrated Ruby and Lua sources
id: integrated-sources
run: |
echo "ruby=$(jq -r .revision site/src/data/api/ruby.json)" >> "$GITHUB_OUTPUT"
echo "lua=$(jq -r .revision site/src/data/api/lua.json)" >> "$GITHUB_OUTPUT"

- uses: actions/checkout@v7
with:
repository: libtmux/libtmux-ruby
ref: ${{ steps.integrated-sources.outputs.ruby }}
path: .port-sources/ruby
persist-credentials: false
- uses: actions/checkout@v7
with:
repository: libtmux/libtmux-lua
ref: ${{ steps.integrated-sources.outputs.lua }}
path: .port-sources/lua
persist-credentials: false

- name: Assemble and check preview
env:
PREVIEW_PREFIX: pr-${{ github.event.pull_request.number }}
LIBTMUX_DOCS_LOCALES_ROOT: /pr-${{ github.event.pull_request.number }}
LIBTMUX_DOCS_VERSION: pr-${{ github.event.pull_request.number }}
LIBTMUX_DOCS_VERSION_KIND: pr
LIBTMUX_DOCS_IS_DEFAULT: 'false'
LIBTMUX_DOCS_CHECKOUT_RUBY: ${{ github.workspace }}/.port-sources/ruby
LIBTMUX_DOCS_CHECKOUT_LUA: ${{ github.workspace }}/.port-sources/lua
run: |
pnpm build:site --versions latest
bash scripts/check-preview.sh _site "$PREVIEW_PREFIX"
- uses: actions/upload-artifact@v7
with:
name: preview-dist
path: _site/pr-${{ github.event.pull_request.number }}/
if-no-files-found: error
retention-days: 1

# Same-repo PRs only. Fork PRs get no secrets on `pull_request` by
# design (a fork's build step above still runs, with no OIDC and no
# secrets in scope — GITHUB_TOKEN aside — so a malicious build script
# gains nothing); this job's `if` is what keeps it that way, not the
# trigger.
#
# The repository went public on 2026-09-06, so a fork pull request is now
# a real scenario rather than a hypothetical one. The guard is unchanged
# and still correct: a fork PR builds and is checked, and simply gets no
# preview URL. That is a degraded experience, not an exposure.
#
# The documented improvement is a `workflow_run` handoff that publishes a
# fork's already-built artifact from a trusted context. It is deliberately
# NOT taken here: such a workflow runs with secrets against a ref the
# forker controls, and every published mistake in that pattern comes from
# trusting `head_sha` or `head_repository` without re-validating them. It
# is worth building carefully, on its own, with its own review — not
# bolted on the day the repo's visibility changed. Widening this `if` is
# never the answer (notes/research/06, 07).
publish-preview:
needs: build-preview
if: |
github.event_name == 'pull_request' &&
github.event.pull_request.head.repo.full_name == github.repository
permissions:
contents: read
id-token: write
uses: ./.github/workflows/reusable-deploy.yml
with:
path-prefix: pr-${{ github.event.pull_request.number }}
artifact: preview-dist
version-kind: pr
environment: docs-preview
secrets:
role-arn: ${{ secrets.LIBTMUX_DOCS_PREVIEW_ROLE_ARN }}
bucket: ${{ secrets.LIBTMUX_DOCS_BUCKET }}
distribution: ${{ secrets.LIBTMUX_DOCS_DISTRIBUTION }}

# `check-publish` needs the production build's artifact, which only a push
# produces, so a pull request never exercised the publisher at all. A preview
# assembly has the same shape one locale down, so the same two scripts run
# against it here and a mistake in either surfaces on the pull request rather
# than on the deploy that uploads. No credentials: the recording stand-in
# prints what would have been called.
check-publish-preview:
if: github.event_name == 'pull_request'
needs: build-preview
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/download-artifact@v8
with:
name: preview-dist
path: _site
- name: Exercise the publisher against the preview assembly
env:
LOCALE: en
BUCKET: reproduction
run: |
set -euo pipefail
node scripts/publication-metadata.mjs
cp scripts/publish-root.sh publish-root.sh
cp scripts/publish-default-versions.sh publish-default-versions.sh
mv "_site/$LOCALE" dist
mkdir bin
# Prints each call, and answers the two store reads the
# default-version publisher parses.
cat > bin/aws <<'SH'
#!/usr/bin/env bash
case "$2" in
describe-key-value-store) echo '{"ETag":"dry-run"}' ;;
list-keys) echo '{"Items":[]}' ;;
*) printf 'aws'; printf ' %q' "$@"; printf '\n' ;;
esac
SH
chmod +x bin/aws
PATH="$PWD/bin:$PATH" bash publish-root.sh

# Against the build's own versions.json: a preview merges no published
# fragments.
- name: Exercise the default-version publisher against the preview assembly
env:
KVS_ARN: reproduction
run: |
set -euo pipefail
PATH="$PWD/bin:$PATH" bash publish-default-versions.sh

check-publish:
if: github.event_name != 'pull_request'
needs: [locales, build]
Expand Down
Loading
Loading