From fdc13ea06c32ddafea57f2713ffb4cb671487549 Mon Sep 17 00:00:00 2001 From: wangjia <809946525@qq.com> Date: Sat, 1 Aug 2026 23:47:29 +0800 Subject: [PATCH] =?UTF-8?q?fix(ci):=20client=20release-deploy=20=E6=8C=AA?= =?UTF-8?q?=E5=88=B0=20nas=20runner=20+=20=E7=AD=89=E5=85=A8=E5=B9=B3?= =?UTF-8?q?=E5=8F=B0=E6=9E=84=E5=BB=BA?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit client-v1.1.1 首跑:4 平台 build 全绿,但 release-deploy 卡在「Release → Forgejo」curl exit 28(超时,3m3s=release_ensure 60s×3 重试耗尽)。根因: release-deploy `runs-on: mac`(mac-pangolin-2)访问 git.51yanmei.com 走 frps 隧道 → 抖断。deploy-server/deploy-site 同类 Forgejo release 步跑在 ubuntu-latest(nas act_runner,与 gitea 同机/同网)稳定通过(server 仅 13s)。 - runs-on: mac → ubuntu-latest:release-deploy 全为网络/SSH 步骤(下载产物/ 传 Forgejo/SSH pangolin1/通知),无 mac 专属需求,挪到 nas runner 走本地。 - needs: [build-android] → [build-android, build-windows, build-macos, build-ios]: 等全部平台 build 完再发布,修旧竞态(只等 android → macos/ios 产物没传就发布 漏平台)。macos/ios 保留 continue-on-error,失败不阻断已成功平台。 - 更新过时注释(原称 Apple secret 未配 / needs 仅 android+windows)。 yaml 校验通过。build 四平台本身已在 run 639 全绿,本次只修发布环节。 Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01A79VtQA1BwTuQN1ThpvYpo --- .gitea/workflows/deploy-client.yml | 40 ++++++++++++++---------------- 1 file changed, 19 insertions(+), 21 deletions(-) diff --git a/.gitea/workflows/deploy-client.yml b/.gitea/workflows/deploy-client.yml index fc76eca..ec32161 100644 --- a/.gitea/workflows/deploy-client.yml +++ b/.gitea/workflows/deploy-client.yml @@ -90,25 +90,16 @@ jobs: name: windows path: dist/ - # Why build-macos/build-ios don't block the working android+windows pipeline - # when Apple secrets aren't configured yet (they aren't, as of this writing): - # 1. release-deploy's `needs:` below is [build-android, build-windows] - # ONLY — macOS/iOS are NOT dependencies, so release-deploy never waits - # on them and never fails because of them. - # 2. `continue-on-error: true` on both jobs keeps the overall workflow-run - # status green even while compile-macos.sh hard-fails (Apple Developer - # ID / notary secrets absent — see its fail-fast checks) — that failure - # is real signal ("go configure the secrets"), but it shouldn't read as - # "the release pipeline is broken" when android+windows shipped fine. - # 3. compile-macos.sh's own default behavior is to hard-fail (not skip) - # when its secrets are missing (macOS distribution must never ship - # unsigned/unnotarized — see its header comment); compile-ios.sh's - # default is to skip gracefully (exit 0) since an unconfigured iOS - # account is a normal "not set up yet" state, not a defect. Either way - # the job produces no dist/pangolin-macos-x64.zip, and - # release-deploy's "Download all artifacts" step (no `name:` filter) - # simply picks up whatever artifacts DO exist — an absent "macos" - # artifact is not an error there. + # build-macos/build-ios 用 `continue-on-error: true` → 即便 Apple 侧构建抖了 + # (frps 拉 sing-box 源码 / 公证超时等),也不阻塞 android+windows 发布: + # 1. release-deploy 现在 `needs:` 全部四个平台(见下),所以它会**等**全部 + # build 完成再发布 —— 避免旧 `needs: [build-android]` 只等 android、 + # macos/ios 还没传产物就发布导致漏平台的竞态。 + # 2. continue-on-error 让 macos/ios 失败仍算「completed」满足 needs,不使整个 + # workflow 变红、不阻断已成功平台的发布;release-deploy 的「Download all + # artifacts」(无 name 过滤)只捡实际存在的产物,缺某平台不报错。 + # 3. Apple 签名 secret 现已在 gitea 用户级配齐(DEVELOPER_ID_P12/IOS_DIST_P12/ + # APPSTORE_API_* 等),macos/ios 正常应成功;continue-on-error 只是抖动兜底。 build-macos: runs-on: mac continue-on-error: true @@ -177,8 +168,15 @@ jobs: # dist-raw/ 里"当时存在"的产物。windows 机离线 / Apple secret 未配 都不阻塞发版 # (对应平台下载保留 pangolin1 上一版,待可用时下个 client-v* 追上)。 release-deploy: - needs: [build-android] - runs-on: mac + # 等全部平台 build 完再发布,否则 download-artifact 会漏掉尚未上传的平台 + # (原来只 needs build-android → android 一完就发,macos/ios 常还没传产物)。 + needs: [build-android, build-windows, build-macos, build-ios] + # ubuntu-latest = 家里 nas act_runner,与 gitea 同机/同网:Release → Forgejo 的 + # API 调用走本地不过 frps 隧道(mac runner 走 git.51yanmei.com→frps→抖,curl 超时 + # exit 28,3m3s=release_ensure 60s×3 重试耗尽)。deploy-server/deploy-site 同为 + # ubuntu-latest,其 Forgejo release 步稳定通过(server 仅 13s)。此 job 全为网络/ + # SSH 步骤(下载产物/传 Forgejo/SSH pangolin1/通知),无 mac 专属需求。 + runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4