Canary and commit builds must not replace stable or share its desktop
state. Package names alone are insufficient because Electron reads the
product name before main initializes its paths. Pin nonstable userData
before the first lookup, and keep the packaged identity independent of
runtime build variables.
Keep release artifact filenames unchanged. Qualify payload CLI names,
route each nonstable MSIX alias to its own entrypoint, and copy the
immutable desktop provenance into the embedded Python checkout. Only
stable releases can use the official Store identity.
Targeted validation: 75 JavaScript tests passed, 2 platform skips;
15 Python tests passed with file retries disabled. Native Windows SDK
manifest proof is tracked separately. Full app install, signing and macOS
launch validation are not claimed.
Keep commit admission on the trusted workflow checkout and reject mixed
release inputs before loading repository code. Stage every built product
under its commit with receipt-bound summary links, never channel writes.
Build both Windows universal bundles through the existing SDK scripts.
Keep Store calendar versions separate from sideload app versions so zero-
major app versions remain packageable. Reject invalid arguments before
modifying bundles. Bind desktop and Termux versions to the source commit,
and record Termux cache provenance without labeling commits as tags.
Verification: 77 Python tests and 36 JS tests passed. Real makeappx packed
and unpacked disposable per-arch and universal packages. Seven official
workflow-expression checks, actionlint, syntax, lint and prose passed.
No signing, installed-app update, Android build, or remote dispatch ran.
The fast-moving desktop prerelease channel is now "canary" everywhere:
the tag shape (vX.Y.Z-canary.<ts>), the electron-updater/R2 feed dirs
(canary.yml / releases/<os>/canary/), the update-channel consts and CLI
choices, the MSIX build-number derivation, the App Installer channel
paths, and the Windows Store flight var (MS_STORE_CANARY_FLIGHT_ID).
Also renames the scheduled workflow to canary-release.yml and the
release test file to test_release_canary.py, and flips the CLI flags
(--canary / --prune-canaries / prune-canaries subcommand).
Unrelated "nightly" mentions are untouched: Brave's own browser channel
(browser_connect), cron scheduling prose (README, i18n, cron/browser/
kanban docs, zh-Hans), upstream skill docs (comfyui/unsloth/torchtitan),
evals fixtures, Node's node-nightly prereleases, and cron job names in
gateway tests.
Note: MS_STORE_NIGHTLY_FLIGHT_ID was renamed to MS_STORE_CANARY_FLIGHT_ID
in the workflow — the matching repo/org variable on GitHub must be
renamed in repo settings for the Store flight ring to keep working.
The msixbundle + finalize jobs were both gated on the entire 6-leg build
matrix, so macos + linux legs blocked the win32 App Installer feed and
everything else downstream.
Restructure desktop-bundled-release.yml into per-OS jobs:
- build-win32 (x64 + arm64) — the only active builder legs; builds the
bundled + Store variants, audits arch, uploads *.msix, stages to R2.
- build-darwin / build-linux — dummy skips for now (no macOS updater arm;
linux unshipped). Matrix kept so downstream jobs stay green; re-enable
by restoring the build body + runners.
- publish-win32-updater (was msixbundle) — needs build-win32 only; stages
the App Installer feed (.appinstaller + universal .msixbundle).
- publish-win32-store (NEW, parallel) — bundles the two Store-*.msix into
one universal Store .msixbundle and submits it to the Windows Store via
the MSStore CLI (microsoft/microsoft-store-apppublisher@v1.4). Stable
tags only; gated on MS_STORE_PRODUCT_ID var so it stays skipped until
the release-signing environment is configured. The store bundle is left
unsigned on purpose — Partner Center re-signs on ingestion.
- publish-darwin-updater (was finalize) — dummy skip; no mac feed to
publish until the darwin electron-updater arm returns.
Shared plumbing: resolveWinSdkTools moves into msix-shared.mjs (single
resolver for both bundle jobs, kills the dead candidates var); new
bundle-store-msixbundle.mjs bundles the store per-arch packages and
prints the bundle path on stdout for the workflow.
Verified: node --check all scripts, yaml parses + needs graph resolves,
107 r2-release tests pass.