Skip to content

release: ship macOS x86_64 (Intel) builds from macos-15-intel - #378

Merged
eval-exec merged 2 commits into
mainfrom
release-macos-x86_64
Sep 12, 2026
Merged

eval-exec merged 2 commits into
mainfrom
release-macos-x86_64

Conversation

@eval-exec

Copy link
Copy Markdown
Owner

Closes the last single-arch hole in the release matrix: Linux and Windows each ship x86_64 + aarch64; macOS shipped aarch64 only, and install.sh told Intel Macs "no Intel Mac (x86_64) builds are published yet".

Why now: macos-15-intel is GitHub's last x86_64 runner image, promised only until August 2027 (macos-13 closed in Dec 2025). Native builds are cheap while the image exists; afterwards the only path is cross-compiling + Rosetta for the pdump bootstrap.

  • release.yml — new build-macos-x86_64 job (copy of the aarch64 job, same RELEASE_FEATURES, same signing/notarization secrets); arch-suffixed notarization-diagnostics artifacts; create-release waits on it.
  • ci.yml — check matrix gains macos-x86_64, so the target compiles on every PR instead of being discovered at tag time.
  • package-macos-app.sh — artifact triple derived from the build host instead of hardcoded aarch64-apple-darwin (vendor-macos-runtime.sh already thins to the same value).
  • generate-release-notes.sh + test — three x86_64 macOS containers in the required list and download table (18 links).
  • install.sh — darwin:x86_64 resolves the triple instead of dying.

Verification: test-generate-release-notes.sh passes; the xtask RELEASE_FEATURES pinning test passes; both workflows parse with the new wiring asserted; this PR's CI runs the new check entry, and a branch dispatch of the tmp macOS fresh-build workflow exercises compile + bootstrap + pdump natively on macos-15-intel.

Every other platform in the release matrix publishes two architectures
(Linux x86_64/aarch64, Windows x86_64/aarch64) while macOS shipped
aarch64 only, and install.sh answered Intel Macs with "no Intel Mac
(x86_64) builds are published yet".  This closes that gap.

Why now: actions/runner-images#13045 promises the macos-15-intel image
only until August 2027 and names it the LAST x86_64 runner image;
macos-13, the previous Intel image, closed in December 2025.  Building
the target natively is cheap while the image exists.  Afterwards the
only path is cross-compiling x86_64-apple-darwin on an arm64 runner and
running the pdump bootstrap under Rosetta.

- release.yml: new build-macos-x86_64 job, a copy of the aarch64 job on
  macos-15-intel.  RELEASE_FEATURES is unchanged: darwin declares one
  cargo-features list for the platform, and the xtask test pinning the
  release jobs to that table passes because both macOS jobs carry the
  same value.  Developer ID signing and notarization reuse the same
  secrets, which are architecture-agnostic.  The failure-only
  notarization-diagnostics uploads are now arch-suffixed on both jobs so
  a simultaneous failure cannot collide on one artifact name.
  create-release waits on the new job before publishing.
- ci.yml: the workspace check matrix gains macos-x86_64 on the same
  image, so an x86_64-apple-darwin breakage surfaces on every PR instead
  of being discovered at tag time.
- package-macos-app.sh: derive the artifact triple from the build host
  instead of hardcoding aarch64-apple-darwin.  vendor-macos-runtime.sh
  already thins bundle images against the same value (its
  MACOS_BUNDLE_ARCH default is uname -m), so the asset name and the
  bundle contents always describe one architecture.
- generate-release-notes.sh + test-generate-release-notes.sh: the
  required-asset list and the download table gain the three x86_64 macOS
  containers; macOS renders as two arch groups of three rows, mirroring
  the Windows layout (18 download links total).
- install.sh: darwin:x86_64 resolves x86_64-apple-darwin instead of
  dying.

Verification: scripts/test-generate-release-notes.sh passes;
cargo test -p xtask release_jobs_share_the_features_their_platform_declares
passes; both workflows parse under PyYAML with the new job's
runner/target/features, the arch-suffixed diagnostics artifacts, and
create-release's needs asserted; PR CI runs the new ci.yml check entry
and the branch's tmp macOS fresh-build dispatch compiles, bootstraps and
pdumps natively on macos-15-intel.
verify-macos-install-script ran on macos-latest (arm64) only, so exactly
one of the two macOS tarballs was ever exercised after publication.
install.sh selects its asset from uname -m, so each architecture needs
its own runner to verify its own tarball: matrix the job over aarch64
(macos-latest) and x86_64 (macos-15-intel), the same last-Intel-image
dependency as the new build job.  The run steps are arch-neutral.

Also finish the packaging-script text that release-macos-x86_64 missed:
package-release.sh's usage named only aarch64-apple-darwin as the macOS
default, though its detect_target already derives the host arch.
@eval-exec
eval-exec marked this pull request as ready for review September 12, 2026 10:40
Copilot AI balanced review requested due to automatic review settings September 12, 2026 10:40
@eval-exec
eval-exec merged commit 331cca6 into main Sep 12, 2026
54 of 102 checks passed
@eval-exec
eval-exec deleted the release-macos-x86_64 branch September 12, 2026 10:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It modifies the high-impact release pipeline (code signing/notarization and a new native build job) and depends on the external macos-15-intel runner, which cannot be fully verified here and warrants human sign-off.

Pull request overview

This PR closes the last single-arch gap in the release matrix by shipping native macOS x86_64 (Intel) builds from GitHub's macos-15-intel runner image, so Intel Macs get published .dmg/.zip/.tar.gz assets and install.sh can resolve them instead of erroring. It fits into the existing release pipeline where Linux and Windows already ship both x86_64 and aarch64.

Changes:

  • Adds a native build-macos-x86_64 release job (mirroring the aarch64 job) and wires it into create-release; arch-suffixes the notarization-diagnostics artifacts and matrixes the macOS install-script verification.
  • Adds a macos-x86_64 entry to the CI check matrix so the target compiles on every PR, and derives the macOS artifact triple from uname -m in package-macos-app.sh.
  • Extends release-notes generation/tests and install.sh to include the three new x86_64 macOS assets (download table now 18 links).
File summaries
File Description
.github/workflows/release.yml New build-macos-x86_64 job, arch-suffixed diagnostics artifact, create-release dependency, and matrixed macOS install-script verification.
.github/workflows/ci.yml Adds macos-15-intel/macos-x86_64 to the check matrix so x86_64-apple-darwin compiles on every PR.
scripts/package-macos-app.sh Derives the artifact triple from uname -m (arm64→aarch64, x86_64) instead of hardcoding aarch64.
scripts/generate-release-notes.sh Adds x86_64 macOS asset variables, download-table rows (rowspan 6), and required-asset entries.
scripts/test-generate-release-notes.sh Adds the three x86_64 macOS assets and updates the expected download-link count to 18.
install.sh Resolves darwin:x86_64 to x86_64-apple-darwin instead of failing.
scripts/package-release.sh Help-text update noting aarch64/x86_64 macOS defaults (documentation only).
Review details
  • Files reviewed: 7/7 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +245 to +247
build-macos-x86_64:
name: build macOS x86_64
runs-on: macos-15-intel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants