Commit graph

410 commits

Author SHA1 Message Date
Dan Stillman
22f08d1ced Fix changelog URL generation for two-digit major versions
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
The short version was derived from the first three characters of the
version string, so 10.0 produced a detailsURL of "10._changelog".

(cherry picked from commit 5757396197)
2026-08-17 12:30:00 -04:00
Dan Stillman
395224d7ac Update release script to 10.0 branch
And delete 8.0 script
2026-08-17 10:42:31 -04:00
Dan Stillman
4d571e2b74 Update to Firefox 140.14.0esr 2026-08-17 10:23:34 -04:00
Dan Stillman
7c52e30137 Update to Firefox 140.13.0esr
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
2026-08-13 22:02:58 -04:00
Dan Stillman
d6498a1906 Switch to 10.0 branch for beta builds
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
2026-08-12 14:30:46 -04:00
Dan Stillman
9230e935dc Check that local app/ matches commit being built before deploying
The build-and-deploy scripts run scripts and config from the local
checkout but build source files from the tip of the remote branch, so
a stale or wrong-branch checkout could silently build with the wrong
Gecko version or omni patches.

(cherry picked from commit d9d52de516)
2026-08-12 12:51:00 -04:00
Mynacol
b5ea455c1f
Fix release build on x86 mac (#5926)
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
While trying to [fix](https://github.com/NixOS/nixpkgs/pull/519431) another issue in the Zotero package for nixpkgs, I discovered a new bug. When setting a non-`source` update channel, the build fails on MacOS with x86 architectures.

The build fails with:
```
source not found twice in ChannelPrefs

source

stringWithCString:encoding:
```
Which definitely means it is caused by the `strings` command [here](https://github.com/zotero/zotero/blob/main/app/mac/set-channel-prefs-channel#L29).

When manually executing the strings command on the file, I can repeat getting only one `source` result on x86 mac, while getting two on arm64 or linux. After digging around, I tried with the flag `-arch all`, and both `source` values are found on x86 mac. Full command: `strings -n 3 -arch all $binary`.
2026-07-31 13:41:33 -04:00
Dan Stillman
ce20a5f228 Ship legacy Safari App Extension alongside the web extension on Mac
Developer ID-signed Safari web extensions load only in Safari 18.4 and
later -- older Safari blocks them at the code-signing layer -- so macOS
11 and 12 users, whose Safari versions top out at 16.6 and 17.6, lost
the connector with the web extension conversion.

Embed the prebuilt legacy App Extension ($SAFARI_APP_EXTENSION, set by
the deploy scripts) at Contents/PlugIns/ZoteroSafariExtension.appex with
the historical bundle identifier, and move the web extension to
Contents/PlugIns/ZoteroSafariWebExtension.appex with a new
.SafariWebExtension identifier. The web extension's
SFSafariAppExtensionBundleIdentifiersToReplace key causes Safari
versions that can load it to hide the App Extension and migrate its
enabled state, while older Safari shows only the App Extension.

Also remove the removed-files entries for the App Extension's
resources, which would otherwise delete them on update.

https://forums.zotero.org/discussion/132925/
2026-07-28 07:24:27 -04:00
Dan Stillman
91d7e73d26 Strip com.apple.FinderInfo xattrs from files in Mac disk images
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
hdiutil makehybrid gives every file on the image non-empty Finder info
(it sets an icon location), which appears as a com.apple.FinderInfo
extended attribute. codesign --verify --strict rejects FinderInfo as
detritus, and it can cause Safari to fail to load the web extension.
(Reported by a user with Safari 17.6 on macOS 12. No other reports from
the beta, so maybe not universal.) The Safari App Extension apparently
wasn't affected, since it shipped with the same attributes for years.

Convert the hybrid image to a read-write image, mount it, strip the
attributes from its files, and compress from that. The volume header is
untouched, so the open-folder flag that makes Finder open the volume
window on mount is preserved.

Only fresh installs from the DMG were affected. The updater writes fresh
files without the attributes, so copies updated in place were clean.
(Notably, this is the reverse of the post-update extension breakage for
which the standard advice has always been to delete Zotero.app and
redownload. Following that advice is exactly what resulted in a broken
copy here.)

https://forums.zotero.org/discussion/132925/
2026-07-27 15:31:18 -04:00
Dan Stillman
6fb30346e6 Bundle Safari web extension instead of Safari App Extension
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
The connector is now a Safari web extension, so the bundled appex is a
static wrapper stub whose placeholder resources are replaced at build
time with a connector build via $SAFARI_EXT_RESOURCES. The stub only
needs to be rebuilt when the native wrapper project changes, not for
connector releases.
2026-07-22 15:11:23 -04:00
Dan Stillman
228799774f Sign both per-arch JNA .jnilibs in LibreOffice plugin during Mac build
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
JNA 5.x ships per-architecture macOS native libraries instead of a
single com/sun/jna/darwin/ directory, so the notarization re-signing
step failed with "filename not matched".

This step can be removed entirely once the plugin ships a jna.jar
without the macOS natives, which are never loaded.
2026-07-16 12:54:47 -04:00
Dan Stillman
bdea584a17 Update LibreOffice submodule 2026-07-14 13:39:07 -04:00
Dan Stillman
dea2fb8491 Fix build_for_deploy dying silently on an empty incrementals file 2026-07-10 15:26:52 -04:00
Dan Stillman
1c9bf88888 Unpack update archives for different architectures in parallel
Some checks are pending
CI / Test (shard 1) (push) Waiting to run
CI / Test (shard 2) (push) Waiting to run
CI / Test (shard 3) (push) Waiting to run
CI / Test (shard 4) (push) Waiting to run
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
2026-07-08 12:10:46 -04:00
Dan Stillman
39a1c56f6c Cache update diffs and compressed files across builds
Cache patches and compressed files by content hash so that they're reused
across FROM versions and releases. Cache entries are touched when used and
expire after 60 days.

The cache key includes a tag covering the xz/mbsdiff versions and the
compression options, so entries are invalidated when the toolchain changes.
2026-07-08 12:10:45 -04:00
Dan Stillman
d07dd66c21 Parallelize update MAR generation
Run the per-file mbsdiff/xz work in make_incremental_update.sh and
make_full_update.sh through a parallel job pool, largest files first, and
assemble the manifests serially afterward, producing byte-identical MARs.

Set UPDATE_PACKAGING_JOBS to override the number of parallel jobs.
2026-07-08 12:10:45 -04:00
Dan Stillman
bd25413213 runtests.sh: Add -p option to run a shard of the test files (e.g., -p 2/4)
The sorted file list is split into contiguous chunks of roughly equal total
file size, using size as a stand-in for run time, so new test files are
included automatically and slow test files are spread across shards rather
than landing in the same shard by chance. Contiguous chunks preserve the
alphabetical run order of a full run, so files keep the same preceding files
as in a full run except at chunk starts, and a shard can be reproduced locally
by passing its first and last files to -s and -e.
2026-07-08 10:50:32 -04:00
Dan Stillman
094d5cc2b6
Update staged builds in place for faster dev builds (#5994)
After a full build, dir_build saves a manifest of build/ files to
staging/.build-manifest. On subsequent runs, if all changed files are
ones that build.sh copies into omni.ja unmodified (chrome/, components/,
resource/, and test/ when tests are staged), zip just those files into
the staged omni.ja instead of rebuilding, taking rebuilds from ~15
seconds to ~0.3 seconds on an M1 Mac. Files are prescreened by size and
mtime so that only changed files need to be hashed. Zotero .ftl files
are also updated at their localization/<locale>/ paths, and test files
are also copied to the staged tests/ directory.

Any other change triggers an automatic full rebuild: files transformed
by build.sh (defaults/, chrome.manifest, version, translators/, styles/,
mozilla .ftl files, CSL locales), removed files, changes to build inputs
in app/ (detected via a size/mtime fingerprint, with xulrunner runtimes
covered by the hash-* files written by fetch_xulrunner), or requesting
tests or devtools that the staged build doesn't include.

Other changes:

- dir_build no longer takes -q and always skips omni.ja compression and
  optimization, which only matter for distribution builds made via
  build.sh. Use -f (dir_build or build_and_run) to force a full rebuild.
- build_and_run now always rebuilds. -r is deprecated, and -n skips the
  rebuild and just launches the app.
- build_and_run no longer passes -purgecaches. Startup caches are
  invalidated automatically when the BuildID changes, which now happens
  whenever omni.ja is modified (including via add_omni_file), so
  relaunching an unchanged build can use the startup cache.
- build_and_run and runtests.sh invoke js-build directly instead of via
  'npm run', which saves ~270ms of npm overhead per build.
- The Word integration dylib is now ad-hoc-signed by dir_build, and only
  on full rebuilds, since incremental updates don't invalidate the
  existing signature. This also covers test builds, which were never
  signed before.
- dir_build removes broken symlinks left in build/ when source files are
  deleted, which previously broke rsync in prepare_build.
2026-07-08 10:07:58 -04:00
Tom Najdek
95ee1c616c
Fix xulrunner_hash to read the hash from openssl output on LibreSSL/macOS
Some checks are pending
CI / Build, Upload, Test (push) Waiting to run
Previous command only worked with OpenSSL's labeled output where the hash is the second field; the update also handles LibreSSL (macOS), which prints just the bare hash.
2026-07-01 20:14:30 +02:00
Dan Stillman
40b272c46b Add -b (build-only) flag to beta_build_and_deploy 2026-06-30 17:44:49 -04:00
Dan Stillman
1d8cdb13c1 Update Windows build to Firefox 140.12.0esr 2026-06-30 16:41:38 -04:00
Dan Stillman
d28bdd8d6e Update Mac and Linux builds to Firefox 140.12.0esr
Some checks are pending
CI / Build, Upload, Test (push) Waiting to run
2026-06-30 15:09:55 -04:00
Adomas Venčkauskas
9cffc1c7c2 Update LibreOffice submodule 2026-06-30 14:35:38 +03:00
Dan Stillman
c72d80f22b Update Word for Windows submodule 2026-06-12 12:58:00 -04:00
Dan Stillman
55434d14a1
Encrypt API key and WebDAV password using OS keychain (#5897)
Wraps the values stored in nsILoginManager with OSKeyStore, which derives
its master key from Keychain on macOS, DPAPI on Windows, and libsecret on
Linux. A copy of the profile alone is no longer enough to extract these
credentials.

Existing plaintext entries are mirrored once per session to a new
"(encrypted)" realm but preserved in the original realm so a user can
still downgrade to a release that doesn't know about encryption. Active
credential changes (sign in, sign out, password change) write to the
encrypted realm only and remove the legacy entry. A future version can
clear any remaining legacy entries on startup.

Patches MOZ_APP_BASENAME in the bundled runtime so the keychain master
key is labeled "Zotero Encrypted Storage" rather than "Firefox Encrypted
Storage", with a check_line guard so a future Mozilla change to the
OSKeyStore label format fails the build instead of silently rebranding
the entry. Also fixes check_line to take an explicit file argument.
2026-06-12 11:16:22 -04:00
Dan Stillman
de1bf1cec1 Update Mac Word plugin install flow for macOS 27 Golden Gate
On macOS 27 and later, the installer gets access to the Word startup
folder via a folder-selection dialog rather than an OS permission
prompt, so support an adjusted banner message and add strings for the
folder dialog.
2026-06-10 15:06:01 -04:00
Adomas Venčkauskas
3e7030a642 Update Word for Windows submodule
Some checks are pending
CI / Build, Upload, Test (push) Waiting to run
2026-06-10 12:31:08 +03:00
Dan Stillman
9ca79a2cb1 Update Mac and Linux builds to Firefox 140.11.0esr 2026-05-21 10:43:53 -04:00
Abe Jellinek
714d4416f8 Suppress Crash Reports and RemoteSettings console spam
Some checks failed
CI / Build, Upload, Test (push) Has been cancelled
2026-05-13 14:40:51 -04:00
Abe Jellinek
ba7e036582 Devtools: Fix profiler (Performance tab)
Fixes #5111
2026-05-13 14:01:55 -04:00
Dan Stillman
ddf2419e78 Update Windows builds with Word template compatibility fix from #5904
Some checks are pending
CI / Build, Upload, Test (push) Waiting to run
2026-05-06 10:51:13 -04:00
Adomas Venčkauskas
d66682b04e
Undo Mozilla changes that allow non-UTF-16 command line args (#5904)
To allow old Word Zotero.dotm to continue to work
2026-05-06 10:27:13 -04:00
windingwind
fda72a3434
Fix beta build plugin max version compatibility check (#5903)
Some checks are pending
CI / Build, Upload, Test (push) Waiting to run
Ignore persisted compatibility flag from previous app version in non-stable releases to fix disabled for wrongly using old flag
Ignore max version compatibility for plugin update check on non-stable releases
Relevant: https://forums.zotero.org/discussion/131096/

---------

Co-authored-by: Dan Stillman <dstillman@zotero.org>
2026-05-05 14:26:50 -04:00
Mynacol
ede90ac04a
Make icons directory during build (#5889) 2026-05-04 15:27:03 -04:00
Mi Ramon
462357e49e
"Updating add-ons" → "Updating plugins" (#5893) 2026-04-27 14:50:51 -04:00
Dan Stillman
df6037ce0a Update Windows build to Firefox 140.10.0esr 2026-04-23 13:43:12 -04:00
Dan Stillman
24e16c0aad extract_xul_dll: Process whichever arch ZIPs are present 2026-04-23 13:38:26 -04:00
Dan Stillman
2d14f33de2 Windows build: Copy custom Firefox ZIP back to app/win/ 2026-04-23 13:38:26 -04:00
Dan Stillman
de69835419 Update Mac and Linux builds to Firefox 140.10.0esr 2026-04-23 11:40:55 -04:00
Adomas Venčkauskas
e7ed0b2881 Update Word for Windows submodule 2026-04-23 09:09:06 +03:00
Dan Stillman
1ed1fab55b Switch to 9.0 branch for 9.0 releases 2026-04-10 13:40:13 -04:00
Dan Stillman
a0198e2571 Support pinned incrementals from deploy server
Fetch pinned-incrementals-{platform} from the deploy server and merge
with the normal last-N incrementals list. This ensures incremental MARs
are always built from key versions (e.g., last release of each major
version) regardless of how many newer versions have been released.
2026-04-09 14:35:18 -04:00
Dan Stillman
e96d65f0ed Fix manage_incrementals on Cygwin
Remove Windows path conversion that was needed for aws s3 cp but
breaks scp (which interprets the drive letter colon as a hostname).
2026-04-09 12:32:03 -04:00
Dan Stillman
1a89239a13 Separate build and deploy for release scripts
Split build_and_deploy into build_for_deploy (builds, uploads to S3,
rsyncs manifests) and a deploy script in client-downloads (updates
updates JSON, updates incrementals, runs deploy command).

Release scripts support -b flag for build-only (deploy later manually).
Beta/dev/test scripts build and deploy automatically via SSH.

Move incrementals files from S3 to deploy server. Update DEPLOY_PATH to
root of client-downloads so manifests and deploy script paths are
derived from it.
2026-04-09 11:37:05 -04:00
Dan Stillman
ea230faa26 Add deployment script for 9.0
Some checks are pending
CI / Build, Upload, Test (push) Waiting to run
2026-04-08 14:58:25 -04:00
Dan Stillman
c2ce0af87a Update Windows build to Firefox 140.9.0esr 2026-04-02 15:20:52 -04:00
Dan Stillman
842115ff7e Update Mac and Linux builds to Firefox 140.9.0esr 2026-04-02 11:20:52 -04:00
Dan Stillman
8a0a798672 Update word processor submodules for Add Annotation 2026-03-24 15:38:33 -04:00
Tom Najdek
d3509ae259 Add support for test retries and enable three retries on CI 2026-03-11 14:35:39 -04:00
Adomas Venčkauskas
ce11d5295c Update LibreOffice submodule 2026-03-06 13:57:53 +02:00