#!/usr/bin/env bash # Verify packaged GUI artifacts are healthy before a release is declared done. # # Background: on 2026-08-28 (1.3.0) the host wine broke (missing syswow64, so # wine -- the NSIS self-extract step -- failed), and electron-builder silently # wrote a 264 KB installer shell that did NOT embed the 86 MB payload. No gate # caught it, so a broken Windows installer shipped. This script is that gate. # # It enforces a per-artifact minimum size, so a degenerate installer (or a # build that only emitted a shell without its embedded payload) fails loudly. # A size check is the right signal here: a healthy NSIS exe is ~86 MB and the # broken 1.3.0 one was 264 KB (326x) — electron-builder compresses the embedded # app.7z, so a plaintext-payload string probe would be unreliable. set -uo pipefail GUI_DIST="${1:-cmd/build/gui-dist}" VERSION="${2:-}" log() { printf '[verify-dist] %s\n' "$*"; } fail() { printf '[verify-dist] FATAL: %s\n' "$*" >&2; exit 1; } [ -d "$GUI_DIST" ] || fail "no dist dir: $GUI_DIST" # (glob, min-bytes) checks=( "ModelRouter*.AppImage:10000000" "modelrouter-*.deb:10000000" "modelrouter-*.rpm:10000000" "modelrouter-*.nsis.7z:10000000" "ModelRouter Setup*.exe:5000000" ) for entry in "${checks[@]}"; do glob="${entry%%:*}"; min="${entry#*:}" # gui-dist accumulates installers from previous versions; check the MOST # RECENT artifact (last in sort) so a stale file never masks a broken build. # `find -name` (not a bare glob) so the space in "ModelRouter Setup *.exe" # is preserved as one file pattern. match="$(find "$GUI_DIST" -maxdepth 1 -name "$glob" -type f | sort -V | tail -1)" [ -z "$match" ] && fail "no artifact matching '$glob' in $GUI_DIST" sz=$(stat -c%s "$match") if [ "$sz" -lt "$min" ]; then fail "$(basename "$match") is only $sz bytes (min $min) — likely a degenerate shell like the 1.3.0 264KB exe" fi log " ✓ $(basename "$match") ($((sz/1024)) KB)" done log "all artifacts healthy"