You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Promote the maintained patch-1 development line for the first versioned release in this repository. This PR includes the accumulated 2.0.0 work, not only the final CI repair.
One administrator authentication for macOS disk preparation and an already-authorized worker for late partition changes and the Pi 3 GPT patch.
Automatically choose Ignore only for the exact macOS unreadable-disk alert during authenticated GUI writes. Never choose Initialize/Eject, disable Disk Arbitration globally, or dismiss unrelated alerts. Report Accessibility/Automation permission failures.
Repair the observed GitHub CI failures: install pv before progress tests and inspect loop-device geometry with the privileges used by flashing.
Resolve release versions from canonical JSON metadata, include README/LICENSE/NOTICE with runtime artifacts, and add publication regression coverage and explanatory comments.
How was it tested?
Local npm run check: 43 tests passed, including seven new release-workflow/CI regressions.
The obsolete release-version lookup was restored in an isolated copy and the new regression test correctly failed.
Previous complete local validation: macOS 194 passed, Linux loop-device suite 281 passed; platform-specific skips covered on the other platform. Fresh GitHub checks on this PR remain the publication gate.
Native alert test: the matching synthetic system alert was ignored; an unrelated system alert was left untouched. No physical drive was erased by these tests.
Publication and limitations
After required checks pass, publish v2.0.0 with the existing release workflow; create the immutable tag only after release-candidate validation and packaging succeed. Do not overwrite existing tags.
The macOS bundle is unsigned/unnotarized. Physical-media completion and Raspberry Pi boot success are not established by the automated tests. The experimental disk-claim helper remains inactive and unbundled. Preserve Botspot attribution and the upstream licensing caveats in NOTICE.
README and release notes updated
No downloaded Windows media, credentials, local configuration, or generated releases committed
…iles
install-wor.sh is now the single source of truth and install-wor-gui.sh only
draws windows over it. The GUI used to define its own error, dialog and cache
helpers before sourcing the installer, so those copies were silently shadowed
at source time - dead code that had already drifted from what actually runs.
Real divergences this uncovered:
* Only the GUI applied config-templates/piN.config.txt, so a plain CLI run left
the firmware's own config.txt in place and wrote different media.
* The run summary existed in three hand-written copies with different contents.
HIDE_EMPTY_DRIVES and the ISO source were missing from both GUIs; the UEFI,
driver and config toggles were missing from the CLI banner.
* Each front-end kept its own export list. macOS dropped DIRECTORY, SOURCE_FILE
and WOR_APP_TITLE; both dropped HIDE_EMPTY_DRIVES.
* Linux deleted the installer log on failure while macOS kept it, and trusted a
bare -e on the error marker instead of -e plus -s.
* Linux never ran is_safe_target_device on a caller-supplied DEVICE.
* ISO validation was written out three times, cached-winfiles discovery twice
with different globs, and drive enumeration twice with different lsblk calls.
* warning() was called by the self-updater but never defined.
Moved into the engine: warning, human_size (renamed from darwin_human_size,
which was never Darwin-only), uefi_pinned_version, cache_mode_label,
install_mode_label, set_default_config_txt, describe_device, list_dev_paths,
validate_iso_file, bid_from_iso_name, lang_from_iso_name, is_known_win_lang,
list_langs_preferred, list_cached_winfiles, bid_from_winfiles_dir,
lang_from_winfiles_dir, settings_summary and its two renderers, and
WOR_INSTALLER_SETTINGS with export_installer_settings.
Added an explicit --gui entry point that execs the front-end. The front-end is
never chosen by sniffing DISPLAY: DISPLAY is also set over SSH and in CI, and a
tool that erases a disk should do exactly what it was asked to do.
Added WOR_FLASHER_VERSION, reported by --version and on every run. Upstream has
never published a tag or a release, so this fork starts its own line at 1.0.0,
with the history kept in a comment block and mirrored in the README.
Added LICENSE (GPL-3.0, matching Botspot's bvm), NOTICE, CONTRIBUTING,
CODE_OF_CONDUCT, SECURITY and FUNDING. NOTICE records that upstream ships no
license file, so only our own additions carry an unambiguous GPL-3.0 grant.
Restructured the README around a table of contents, a parameters table and a
versions section, and credited Botspot and every upstream contributor.
tests/run-tests.sh gained a shared_function_checks section whose run_in_engine
helper sources the real install-wor.sh and calls the real functions, so no test
restates product logic. It guards against a function being defined in both
files, against the summary and export list drifting, and against the community
files, attribution and table of contents going stale. 58 tests before, 84 now,
all mutation-tested; shellcheck error-clean.
Windows stopped at "Let's connect you to a network" with the answer file
present on the media, because nothing ever read it.
Autounattend.xml at the root of the media is only found by Windows Setup's
implicit answer-file search. WoR-PE does not run that flow - it applies
install.wim with DISM and finalizes with bcdboot - so the file was written,
verified, and then ignored. The settings themselves were correct: Microsoft
documents HideWirelessSetupInOOBE as hiding exactly that Network screen, which
appears when Windows cannot confirm internet access. The Pi shows an
unidentified network with no internet, so the page was shown.
worproject documents a prefinalize.cmd hook that runs just before the installer
finalizes, with the applied Windows partition still mounted and its letter in
WOR_DISK_WINDOWSPARTITION. That is the only point at which the answer file can
be placed somewhere the installed OS will read it, so the hook now copies it to
Windows\Panther\unattend.xml.
The hook and the answer file are staged into the WoR-PE application directory
alongside settings.ini, so the existing wimupdate carries them into boot.wim.
Both are removed again when neither customization is wanted, or a stale hook in
the cache would keep applying settings the user had turned off. Editing cached
payload changes its manifest, so the re-record that settings.ini already needed
is now shared as remark_pe_cache; genuine tampering is still detected.
The media-root copies stay as they are. They cost nothing and remain correct if
the media is ever used with real Windows Setup.
This also fixes the Pi 4 RAM unlock, which was undelivered for the same reason -
it rides in the same answer file.
The script always exits 0: worproject documents that a non-zero exit aborts the
whole installation, and a missing answer file is not worth failing a flash over.
Guarded by two tests that stage the hook against a stub PE tree and assert the
answer file reaches Panther, the script cannot abort the install, line endings
are CRLF, the cache stays valid, and a stale hook is cleaned up. Mutation-tested
by reverting to media-root-only delivery, by pointing the hook elsewhere, and by
letting it exit non-zero. 86 tests pass.
The GUI collected a credential and then the installer collected another, so the
password dialog appeared twice.
A sudo timestamp is recorded against the terminal of the process that collected
it, and the installer runs as a separate background job, so the credential the
GUI held did not satisfy the installer's own check. It fell through to its
askpass fallback and asked again.
Removing the GUI's prompt alone would have reintroduced an older bug: the
remaining dialog would open behind the progress window, which is a Regular
policy app that has already called activateIgnoringOtherApps, and could never
be answered. So the authentication moves into the installer - the process that
actually uses it - and the front-end holds its progress window back until that
has happened.
install-wor.sh gains gui_preauthenticate, called right after setup in GUI mode,
before any downloads. It authenticates, starts the keep-alive against its own
pid, and touches WOR_GUI_AUTH_MARKER. gui_start_installer exports that marker
and waits for it, or for the done marker if the run fails before reaching it, so
an early failure cannot hang the front-end. Verified both paths: the wait
returns as soon as the installer authenticates and leaves it running, and an
installer that exits 42 first returns without hanging and still records 42.
darwin_flash_device no longer prompts in GUI mode. It was the second dialog. In
CLI mode it still prompts, because there is a terminal to answer it on.
Both front-ends share the change, so the Linux progress window gets the same
ordering.
Guarded by three tests, mutation-tested by reinstating the GUI prompt, by
removing the wait, and by letting the engine prompt again at partitioning.
Also corrects the config-templates count, which prefinalize.cmd had made stale.
The log path was hardcoded as $DL_DIR/last-run.log inside the GUI, which meant
it could not be moved and, on Linux, could end up somewhere the user had not
expected: that front-end lets DL_DIR be changed after the script is sourced, and
the ZRAM option repoints it at /zram.
wor_log_file() now resolves it on use rather than at source time, so it follows
a late DL_DIR change, and WOR_LOG_FILE overrides it outright. The confirmation
screen and the CLI banner list the resulting path, so it is visible before the
flash starts rather than only in the error dialog afterwards.
Deleted the stray wget-log and wget-log.1 left beside the scripts. They date
from 02 September and nothing in the current code reproduces them - there is no
background wget, and a spider check with stderr captured does not write one - so
this is old debris rather than a live bug. Both were already gitignored, so they
were never committable; *.log is now ignored as well, since WOR_LOG_FILE can be
pointed anywhere including inside the checkout.
cache/ is deliberately kept. It is a working cache that install-wor.sh recreates,
it is ignored, and USE_CACHE=0 already clears it on demand.
.gitattributes drops a rule for config_txt_tips, which no longer exists here, and
pins *.cmd to LF. That one matters: install-wor.sh appends the CR itself when it
writes prefinalize.cmd into boot.wim, so a CRLF copy in the repo would produce
CRCRLF and cmd.exe would choke on the hook.
Three tests added, mutation-tested by hardcoding the path again, by dropping the
*.log ignore, and by converting the batch template to CRLF. A fourth check would
have been silently useless: git check-ignore -q accepts a single pathname only,
so the first version of that assertion always failed. It asks one at a time now.
"Limit RAM to 3 GB" was still Enabled in UEFI after a flash that had the unlock
turned on.
Pi4Disable3GB.ps1 was written only to the two media roots, and the specialize
action looked for it by walking every lettered filesystem drive. That runs on
the installed OS, where the WoR media is not necessarily still visible or
lettered - the same delivery gap that kept the answer file from being read.
The script now travels with the answer file through the prefinalize hook, into
Windows\Setup\Scripts. The specialize action tries that fixed path first and
keeps the drive walk as a fallback, so media that is still mounted also works.
It no longer exits non-zero when the script is missing. As written, a
RunSynchronousCommand that fails takes Windows Setup down with it, which is a
poor trade for an optional tweak. It now records what it did to
%windir%\Temp\Pi4Disable3GB.log and always exits 0, so the next report can say
whether the action ran, could not find the script, or threw.
The media copies stay, and their verification is unchanged.
Guarded by a test that stages against a stub PE tree and asserts the script is
carried, the hook copies it, a Pi 5 does not get it at all, and the action cannot
fail setup. Mutation-tested by reverting to media-only delivery and by restoring
the non-zero exit.
Confirmed on hardware that C:\Windows\Panther\unattend.xml is present after a
flash, so the prefinalize hook does deliver it and the offline-OOBE bypass is
genuinely applied rather than the network page being skipped by a working
wired connection.
That makes the answer file's validity load-bearing, and it is assembled by
concatenating fragments: a bad escape, or a missing newline between two of them,
would produce XML that Windows silently ignores with no error anywhere. Nothing
checked that. A test now parses the generated file and asserts both the
specialize and oobeSystem passes survive, in order.
Mutation-tested by removing a closing bracket from one fragment.
Also adds the trailing newline .editorconfig asks for on the specialize fragment.
Ethernet came up with a physical address of 00-00-00-00-00-00, no DHCP, and an
APIPA address. The driver was fine; the firmware never handed it a MAC.
This is pftf/RPi4#283: v1.51 and v1.52 report a zero MAC, and v1.50 does not.
We were pinned to v1.51.
v1.53 fixes the MAC, but pftf/RPi4#285 reports that v1.52 and v1.53 both fail to
boot from microSD, confirmed for v1.53 earlier today. Moving forward would have
traded a dead NIC for a drive that does not boot at all, which is worse for a
tool whose usual target is an SD card. v1.50 is the last release with neither
problem, so that is the pin.
Ruled out first, rather than guessed at:
* config-templates/pi4.config.txt matches pftf's own config.txt exactly, apart
from HDMI lines. dtoverlay=upstream-pi4 looked suspicious but is upstream's
own default.
* The UEFI package we copy contains RPI_EFI.fd, all three .dtb files, both
overlays, start4.elf and fixup4.dat.
* v0.17 is the final driver release, and its INF picks the right GENET binary
by build number on its own, so a build-22621 install gets netadaptercx21.
Documents the symptom, and that the several Unknown devices in Device Manager
are expected: no Windows drivers exist for the Wi-Fi, camera or VCHIQ.
The test now rejects v1.51, v1.52 and v1.53 by name with the reason for each.
Mutation-tested by restoring the v1.51 pin.
Version history and the README badge had to move together; the guard added last
commit caught the stale badge, and the assertion is now version-agnostic rather
than matching the 1.0.0 release wording.
- Hide the disabled zoom/maximize button on all 4 windows (dropping
NSWindowStyleMaskResizable alone leaves it drawn but greyed out)
- Fix Back/Next button overlap in message-mode dialogs where the
primary button is centered instead of right-aligned
- Match Back button width to the primary button so button pairs read
as one uniform row
- Fix Back on the no-drive-found chooser screen not propagating a
cancel, so it looped instead of returning to the previous step
- Give Back an explicit cancelValue on the pi/language/mode/device
wizard steps so a real Quit exits the whole wizard instead of just
stepping back one screen, matching the existing confirm-screen
pattern
- Add a WOR_ICON_PATH fallback to WOR_LOGO_PATH so a bare script run
(outside the packaged .app) shows WoR-Flasher branding instead of
the generic osascript icon
- Resize the partnership banner to 800x533 so the Linux yad
announcement window fits on screen
- Add mutation-tested regression coverage for the Back-vs-Quit fix
and resync the bundled macOS app runtime
macOS 26+ mounts exFAT through FSKit, and fskitd unmounts an idle volume
on its own ("Unmounting /Volumes/WOR_INSTALL how 02"). WOR_INSTALL could
therefore disappear while the 549 MB boot.wim was still being written to
WOR_BOOT, so the mount point resolved for the install.wim copy was stale
by the time the copy opened it and the run aborted at step 6.
Re-resolve the mount point and retry the copy up to three times, but only
when the volume actually vanished; a failure with the mount point still
present is a real copy error and is reported immediately as before.
Also stop darwin_report_copy_failure claiming administrator access works
when it does not. It used `sudo -n rm -f` as proof, which succeeds on a
path that was never created, so the branch fired whenever sudo happened
to be authenticated and blamed permissions for a missing volume. Require
empty touch output instead, and report an unmounted volume as such.
The banner rendered beside the copy instead of above it, squeezing the
attribution links into a narrow sidebar column. yad only honours
--image-on-top for a --form dialog when --image is parsed before --form;
here it came after, so yad packed the image and the field column side by
side regardless of the flag. Move --image ahead of --form, matching the
already-working overview.png dialog earlier in this file.
Not verified against a running yad instance: this host is macOS, which
routes through the native JXA announcement instead, and yad is not a
macOS dependency. Please confirm the fix on Linux.
Refresh macOS app runtime behavior for per-run settings, host locale defaults, TCC guidance, and native sudo reuse during disk preparation/finalization.
Package the maintained Linux entry points in the release tarball and cover the archive contents in release tooling tests.
Validation: bash -n install-wor.sh install-wor-gui.sh tests/run-tests.sh; shellcheck --severity=error install-wor.sh install-wor-gui.sh tests/run-tests.sh; npm run check; ./tests/run-tests.sh; npm run build:macos.
Align the Linux YAD presentation with the macOS flow by widening the overview and advanced dialogs, giving Advanced Options contextual copy, and opening config.txt in a properly branded editor window.
Clarify early progress so preflight/setup work does not look frozen at 0%, replace visible DL_DIR wording with download-folder copy, align Windows file status as a read-only field, and normalize locale casing in shared summaries.
Validation: bash -n install-wor.sh install-wor-gui.sh tests/run-tests.sh; shellcheck --severity=error install-wor.sh install-wor-gui.sh tests/run-tests.sh; ./tests/run-tests.sh; npm run check; npm run build.
Force YAD to use the Unix GIO volume monitor so Ubuntu VM sessions do not surface unrelated usbredir protocol parse errors while the target picker is open.
When no safe writable target drive is listed, show only Cancel and Refresh instead of an empty list with a misleading Next button.
Validation: bash -n src/lib/gui.sh install-wor-gui.sh tests/run-tests.sh; shellcheck --severity=error src/lib/gui.sh install-wor-gui.sh tests/run-tests.sh; ./tests/run-tests.sh; npm run check; npm run build.
Reuse pre-authorized workers for late disk writes and avoid unnecessary elevation for ISO cleanup. Automatically choose Ignore only for the matching macOS disk alert during authenticated writes, with bounded cleanup and explicit permission warnings.
Expand authorization, alert-safety, and lifecycle coverage; harden the integration harness. Keep the documented experimental disk-claim helper inactive and unbundled.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Install progress-test prerequisites before integration checks, inspect loop-device geometry with the correct privileges, and resolve release versions from canonical JSON metadata. Add targeted regression coverage and trigger CI for runtime helper and metadata changes.
Include README, LICENSE, and NOTICE in runtime artifacts; document release behavior, automatic Ignore permissions, and hardware validation limits.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Candidate commit: fa4c023a8608f03cc0f9a0c79e3e46e6317429e6 (synchronized on patch-1). Target release: v2.0.0.
The earlier failed GitHub job was diagnosed rather than bypassed: its progress check ran before pv was installed, and its partition-layout assertions read a root-owned loop device without sudo. Both are corrected. The release workflow now reads the actual canonical JSON version and has the scoped permission needed for its optional preparation commit.
Local npm run check passes 43 tests. The seven new publication regressions cover version lookup, CI prerequisites, metadata/helper path triggers, notice inclusion, and successful/failed privileged geometry reads. Reintroducing the obsolete version lookup in a disposable copy makes the regression fail.
README, LICENSE, and NOTICE are now carried inside both runtime distributions. The experimental disk-claim helper remains inactive and unbundled. Native automatic Ignore handling was tested with harmless system notifications; physical Raspberry Pi boot success is not claimed.
Publication remains gated on fresh GitHub CI and the release workflow's own Linux/macOS validation and packaging. No force-push or existing-tag rewrite is planned.
All three checks on the exact candidate fa4c023a8608f03cc0f9a0c79e3e46e6317429e6 succeeded in GitHub run 36257220627:
shellcheck
macos-syntax
dry-run-integration
GitHub reports zero required approvals and no requested changes. Local publication regressions also detected both deliberate regressions: restoring the stale version lookup and removing privileged loop-device inspection.
The next step is normal PR promotion to main, then the v2.0.0 release workflow with version updates disabled because the canonical version is already 2.0.0. The workflow must validate both operating systems and package artifacts before creating the new tag. No existing tag or repository protection will be changed.
Prepares the accumulated cross-platform WoR-Flasher 2.0.0 release, including macOS support, release packaging, configuration, verification, and expanded CI coverage.
Changes:
Adds macOS-native runtime, GUI, disk handling, and verified updates.
Introduces canonical metadata, configuration templates, packaging, and automation tooling.
Expands release workflows, integration tests, documentation, and project assets.
File
Description
tests/run-tests-macos.sh
Adds macOS launcher and runtime tests.
tests/run-tests-gui.sh
Supports Linux and macOS GUI walkthroughs.
tests/run-linux-integration.sh
Adds required container dependencies and model forwarding.
tests/release-workflow.test.mjs
Tests publication and CI prerequisites.
tests/node-tools.test.mjs
Tests metadata, packaging, manifests, and updater tooling.
tests/macos-disk-alerts.test.mjs
Tests alert policy and helper lifecycle.
terminal-run
Removes terminal-emulator launching.
src/updater.mjs
Adds release and manifest CLI operations.
src/sync-package-metadata.mjs
Synchronizes package metadata.
src/set-version.mjs
Updates release version surfaces.
src/package-macos-app.mjs
Generates and validates embedded runtimes.
src/macos-disk-claim.c
Adds experimental Disk Arbitration helper.
src/macos-app/Contents/Info.plist
Defines macOS bundle metadata.
src/lib/paths.sh
Adds shared path resolution.
src/lib/node-runtime.mjs
Implements runtime manifests and release checks.
src/lib/metadata.sh
Loads canonical shell metadata.
src/lib/macos-disk-alerts.js
Handles exact unreadable-disk alerts.
src/lib/gui.sh
Adds shared GUI definitions.
src/lib/dependencies.sh
Centralizes platform dependencies.
src/lib/cleanup.sh
Centralizes runtime cleanup.
src/config/metadata.schema.json
Defines project metadata validation.
src/config/metadata.json
Supplies canonical release/runtime metadata.
src/check-pe-installer.mjs
Verifies pinned PE installer assets.
src/build-release.mjs
Builds release artifacts.
SECURITY.md
Adds security policy and reporting guidance.
package.json
Defines Node tooling and release scripts.
NOTICE
Documents attribution and licensing status.
install-wor-hook.sh
Adds the external automation adapter.
CONTRIBUTING.md
Adds contribution and testing guidance.
config-templates/prefinalize.cmd
Stages Windows setup customizations.
config-templates/pi5.config.txt
Adds Pi 5 boot configuration.
config-templates/pi4.config.txt
Adds Pi 4 boot configuration.
config-templates/pi4-ram-unlock.ps1
Adds post-install RAM-limit handling.
config-templates/pi4-ram-unlock-specialize.xml
Runs RAM customization during specialize.
config-templates/pi3.config.txt
Adds Pi 3 boot configuration.
config-templates/oobe-network-bypass.xml
Adds offline OOBE settings.
config-templates/config.schema.json
Defines user configuration schema.
config-templates/config.json
Provides default configuration.
CODE_OF_CONDUCT.md
Adds community conduct policy.
assets/ram.png
Adds RAM customization artwork.
assets/logo-full.png
Adds shared branding artwork.
AGENTS.md
Documents architecture and safety rules.
.gitignore
Ignores generated releases, logs, and local configuration.
Refresh and verify staged runtime contents, reject linked paths and stale versions, and propagate packaging failures. Align update discovery, bootstrap, macOS minimum version, and the supported security line with the maintained 2.0 release.
Stage the optional Pi4 UEFI Shell independently of answer-file options, preserve upstream attribution, and add ten focused review regressions.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Review completed and release candidate revalidated
All ten review comments are addressed in d998c6cb06fcb485fc2495ae6d466b7a446a6e23, with individual replies and resolved threads. The release destinations now match this repository, macOS 13 and the 2.0.x support policy are consistent, package writes/checks reject stale or linked runtimes, version-build failures propagate, and UEFI Shell staging no longer depends on answer-file options.
Local npm run check: 53 tests passed.
Ten new review regressions pass; stale-copy and stale-version mutations are detected.
Fresh GitHub PR CI run 36258102801: success, covering Linux integration, ShellCheck/package validation, and macOS validation.
The publication plan remains v2.0.0 from the promoted PR, with the release workflow performing its own validation before creating the tag. Native media completion / Raspberry Pi boot and actual WinPE execution of the optional shell handoff remain explicitly unverified by automated tests.
Merged through the normal PR path as 54ad7d199c47feddec9424fcde98ef7ed86aad29 after all CI checks passed and review threads were resolved. The v2.0.0 release workflow has now been requested on main with project-version updates disabled, since canonical metadata is already 2.0.0. Release publication is not considered complete until the workflow succeeds and the downloadable assets are verified.
Schema rejects the shipped configuration's top-level $schema property
config-templates/config.schema.json:6
The shipped config.json contains a top-level $schema, but this schema omits that property while setting additionalProperties: false. As a result, the documented default configuration fails validation against its own schema.
Manifest path list ignores the specified repository directory
src/updater.mjs:83
--repo-dir changes the source root and version lookup, but the runtime path list is still read from the updater tool's own checkout. Building a manifest for another repository can therefore copy the wrong paths or fail despite valid metadata in that repository.
macOS preflight checks reference a nonexistent image path
tests/run-tests-gui.sh:37
The macOS preflight checks a root-level image that does not exist, so every macOS GUI walkthrough exits before reaching the test. The actual asset is assets/partnership.png.
Version update guidance edits obsolete generated metadata
AGENTS.md:214
This release guidance references a WOR_FLASHER_VERSION assignment that no longer exists in metadata.sh; the canonical version is now product.version in src/config/metadata.json. Update this instruction to use the version-setting tool so automated contributors do not edit the generated loader incorrectly.
The release workflow completed successfully: tag resolution, Linux validation, macOS validation, and packaging/publication all passed. The new v2.0.0 tag points to the promoted commit 54ad7d199c47feddec9424fcde98ef7ed86aad29.
Downloaded all five public release assets after publication. Every entry in SHA256SUMS passed. The downloaded macOS app's runtime, launcher, and property list match the committed source; the downloaded Linux runtime matches the source file digests and modes. macos-runtime.json has the correct version, publishing-repository URL, and runtime-archive SHA-256.
The release includes macOS and Linux ZIPs, the verified runtime-update archive and metadata, checksums, README/LICENSE/NOTICE, and the documented permission/hardware-validation limitations. The macOS app remains unsigned and unnotarized.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this change?
Promote the maintained
patch-1development line for the first versioned release in this repository. This PR includes the accumulated 2.0.0 work, not only the final CI repair.pvbefore progress tests and inspect loop-device geometry with the privileges used by flashing.How was it tested?
npm run check: 43 tests passed, including seven new release-workflow/CI regressions.Publication and limitations
After required checks pass, publish
v2.0.0with the existing release workflow; create the immutable tag only after release-candidate validation and packaging succeed. Do not overwrite existing tags.The macOS bundle is unsigned/unnotarized. Physical-media completion and Raspberry Pi boot success are not established by the automated tests. The experimental disk-claim helper remains inactive and unbundled. Preserve Botspot attribution and the upstream licensing caveats in NOTICE.