Automate Firefox releases and qualify browser release checks - #1
Merged
Merged
Conversation
abduljawada
marked this pull request as ready for review
September 28, 2026 13:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stable version tags now validate the release commit and matching package/manifest versions, build and qualify both browser packages, and submit listed Firefox updates with the official web-ext tool, source archive, and release notes. Manual status/retry operations inspect store state first; pending or uncertain submissions cannot silently upload again. Chrome V2 publishing is prepared behind an explicit disabled setting. Packages, checksums, commit metadata, and submission results are retained as artifacts.
The required release gate runs eight controlled configurations: pinned original Asteroids (JavaScript), Breakout (WebAssembly), Interactive Buddy (AVM1), and Bloons TD3 (AVM2), each in Firefox and Chrome. Buddy replaced only the AVM1 slot after complete gameplay/edit, pause/cancel, lifecycle, and loaded-byte provenance qualification passed in both browsers. Xeno remains optional with its failed and incomplete evidence preserved. A separate advisory workflow visits the actual websites and retains blocked sites and compatibility failures without treating them as core passes.
Qualification also repairs three product races: paused Ruffle players accepting activation input, asynchronous reset cleanup erasing a newer scan, and stale background snapshots replacing an active scan request. Regression tests cover each. Browser test fixes wait for rendered gameplay/UI readiness, actual response capture, and fixture reload completion. Cancel reacts to visible partial progress and still requires explicit acknowledgement plus a public suspended sample inside actual busy-state transitions. Chrome observes the original request stream; aborted responses require complete unencoded declared length, and all loaded bytes must match the unchanged pins. Browser profiles are muted.
Validation on this branch:
Current-head verification (core passed; advisory remains failed): required core CI and advisory live-site compatibility.
The final advisory run retained one PASS, four BLOCKED, and three FAIL: Asteroids Chrome navigation and both Breakout security screens were blocked; Buddy Firefox lacked an observed cancellation-pause sample and Chrome shop OCR was below threshold; Bloons Firefox had an unavailable Pause control and Chrome a screenshot timeout. These are not counted as core passes.
This setup does not create a release tag or publish the current candidate. Mozilla credentials are configured in repository secrets; Chrome publishing remains disabled. After required CI passes, the approved merge is followed by the read-only store-setup workflow on main.