From bfbdd0c19910f464e779fa64cc0ec8590f8e37c1 Mon Sep 17 00:00:00 2001 From: Christian Kolset Date: Fri, 31 Jul 2026 15:52:28 -0600 Subject: Add PyInstaller packaging and tufup-based auto-update pipeline MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Full pipeline, verified end-to-end against the real installed tufup 0.10.0 API (initial docs/summaries turned out inaccurate in places — e.g. the apply method is download_and_apply_update, not update; confirmed by inspecting installed package source directly rather than trusting docs alone): - core/version.py: single-source app version constant. - labdaq.spec: PyInstaller onedir build (must be onedir, not onefile — tufup replaces individual files in the install dir on update). Bundles ui/*.qss, plugins/ (needed for runtime plugin discovery), and repository/metadata/root.json once repo_init.py has produced one. Built and smoke-tested: the frozen exe launches and stays running. - scripts/release/{repo_init,repo_release}.py: maintainer-run release tooling using tufup.repo.Repository, manual local signing (keys never touch CI). Both actually run end-to-end during development of this feature against a real build, not just written and assumed correct. Longer expiration_days than tufup-example's CI-oriented defaults (targets/snapshot/timestamp 90d instead of 7d/7d/1d), since we're signing manually, not on an automated daily schedule — see scripts/release/README.md for the re-signing cadence this still requires even between releases. - core/updater.py: thin Client wrapper. Refuses to run outside a frozen build (getattr(sys, "frozen", False)) since there's no installed bundle for tufup to update in `python main.py` dev mode. Bootstraps the bundled root.json into the metadata cache dir on first run — tuf.ngclient.Updater loads root.json from local disk on construction, it does not fetch it remotely by design (the root of trust can't come from the same server being verified). - core/app_settings.py: factored out app_data_dir() (was inline in _settings_path()) so the updater's metadata/target cache dirs live in the same per-user location as settings.json, deliberately outside the install directory an update can replace/move. - Settings > General: version display + "Check for Updates" button, manual-only per discussion (no silent background network calls or surprise restarts for a lab-instrument-control app). Metadata/targets are hosted on this repo's "updates" GitHub Release — a fixed tag, not a normal per-version tag, because TUF's top-level metadata needs a stable URL across app versions. No such GitHub-Releases- hosting example exists in tufup or tufup-example; verified this by fetching tufup-example's actual GitHub Actions workflow file directly after a web search wrongly suggested one existed — the design here is ours, not copied from upstream. Not yet done, deliberately left for the user: running repo_init.py for real (generates production signing keys), and creating the actual "updates" GitHub Release. Both are irreversible-ish, security-sensitive, externally-visible actions outside what should happen without the user directly driving them. Co-Authored-By: Claude Sonnet 5 --- ui/windows/settings_window.py | 56 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+) (limited to 'ui/windows/settings_window.py') diff --git a/ui/windows/settings_window.py b/ui/windows/settings_window.py index 290d9e0..75b6991 100644 --- a/ui/windows/settings_window.py +++ b/ui/windows/settings_window.py @@ -118,6 +118,23 @@ class SettingsWindow(QWidget): ) lay.addRow("Developer mode:", self._dev_chk) + from core.version import __version__ as _app_version + version_lbl = QLabel(f"v{_app_version}") + version_lbl.setObjectName("traceSource") + lay.addRow("Version:", version_lbl) + + update_row = QHBoxLayout() + self._update_btn = QPushButton("Check for Updates") + self._update_btn.setObjectName("configButton") + self._update_btn.clicked.connect(self._check_for_updates) + update_row.addWidget(self._update_btn) + update_row.addStretch() + lay.addRow("Updates:", update_row) + self._update_status_lbl = QLabel("") + self._update_status_lbl.setObjectName("traceSource") + self._update_status_lbl.setWordWrap(True) + lay.addRow("", self._update_status_lbl) + rst = QPushButton("Reset to Defaults"); rst.setObjectName("configButton") rst.clicked.connect(self._reset_to_defaults) lay.addRow("", rst) @@ -286,6 +303,45 @@ class SettingsWindow(QWidget): # ── Actions ─────────────────────────────────────────────────────────── + def _check_for_updates(self): + from core.updater import is_frozen + + if not is_frozen(): + self._update_status_lbl.setText("Not available outside the packaged app (dev mode).") + return + + from PyQt6.QtWidgets import QApplication + from core.updater import apply_update, check_for_update + + self._update_btn.setEnabled(False) + self._update_status_lbl.setText("Checking…") + QApplication.processEvents() + try: + new_version = check_for_update() + except Exception as e: + self._update_status_lbl.setText(f"Check failed: {e}") + self._update_btn.setEnabled(True) + return + self._update_btn.setEnabled(True) + + if not new_version: + self._update_status_lbl.setText("Up to date.") + return + + self._update_status_lbl.setText(f"Version {new_version} available.") + reply = QMessageBox.question( + self, "Update Available", + f"Version {new_version} is available. Download and install now?\n\n" + f"The app will close and relaunch to complete the update.", + QMessageBox.StandardButton.Yes | QMessageBox.StandardButton.No, + QMessageBox.StandardButton.No, + ) + if reply == QMessageBox.StandardButton.Yes: + try: + apply_update() # may close/relaunch the process during this call + except Exception as e: + QMessageBox.critical(self, "Update Failed", str(e)) + def _reset_to_defaults(self): reply = QMessageBox.question( self, "Reset Settings", -- cgit v1.2.3