Linux/macOS now follow the local-build path in CI and CD:
tooling/install-deps.sh installs the distro codec packages and
tooling/ffmpeg/build-ffmpeg.sh builds the pinned static FFmpeg into
.cache/ffmpeg, with FFMPEG_DIR/PKG_CONFIG_PATH pointing there. CI caches
the built tree keyed on the script, distro and arch (the
.build-complete marker rejects partial saves); CD rebuilds it from
scratch per its no-cache policy. Windows keeps BtbN's prebuilt shared
archive, downloaded from the release page and verified against its
checksums.sha256 — no pkg-config is needed there any more.
vcpkg.json, the release-only overlay triplets and the x264 mirror
overlay are deleted; docs/build.md describes the new flow.
A cold vcpkg FFmpeg build costs ~40 minutes per Windows run and the
Windows dependency chain is the hardest to keep healthy; BtbN's builds
come from public GitHub Actions on the release/8.1 branch (BtbN is an
FFmpeg developer; ffmpeg.org links these builds as the official Windows
option). The archive ships include/, MSVC import libs (.lib), pkg-config
files and the runtime DLLs, and is fetched straight from his release
page with the checksums.sha256 published in the same release — nothing
is mirrored here, so provenance stays upstream.
The Windows jobs download/verify/extract it to .cache/ffmpeg (the
checksum comes from that release's own checksums.sha256), point
FFMPEG_DIR/PKG_CONFIG_PATH at it (pkgconf still comes from vcpkg) and
the installer bundles its DLLs. The manifest gates ffmpeg to !windows
and drops librsvg (the icon now ships as the committed PNG).
vcpkg's x264 port downloads from code.videolan.org, whose GitLab serves
the archive behind an anti-bot challenge: CI runners hit curl 7/35
(connection/SSL) or 404 at random, so whether a vcpkg install succeeded
was a coin flip. This overlay port is a verbatim copy of the builtin
port at baseline 771b0a2e with vcpkg_from_gitlab swapped for
vcpkg_from_github against mirror/x264 (byte-identical archive, same
SHA512); both workflows now pass --overlay-ports tooling/vcpkg-ports.
Verified locally in debian:12: the port downloaded from
github.com/mirror/x264 and built libx264.a. No other port in the tree
uses code.videolan.org (dav1d/x265 already fetch from GitHub).
vcpkg builds every port twice (release + debug) in manifest mode and the
VCPKG_BUILD_TYPE environment variable is ignored there; pin the build
type in overlay triplets instead (tooling/vcpkg-triplets/release, one per
supported triplet). The release configuration is what both workflows
consume: FFMPEG_DIR drives the release layout (lib/pkgconfig) and the C
ABI is identical for the debug binary CI tests. Verified locally in
debian:12: a release-only overlay builds zlib/libpng/openssl/pkgconf/
libsndfile with zero debug trees.
Debug-only is not an option: ports like zlib patch files in the release
layout and fail when only the debug configuration is built.
Fedora 41 is EOL, so its mirrors moved to the slow archive: the first
dnf transaction took ~7 minutes in the last CD run. Use the current
fedora:43 image (all dependency names verified against F41 and F43) and
skip weak dependencies / download in parallel in both dnf calls.
Fedora packages core perl modules separately: openssl's Configure died on
"Can't locate FindBin.pm" after IPC::Cmd was fixed, and the build also
uses File::Basename/File::Compare/Copy/Path and File::Temp, plus
Time::Piece for the in-tree utilities. All of them exist for F41 and F43.
CI and CD now run the same seven environments in a single matrix:
Debian 12, Fedora 41, Arch and openKylin x64+arm64 in their distro
containers plus the macOS (12x) and Windows (32x) hosts, with identical
dependency lists and runner sizes, so a package a CD build needs cannot
be missing in CI. CD keeps building every package from scratch (no
vcpkg/cargo caches).
Fixes every failure the last CD run exposed:
- deb packaging: dpkg-shlibdeps needs a Debian source tree (give it a
synthetic debian/control) and Debian 12/openKylin carry an older libva
than FFmpeg 8 needs (vaMapBuffer2), so vcpkg's libva/libdrm ship next
to the app with an $ORIGIN RUNPATH;
- AppImage: register the vcpkg libs with ldconfig so linuxdeploy finds
libva-drm.so.2;
- Fedora: install perl-IPC-Cmd (vcpkg's openssl port requires it);
- macOS: cargo-packager produces "Oak Video Editor.app"; resolve the
bundle instead of assuming "Oak.app";
- Windows: the vendored OCIO is compiled /MD, so drop +crt-static (the
LNK2038 RuntimeLibrary mismatch) and bundle the MSVC runtime DLLs
app-locally;
- containers: pin HOME for rustup and give WarpCache its token on the
cache steps only (job-level env cannot reference the env context).
A restored vcpkg_installed or target tree masked packaging problems
before (stale ports, a missing librsvg tool) and release artifacts must
not depend on restored state, so remove every cache step from the CD
jobs: vcpkg builds its ports from source and cargo compiles cold on each
release run.
vcpkg's vaapi feature builds libva, which needs libdrm headers: the CI
Linux job installs libdrm-dev and the CD debian container did not
(fedora/arch already carry libdrm-devel/libdrm), so its vcpkg install
failed with "You will need to install libdrm dependencies".
Windows has no rsvg-convert either: vcpkg's librsvg port is built with
-Drsvg-convert=disabled, so the icon step now copies the committed
512x512 render (assets/app-icon.png); the Linux icon step falls back to
it too when librsvg2-bin is missing.
The Fedora dnf list had a trailing space after a line-continuation
backslash, which became a blank argument dnf rejects with "No match for
argument:". The AppImage job cloned vcpkg with --depth 1, but the
manifest pins a builtin-baseline and port trees a shallow clone cannot
check out ("failed to unpack tree object"); use a full clone like the
other packaging jobs.
The Linux package matrix now carries arch/triplet/runner per entry and
gains two openKylin entries (x64 on a 16x runner, arm64 on a 32x runner),
each building inside the openkylin container so dpkg-shlibdeps resolves
against openKylin's own repo names. Deb packages are labeled by build
distro: the general debian:12 package becomes
oak-editor_<version>+debian_<arch>.deb, openKylin's
oak-editor_<version>+openkylin_<arch>.deb; build-deb.sh takes the variant
and stamps dpkg --print-architecture (the file name hardcoded amd64
before).
Also: pin HOME for rustup in the openKylin container, create the icon
directory before rendering (and degrade to the scalable icon when
rsvg-convert is missing), add the Windows Defender step to the Windows
packaging job, and take the bumped runner sizes (AppImage/Linux 16x,
macOS 12x, Windows 32x).
A job container does not inherit the runner environment, so every cache
step logged "Authentication token is invalid" and the vcpkg cache was
never restored or saved. Pass WARPBUILD_RUNNER_VERIFICATION_TOKEN into
the container explicitly (WarpBuilds/cache README: "Running inside a
container") and install wget there, which the action uses to download
cache segments.
The first WarpCache-cold run failed because x264's source tarball on
code.videolan.org refused connections (curl error 7) and vcpkg refuses
to retry that class of error. Retry the install up to three times on
every platform; vcpkg resumes from its archive/download caches.
- The macOS Test step gets the same in-script watchdog as Linux/openKylin:
after 900 s it prints `sample` stacks of every test process (the hung
test's native stack lands in the log) and kills the suite, instead of
leaving the job to sit until the step timeout with no evidence.
- The multicam graph test additionally prints the `current_in` read-back
after the switch, so the next Windows run distinguishes a lost selector
write from a row/element resolution problem.
The GitHub Actions cache quota is full (the vcpkg trees plus the cargo
target dirs overflow the 10 GiB repo budget). The Linux job and both
openKylin matrix jobs now use WarpBuild's drop-in cache actions
(WarpBuilds/cache restore+save, WarpBuilds/rust-cache); all of them run
on WarpBuild runners, where the service is available. macOS and Windows
keep actions/cache for now.
- The macOS SIGSEGV moved from the gl_bridge unit tests (already gated)
to other real-GL users in the same binary (suites::gl_render,
render_driver): make the gate systemic in the test build on macOS.
gl_available() reports unavailable and acquire() fails unless
OAK_GPU_TESTS is set, so every unit test takes its documented CPU
fallback; release builds are untouched.
- Dump Apple's crash reports on macOS failure: a SIGSEGV in a test binary
prints nothing, and the .ips report carries the native stack.
- The Windows-only multicam graph test failure now prints both decoded
media probes and both rendered source pixels: that separates a broken
test-media encode from a broken graph switch in one run.
- Actions moved to their latest majors: checkout v4->v7, cache v4->v6
(restore/save too), upload-artifact v4->v7, download-artifact v4->v8,
action-gh-release v2->v3. rust-cache and rust-toolchain already track
their latest majors.
- vcpkg caches now save under a per-run key and restore through
`restore-keys` (newest entry for the exact manifest first, then the
newest entry for that OS): saving can no longer fail because the key
already exists ("update if present, create if not"), and a manifest
change reuses vcpkg's content-addressed archives instead of rebuilding
every port.
- Every Test step gets an explicit 40-minute bound. macOS had no watchdog
at all (the Linux/openKylin scripts carry their own) and the current run
has been sitting in Test with no progress; a hung suite now fails the
step instead of running to the job timeout.
- Windows: the first test executable died with STATUS_DLL_NOT_FOUND
(0xc0000135) because vcpkg's x64-windows DLLs (ffmpeg and its codecs)
were not on PATH; add vcpkg_installed/x64-windows/bin in the configure
step.
- openKylin: failure_paths_report_cleanly asserts that a read-only library
write fails, but the container runs as root, which bypasses the file
permission bits (CAP_DAC_OVERRIDE) and the write succeeds; skip that
sub-check when euid is 0 (read from /proc/self/status on Linux) and note
it in the log.
- Disable Windows Defender real-time/script/archive scanning (and exclude
the workspace, cargo, rustup and vcpkg trees) at the start of the
Windows job: the ephemeral runner spends a large share of a cold build
having every object file scanned.
- Raise the openKylin container /dev/shm from 2 GiB to 8 GiB: the suite's
parallel worker pools plus the 512 MiB shared-memory spike used to run
dry, surfacing as an intermittent SIGSEGV in the oak-render tests.
- Add a gdb backtrace step on failure for the big suites (the openKylin
image installs gdb) so a native crash lands in the log next time.
The openKylin container image ships no fonts at all, so the font-backend
combo test found zero families and failed both retries; install
fonts-dejavu-core in the job (the Ubuntu runner image already has them).
Also includes the runner-size bumps (windows 32x, macos 12x) and the
vcpkg/cargo cache save conditions (`if: always()`).
The openKylin image runs as root while Actions sets HOME=/github/home;
dtolnay/rust-toolchain fails with "$HOME differs from euid-obtained home
directory" and the job never reaches the build. Pin HOME/CARGO_HOME/
RUSTUP_HOME to root's for the whole job.
vcpkg resolves the ffmpeg dependency before anything builds and rejects
the manifest because the pinned 8.1.2#3 port has no `png` feature
("ffmpeg@8.1.2#3 does not have required feature png needed by oak"),
so every desktop job died in "Install dependencies (vcpkg manifest)"
and never reached the build or test steps.
PNG decoding in FFmpeg needs zlib (png_decoder_deps=zlib); libpng is
only the encoder backend and this port never enables it. Request
`zlib` instead.
Also point the stale comments/docs at the actual pin: the override is
8.1.2#3 (matching the ffmpeg-next 8.x binding after the 9.0.0 binding
was found broken upstream), not 9.0.1#1.
Adds VAAPI DMA-BUF, D3D11VA shared-handle and VideoToolbox IOSurface
imports behind a tri-state outcome (imported / unsupported / failed),
planar textures with bounded residency and a CPU staging fallback, the
staged montage decode path, reference-counted decoder frames, VAAPI-first
device selection on Linux, and the host-GPU context plumbing used by the
app and worker. See docs/zh/plans/render-pipeline-threads.md (M5).
Three independent failures from the last run:
- Linux undefined `vaMapBuffer2`: the runner had apt libva 2.20 while
vcpkg builds shared libva 2.24.1, and the loader had no path to it.
Drop the apt libva packages and put `$prefix/lib` on LD_LIBRARY_PATH
for the Linux and openKylin jobs.
- openKylin "render manager failed to start": a container's /dev/shm is
64 MiB, but the process pool reserves >64 MiB per worker with
posix_fallocate, so segment creation fails. Run the container with
`--shm-size=2g`.
- macOS "no decoder for codec PNG": the vcpkg ffmpeg manifest never
enabled the `png` feature the oak-cli transcode tests need. Add it.
- Windows dependency install took 41 minutes: it was rebuilding FFmpeg
and every codec port from source because the binary archive cache was
never saved. The combined `actions/cache` step with the deprecated
`save-always: true` does not save after a failed job, and the previous
run failed in Build. Replace it in all four jobs with an explicit
restore + `actions/cache/save (if: always() && cache-hit != 'true')`.
- Windows: vcpkg ships `pkgconf` without the `pkg-config` shim, so the
oak-ffmpeg-link build script failed with "program not found". Probe
`pkg-config`, fall back to `pkgconf` (or honor `PKG_CONFIG`), and join
the child's `PKG_CONFIG_PATH` with the platform separator instead of a
hard-coded `:` (which split `C:\...` apart).
- Linux (and openKylin): the test binaries link the VAAPI stack via
vcpkg's FFmpeg; install the `libva2`/`libva-drm2`/`libvdpau1` runtime
packages the loader needs.
- macOS: bump the gpui submodule
(OakVideoEditorCommunity/oak-gpui@fix/macos-metal-layer-and-dead-code):
`setColorspace:` now sends to the `MetalLayerRef` (`self.layer.as_ref()`
made `&*layer` the owned type, which is not `objc::Message`), and the
viewer's `GpuFrameEntry` carries the non-Linux dead-code allowance.
- openKylin ARM64: switch the ocio patch to the fork's
fix/aarch64-c-char rev. Upstream models C `char*` as `*const i8`;
aarch64's `c_char` is u8, so the crates did not compile. The fix uses
`c_char` throughout ocio-sys and the ocio-rs boundary (pushed as
30338c6a169bbbada862fb3ac256e79b656159cf).
docs/zh/plans/render-pipeline-threads.md M2: the graph's textures stay
on the GPU from evaluation through presentation, and presentation runs
on the UI's own wgpu device.
- wgpu 25 -> 29 (naga 29) across the engine, unifying it with
gpui_wgpu so engine textures are directly sampleable by the presenter
(a single wgpu remains in the lockfile).
- GpuContext::adopt/install_shared: the app registers the window's
device at startup and the render thread renders on it;
texture_handle hands the raw Arc<wgpu::Texture> to
SurfaceSource::Texture - zero-copy present on Linux/FreeBSD. The
shared slot replaces an engine context that has not touched the GPU
yet (startup-order guard) and refuses once it has.
- Texture::Gpu shares a GpuLease so clones release the registry token
exactly once; the compositor, transitions and adjustment sweeps keep
GPU textures end to end (no per-clip readbacks; GPU clears for
black/generated frames).
- Color management stays on the GPU: the output node + display ICC
chain is baked into a 65^3 3D LUT with the exact CPU reference and
applied by the present WGSL pass (manual trilinear);
ColorTransformJob bakes its OCIO processor the same way. Neither
path skips color management.
- The explicit readback boundaries accept GPU textures: export
encoder, CLI, worker shm, disk cache; CPU OpenFX already read back.
- M5 dependency: the YUV->RGB GPU pass (BT.601/709/2020 x
limited/full) matches colormath::yuv444p16_to_rgb_f32.
- Acceptance: gpu_transfer_counters; single-clip and layered
(multi-track + transition + adjustment) playback tests assert zero
GPU->CPU readbacks, and the app test asserts adopted-device present
is zero-copy. GPU tests hard-fail when OAK_REQUIRE_GPU is set (CI
lavapipe) instead of skipping silently.
- vcpkg bootstrapped in every job (the Warp runners carry none):
clone + bootstrap into .cache/vcpkg, VCPKG_ROOT exported.
- vcpkg.json: ffmpeg pinned at 9.0.1#1 via overrides with
builtin-baseline 771b0a2e pinning the port tree; feature fixes
(gnutls -> openssl, ffnvcodec -> platform-qualified nvcodec,
vaapi on Linux, librsvg windows-only).
- Linux and macOS CI/CD jobs also take FFmpeg from the manifest
(static triplets x64-linux / arm64-osx keep the packaging story);
the build-ffmpeg.sh steps, FFmpeg caches and the codec dev
packages leave the workflows — system package managers keep only
the X11/audio/GL/Vulkan/tooling deps, now documented in
docs/build.md.
- New openKylin container job (openkylin/openkylin:latest) on x64
(warp-ubuntu-latest-x64-8x) and ARM64
(warp-ubuntu-latest-arm64-16x, arm64-linux triplet): openKylin
package names surveyed against the live image's apt index
(nasm/zip come from the kylinsoft anything3.0 PPA), clang for
bindgen, xvfb + lavapipe headless tests with the watchdog and
retry policy.
Known follow-ups (declared in the commit chain): vcpkg has not run
end-to-end yet, the pkg-config vs pkgconf executable name on
Windows, TLS semantics moving gnutls -> openssl.
The MinGW path kept fighting the environment (the GitHub image's
MSVC INCLUDE/LIB poison the GNU compiles; ocio-sys' fork then
dragged the MSVC-only headers into g++ and died on vcruntime.h).
The Windows jobs on both workflows now:
- run on warp-windows-2025-vs2026-x64-16x (preinstalled VS 2026)
with the stable MSVC Rust toolchain;
- install dependencies through vcpkg MANIFEST mode: vcpkg.json at
the repo root carries FFmpeg with every free codec + hwaccel
(mirroring build-ffmpeg.sh's configure), pkgconf and librsvg;
the vcpkg_installed tree plus the binary-cache archives are
cached on the manifest hash with save-always;
- build OCIO bundled (ocio-sys' vendored sources are what MSVC
wants — the MSYS2 package was the workaround, not the
preference), so OCIO_RS_NO_MSVC_INCLUDES is gone;
- ship the vcpkg runtime DLLs next to the binaries in the NSIS
installer with a static-CRT release build (no vcruntime DLLs),
replacing the ntldd-based MSYS2 bundling.
FFmpeg version pinning via builtin-baseline is a documented
follow-up: the Configure step logs vcpkg list so the first green
run reports the resolved versions. docs/build.md keeps the MSYS2
flow as the local alternative and points at the CI path.
The Gitea migration left CI on the self-hosted instance with every
cache commented out and the CD workflow broken at parse time
(kiname:). CI runs on GitHub-hosted runners again:
- Linux: ubuntu-latest with the rust toolchain from
dtolnay/rust-toolchain (the self-hosted runner's custom
RUSTUP_HOME/CARGO_HOME lines are gone) and the cargo + FFmpeg caches
re-enabled.
- Windows: windows-latest with msys2/setup-msys2 provisioning the
UCRT64 environment (the Gitea runner had it preinstalled); the
msys2 {0} shell, the GNU-target MSYS2 Rust, the
OCIO_RS_NO_MSVC_INCLUDES gate and the -lmsvcrt link-order workaround
carry over, as do both caches.
- macOS: new job on macos-14 (Apple Silicon) — Homebrew deps, vendored
static OCIO, cached FFmpeg, cargo check + the full suite with the
same retry-once flake policy.
CD fixes: the kiname: typo that kept the workflow from parsing, the
Warp runner labels become the standard GitHub ones, and all eight
commented-out cache blocks are restored. The gpui submodule URL
follows the move to GitHub, the README badge points at the GitHub
workflow, and the .gitea directory is dropped.
- 导出工程文件: the in-app dialog only picks the format (OTIO / OVE /
FCPXML); OK asks the system save dialog with the suggested file name
carrying the format's extension, then exports
- 打开项目: the system open dialog restricts the choosable files to
.ove/.ovexml/.otio/.fcpxml (PathPromptOptions.allowed_extensions
plumbed through gpui; Linux portal glob filter)
The script has no executable bit (git doesn't carry one reliably), so
the bare invocation failed with 'Permission
denied' in the Linux act runs. Every call site now uses
OCIO_RS_ENABLE_REAL=1
OCIO_RS_LINK=static instead.
Linux: 'libffnvcodec-dev' was dropped from Ubuntu noble — the NVDEC
headers are distribution-free, so install them from source
(nv-codec-headers git) like the Fedora branch already did; the
appimage step and install-deps.sh no longer apt-install the package.
Windows: ocio-sys is the GIT fork (pinned in the root manifest), so
the old crate-unpack + build.rs glob patch (registry/cache's
ocio-sys-0.2.1.crate) can never match — git dependencies don't ship a
.crate archive and unpack under registry/src/git/<hash>, hence the
"ls .../ocio-sys-0.2.1/build.rs: No such file" failure. The fork's
build.rs already carries the GNU-toolchain fix; the unpack/glob/sed
step is removed.
Policy change (supersedes the system-first probe): build OpenColorIO
from the vendored sources and link it statically on every platform
that can -- packaged binaries carry no OCIO runtime dependency. The
[patch.crates-io] ocio-sys now tracks shaloong/ocio-rs main
explicitly; its vendored yaml-cpp has the <cstdint> include that makes
the vendored build work on GCC >= 16 (verified on GCC 16.2.1).
Windows/MinGW stays the exception (the vendored source needs MSVC-only
constructs): tooling/ocio-env.sh probes the MSYS2 system OCIO there,
static when libOpenColorIO.a ships, dynamic otherwise. The Linux jobs
drop the system OCIO dev packages the system-first policy needed.
- Install ffnvcodec headers everywhere the project FFmpeg is built
(distro packages on Debian/Ubuntu/Arch/MSYS2, nv-codec-headers from
source on Fedora) so the FFmpeg build picks up NVDEC/NVENC.
- ocio-sys 0.2.1's vendored yaml-cpp misses <cstdint> and fails on
GCC >= 16 (measured on GCC 16.2.1); patch the dependency to the
fixed upstream tree (shaloong/ocio-rs, 933c65dc) until a fixed
release lands on crates.io.
- New tooling/ocio-env.sh decides the OCIO build env per job: system
OCIO >= 2.5 when present (static when the package ships
libOpenColorIO.a, dynamic otherwise), vendored static build as the
fallback. The Arch package gains an 'opencolorio' dependency only
when the binaries link the system OCIO (build-pkg.sh probes ldd).
- CI 'Build' steps switch from cargo build to cargo check: the Test
step links the test binaries anyway, and a full build would codegen
every workspace crate twice.
Gitea prep: .github becomes .gitea (the act runner looks there), and
every actions/cache + Swatinem/rust-cache step is commented out until
the self-hosted instance has a cache provisioned. The remaining
marketplace actions (checkout/upload-artifact are act-compatible;
msys2/setup-msys2, dtolnay/rust-toolchain and softprops/action-gh-release
need a runner test / replacement) are a follow-up.
tests: the two gpui keystroke tests that flaked on Windows CI (undo
pair, snapping toggle — each once, values identical to the pass state,
Global-route keys) now dispatch each key with a double park. The root
cause is not fully pinned: the loss happens inside gpui's synthetic
key dispatch on Windows (both tests hold every test lock; production
is unaffected). The CI retry-once remains the backstop. The earlier
idea of advancing the simulated clock to flush gpui's pending-input
timer is off the table: the mock engine's playback ticks with executor
time, so a clock advance moves the playhead out from under the
assertions (observed: playhead 14 vs expected 9).
Two different gpui keystroke tests flaked on Windows CI with the same
signature: a synthetic keystroke occasionally never reaches the action
(secondary-z lost while secondary-shift-z delivered; then a plain 's'
lost). Both passed every other run — a gpui test-harness delivery
flake, not an oak regression. A single retry pass absorbs it; a real
regression fails both passes.
oakstorage: the sqlite URI parse tests used /tmp/lib.db, which is not
absolute on Windows, so parse_target's is_absolute check rejected it.
Pick the absolute path per platform (C:/tmp/lib.db on Windows).
ci (Linux): wrap the test step in a 1500 s watchdog — a deadlocked
test prints nothing and never fails; on timeout the watchdog dumps
every test/worker process's thread stacks with gdb and then kills the
suite. (One such hang already ate a run; the previous green run needed
~4 min.)
ci+cd: Swatinem/rust-cache gains cache-on-failure everywhere, so a
red run still saves its compile cache (the actions/cache FFmpeg cache
already saves in its post phase regardless of outcome).
Windows: tooling/package/bundle-dylibs-windows.sh collects the MSYS2
runtime DLLs (libstdc++, libgcc, OpenColorIO, ...) with ntldd -R,
iterated to a fixpoint over freshly copied DLLs; a packager resources
glob places them next to the executables in the NSIS installer.
macOS: tooling/package/bundle-dylibs-macos.sh copies every non-system
dylib otool reports into Contents/Frameworks, rewrites the install
names to @executable_path/../Frameworks to a fixpoint, and ad-hoc
re-signs every modified Mach-O (rewriting invalidates the seal).
The CD package version no longer comes from the git tag: the root
Cargo.toml gains [workspace.package] version = "0.5.0", the oak
package inherits it (version.workspace = true — which cargo-packager
also picks up), and the Linux container packaging parses that field.
oakcodec: gate find_ffmpeg_searches_path to unix (chmod 0755 + shebang
fixture) and make find_ffmpeg_missing_returns_empty assert absoluteness
instead of a '/' prefix so the tests compile and pass on Windows.
ci (Windows): export RUSTFLAGS=-C link-args=-lmsvcrt in the build and
test steps. mingw-w64 (Nov 2025) forwards _assert to __msvcrt_assert
inside libmingwex.a, and rustc's link order leaves -lmingwex last, so
binaries that pull _assert.o (oakcommon's real_ocio test) fail to link;
a trailing -lmsvcrt re-scans the CRT import lib afterwards.
ci (Linux): copier_test dies inside ld.so before printing anything.
Replace the LD_DEBUG probe with stronger forensics: exported dynsyms
(interposition suspects), strace tail, valgrind tail, and siginfo
(si_code/si_addr) from the gdb run.
oakaudio: drop cpal's `asio` feature. asio-sys needs the proprietary
Steinberg ASIO SDK at link time (undefined ASIOGetSamplePosition etc.
on the GNU toolchain); WASAPI remains the Windows backend.
ci: the failure-only gdb step passed test args without --args, so gdb
treated --nocapture as a core file. Also collect loader-stage evidence
for the copier_test dl_main SIGSEGV: IRELATIVE reloc count, LD_DEBUG
tail, full backtrace and registers.
- localtime_s/gmtime_s are MinGW header inlines, not symbols — link
_localtime64_s/_gmtime64_s
- copier_test also segfaults only on the Linux runner; add it to the
on-failure gdb backtrace
- oakffmpeg-link forwards pkg-config --static --libs verbatim; FFmpeg's
.pc files can list -ldl via external deps, and MinGW has no libdl
- suites_test segfaults on the Linux runner too; run both plugin test
binaries under gdb on test failure