Skip to content

Ship prebuilt binaries and a task-first README - #9

Merged
jserv merged 5 commits into
mainfrom
prebuilt
Oct 4, 2026
Merged

jserv merged 5 commits into
mainfrom
prebuilt

Conversation

@jserv

@jserv jserv commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Installing hackmd-mcp meant a Rust toolchain and a full build, and the README opened with build commands and environment variable edge cases before it said what the server is for. This adds prebuilt binaries in the style of frama-c-mcp and rewrites the README around why an agent benefits from HackMD access and a five-step quick start, with the detail moved to docs/.

Every push to main that passes the whole lane now replaces a rolling latest release with binaries for Linux x86_64, macOS arm64 and Windows x86_64 (the platforms the test matrix runs on), plus SHA256SUMS. The Linux binary is linked by cargo-zigbuild against glibc 2.17, so it runs on any glibc distribution from RHEL 7 on; a CI step reads the newest GLIBC symbol off the binary, because the smoke run on Ubuntu 24.04 cannot see it. The publish script checks every input before deleting the old release, aborts on any API status other than 200/404, and does nothing when its commit is no longer the head of main.

The docs also correct claims the old README overstated or got wrong: only body edits and folder changes are read back, the body hash guard is optional and not atomic, and Codex forwards only the variables listed in env_vars, so the previous Codex setup left the server without a token.

Verified locally: make check (276 passed) and clippy with -D warnings; actionlint, shellcheck and shfmt on the workflow and .ci/ scripts; a zig cross build whose newest GLIBC symbol is 2.17, with the floor check passing at 2.17 and failing at 2.16; --self-check with no token and a fresh state directory exits 0; both release scripts against a stubbed gh (missing assets, wrong asset set, a 500, a stale commit, a normal publish); every relative link and anchor in README.md and docs/. The build and release jobs themselves have not run on GitHub yet, so this PR's checks are their first run (release only fires after merge).

Left out: Linux arm64, a musl build, and per-commit immutable releases.


Summary by cubic

Makes installing hackmd-mcp a download instead of a Rust build, and rewrites the README to lead with why an agent benefits from HackMD access before a five-step quick start.

Release and install

  • Every push to main that passes CI replaces a rolling latest release with binaries for Linux x86_64, macOS arm64, and Windows x86_64, plus SHA256SUMS.
  • The Linux binary is linked against glibc 2.17 via cargo-zigbuild, so it runs on any glibc distribution from RHEL 7 on.
  • The publish script checks all inputs before deleting the old release, aborts on any API failure, and does nothing when the commit is no longer the head of main.

Documentation

  • Moves configuration, client setup, tool workflows, and development notes into docs/, accessed from a shorter README.
  • Fixes install steps that failed on RHEL-family and minimal Linux, and examples that relied on ~ expansion in JSON and TOML configs.
  • Corrects earlier claims: only body edits and folder changes are read back, the body hash guard is optional and not atomic, and Codex forwards only the variables listed in env_vars.

Written for commit 03d25a5. Summary will update on new commits.

Review in cubic

jserv added 3 commits October 4, 2026 08:18
The documentation tells users to copy it for local development, so it
has to ship with the repository. It holds only placeholders.
Installing meant a Rust toolchain and a full build. Every push to main
that passes the whole lane now replaces a "latest" release holding
binaries for the three platforms the suite runs on, plus SHA256SUMS,
since a rolling tag offers no version to pin.

The Linux binary is linked by zig against glibc 2.17, not the runner's
2.39, so it starts on any glibc distribution from RHEL 7 on. The smoke
run cannot see a symbol versioned past that floor, so a step reads it
off the binary. zig is the linker of what ships, so its wheels are
pinned by hash.

Publishing deletes and recreates the release so the tag moves to the
commit built. Every input is checked before the first deletion, an
older run re-run on main leaves the release alone, and runs on main are
no longer cancelled mid-publish.
The README opened with build commands and spent most of its length on
environment variable edge cases, so a new user had to read all of it to
connect an agent. It now says what an agent gains from HackMD access,
then gives a five-step quick start: download, environment, self-check,
connect, ask.

The detail moved to docs/: configuration, client setup, the editing and
sync workflows, and development. Claims the old text overstated now
match the code: only body edits and folder changes are read back, the
body hash guard is optional and not atomic, and Codex forwards only the
variables listed in env_vars, so the previous Codex setup left the
server without a token.
cubic-dev-ai[bot]

This comment was marked as resolved.

jserv added 2 commits October 4, 2026 08:50
The draft cleanup ran its lookup inside a for list, where set -e does
not see a failure, so an API error there carried on to the create with
the old release already deleted. The lookup is now an assignment of its
own, which set -e does stop.
The checksum step used shasum, which minimal and RHEL-family Linux
systems lack, with --ignore-missing, which coreutils before 8.25 lacks;
it now checks the one asset with sha256sum, and names shasum for macOS.
The absolute-path example used ~, which JSON and TOML configs do not
expand. A replaced workspace root is refused only on Unix, and a root
set in .env is untrusted, and the docs and .env.example now say so.
@jserv
jserv merged commit c61c968 into main Oct 4, 2026
11 checks passed
@jserv
jserv deleted the prebuilt branch October 4, 2026 01:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant