Jens-G opened a new pull request, #3985:
URL: https://github.com/apache/thrift/pull/3985

   [THRIFT-6397](https://issues.apache.org/jira/browse/THRIFT-6397)
   
   **Stacked on #3983 (THRIFT-6396).** The first commit here is #3983's; this 
PR's change is the second commit, 9572dbdba. I will rebase it onto master once 
#3983 is merged.
   
   The Windows installer of a release has to contain the `thrift.exe` the vote 
covered, and a new build of the same source is not the same bytes. The `Windows 
packages` workflow could only package a compiler it built itself, so the 
installer for dist.apache.org had to be built by hand with Inno Setup.
   
   **Changes**
   - `build/windows/get-voted-compiler.ps1` downloads a `thrift-<version>.exe` 
from a release candidate's or a release's directory on dist.apache.org, with 
its `.asc`, its `.sha512`/`.sha256` and `KEYS`. It refuses the file unless 
every checksum matches and the signature is good (`GOODSIG`) and made with a 
key from `KEYS`. Only 
`https://dist.apache.org/repos/dist/{dev,release}/thrift/…/thrift-<version>.exe`
 URLs are accepted.
   - `build/windows/get-voted-compiler-tests.ps1` tests that with a throwaway 
GPG key. A new `download-checks` job runs it on every run of the workflow, pull 
requests included.
   - `windows-packages.yml` packages that executable when it is started with 
the new `compiler_url` input, and, from `dist/release`, when the GitHub release 
is published. The installer then carries the `LICENSE` and `NOTICE` of the 
release tag, or of the branch for a release candidate. Pull requests and runs 
without `compiler_url` still build the compiler from source. If the download or 
the checks fail, nothing is packaged: a release never falls back to its own 
build.
   - `test-installer.ps1` gets `-ExpectedSha256`, which the workflow uses to 
check that the installed `thrift.exe` is the file it packaged. The run summary 
names the compiler's source and hash.
   - `build-installer.ps1` hands `-SourceRoot` to Inno Setup as an absolute 
path. A relative one was resolved against `thrift.iss`. With an echo stand-in 
for `ISCC.exe`, `-SourceRoot voted` arrived as `/DSourceRoot=voted` before this 
change and as an absolute path after it.
   - `doc/ReleaseManagement.md` (the release candidate steps, and adding a 
missing installer after a release) and `build/windows/README.md`.
   
   **Verification**
   - `get-voted-compiler-tests.ps1`: 18 checks pass with pwsh 7.6 and gpg 
2.4.7, and each refusal fails for its own reason:
     - SHA-512 mismatch;
     - `BADSIG` when the checksums were redone after the change;
     - `ERRSIG` for a key that is not in `KEYS`;
     - missing signature or checksum;
     - wrong file name;
     - six bad URLs, refused before anything is downloaded.
   - Real download: `-Url 
https://dist.apache.org/repos/dist/release/thrift/0.25.0/thrift-0.25.0.exe` 
gives SHA-256 `9e1cb466…af08e`, the value in the 0.25.0-rc1 vote mail. The 
signature is good and from `KEYS`.
   - The LICENSE/NOTICE step, replayed in a depth-1 clone:
     - version 0.25.0 takes the files from tag `v0.25.0`;
     - version 0.26.0, which has no tag, takes them from the branch;
     - version 0.27.0 fails with an error, because the branch is at 0.26.0.
   - Job plan, evaluated from the workflow file:
   
   | Run | download-checks | voted-compiler | installer | publish |
   |---|---|---|---|---|
   | pull request | runs | skipped | builds from source | skipped |
   | manual, no `compiler_url` | runs | skipped | builds from source | skipped |
   | manual, `compiler_url` | runs | runs | packages the download | skipped |
   | manual, download refused | runs | fails | skipped | skipped |
   | release | runs | runs | packages `dist/release` exe | runs |
   | release, checks fail their tests | fails | skipped | skipped | skipped |
   
   - actionlint and zizmor (`--persona regular`, with a token) report nothing.
   
   Pull request CI exercises only the build-from-source path, including the new 
hash check on the Windows runner. The download path first runs on a real 
Windows runner when the workflow is started with `compiler_url`. For 0.25.0, 
that means `compiler_url` = 
`https://dist.apache.org/repos/dist/release/thrift/0.25.0/thrift-0.25.0.exe`, 
which also produces the 0.25.0 installer to sign.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to