Jens-G opened a new pull request, #3985: URL: https://github.com/apache/thrift/pull/3985
[THRIFT-6397](https://issues.apache.org/jira/browse/THRIFT-6397) **Stacked on #3983 (THRIFT-6396).** The first commit here is #3983's; this PR's change is the second commit, 9572dbdba. I will rebase it onto master once #3983 is merged. The Windows installer of a release has to contain the `thrift.exe` the vote covered, and a new build of the same source is not the same bytes. The `Windows packages` workflow could only package a compiler it built itself, so the installer for dist.apache.org had to be built by hand with Inno Setup. **Changes** - `build/windows/get-voted-compiler.ps1` downloads a `thrift-<version>.exe` from a release candidate's or a release's directory on dist.apache.org, with its `.asc`, its `.sha512`/`.sha256` and `KEYS`. It refuses the file unless every checksum matches and the signature is good (`GOODSIG`) and made with a key from `KEYS`. Only `https://dist.apache.org/repos/dist/{dev,release}/thrift/…/thrift-<version>.exe` URLs are accepted. - `build/windows/get-voted-compiler-tests.ps1` tests that with a throwaway GPG key. A new `download-checks` job runs it on every run of the workflow, pull requests included. - `windows-packages.yml` packages that executable when it is started with the new `compiler_url` input, and, from `dist/release`, when the GitHub release is published. The installer then carries the `LICENSE` and `NOTICE` of the release tag, or of the branch for a release candidate. Pull requests and runs without `compiler_url` still build the compiler from source. If the download or the checks fail, nothing is packaged: a release never falls back to its own build. - `test-installer.ps1` gets `-ExpectedSha256`, which the workflow uses to check that the installed `thrift.exe` is the file it packaged. The run summary names the compiler's source and hash. - `build-installer.ps1` hands `-SourceRoot` to Inno Setup as an absolute path. A relative one was resolved against `thrift.iss`. With an echo stand-in for `ISCC.exe`, `-SourceRoot voted` arrived as `/DSourceRoot=voted` before this change and as an absolute path after it. - `doc/ReleaseManagement.md` (the release candidate steps, and adding a missing installer after a release) and `build/windows/README.md`. **Verification** - `get-voted-compiler-tests.ps1`: 18 checks pass with pwsh 7.6 and gpg 2.4.7, and each refusal fails for its own reason: - SHA-512 mismatch; - `BADSIG` when the checksums were redone after the change; - `ERRSIG` for a key that is not in `KEYS`; - missing signature or checksum; - wrong file name; - six bad URLs, refused before anything is downloaded. - Real download: `-Url https://dist.apache.org/repos/dist/release/thrift/0.25.0/thrift-0.25.0.exe` gives SHA-256 `9e1cb466…af08e`, the value in the 0.25.0-rc1 vote mail. The signature is good and from `KEYS`. - The LICENSE/NOTICE step, replayed in a depth-1 clone: - version 0.25.0 takes the files from tag `v0.25.0`; - version 0.26.0, which has no tag, takes them from the branch; - version 0.27.0 fails with an error, because the branch is at 0.26.0. - Job plan, evaluated from the workflow file: | Run | download-checks | voted-compiler | installer | publish | |---|---|---|---|---| | pull request | runs | skipped | builds from source | skipped | | manual, no `compiler_url` | runs | skipped | builds from source | skipped | | manual, `compiler_url` | runs | runs | packages the download | skipped | | manual, download refused | runs | fails | skipped | skipped | | release | runs | runs | packages `dist/release` exe | runs | | release, checks fail their tests | fails | skipped | skipped | skipped | - actionlint and zizmor (`--persona regular`, with a token) report nothing. Pull request CI exercises only the build-from-source path, including the new hash check on the Windows runner. The download path first runs on a real Windows runner when the workflow is started with `compiler_url`. For 0.25.0, that means `compiler_url` = `https://dist.apache.org/repos/dist/release/thrift/0.25.0/thrift-0.25.0.exe`, which also produces the 0.25.0 installer to sign. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
