Jens Geyer created THRIFT-6399:
----------------------------------
Summary: Let the WinGet and Chocolatey workflows take the
installer from the GitHub release
Key: THRIFT-6399
URL: https://issues.apache.org/jira/browse/THRIFT-6399
Project: Thrift
Issue Type: Improvement
Components: Build Process
Reporter: Jens Geyer
The WinGet manifest and the Chocolatey package download the Windows installer
from {{archive.apache.org}}. It gets there through {{dist/release}} when the
release vote covered the installer. When the vote did not cover it, it is not
there, and it is not added afterwards, since {{dist/release}} holds what the
vote covered. The 0.25.0 vote covered the source tarball and
{{thrift-0.25.0.exe}}, so the WinGet and Chocolatey runs of that release could
not find the installer.
The GitHub release carries the installer as an unsigned convenience copy, which
the {{Windows packages}} workflow builds around the voted
{{thrift-<version>.exe}} and attaches. Its download URL is permanent and needs
no login. A workflow artifact offers neither: it expires, and downloading it
requires a GitHub login.
h2. Change
* {{build-winget-manifests.ps1}} and {{build-chocolatey-package.ps1}} get
{{-InstallerSource}}. It is {{archive}} by default, or {{github}} for the
installer attached to the GitHub release. The tests cover both, and that an
unknown source, or a source together with {{-InstallerUrl}}, is refused.
* A manual run of the {{WinGet}} and {{Chocolatey}} workflows takes the source
from a new {{installer_source}} input. A release run keeps using the archive.
* The Chocolatey package description no longer says that the installer comes
from the Apache archive.
* {{doc/ReleaseManagement.md}}: when the installer was not part of the release
candidate, it is no longer added to {{dist/release}} after the release.
Instead, the two workflows are run with {{installer_source}} set to {{github}},
once the asset on the GitHub release is the one built around the voted
compiler. That asset must not be replaced afterwards, because both package
managers record its SHA-256. {{build/windows/README.md}} and the comments in
{{windows-packages.yml}} say the same.
The release run of the {{Windows packages}} workflow for 0.25.0 predates
THRIFT-6397 and built its own compiler. The asset on the 0.25.0 GitHub release
has therefore been replaced with the installer built around
{{thrift-0.25.0.exe}}.
_Drafted with AI assistance (Claude Opus 5.5)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)