[
https://issues.apache.org/jira/browse/THRIFT-6399?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jens Geyer reassigned THRIFT-6399:
----------------------------------
Assignee: Jens Geyer
> Let the WinGet and Chocolatey workflows take the installer from the GitHub
> release
> ----------------------------------------------------------------------------------
>
> Key: THRIFT-6399
> URL: https://issues.apache.org/jira/browse/THRIFT-6399
> Project: Thrift
> Issue Type: Improvement
> Components: Build Process
> Reporter: Jens Geyer
> Assignee: Jens Geyer
> Priority: Major
>
> The WinGet manifest and the Chocolatey package download the Windows installer
> from {{archive.apache.org}}. It gets there through {{dist/release}} when the
> release vote covered the installer. When the vote did not cover it, it is not
> there, and it is not added afterwards, since {{dist/release}} holds what the
> vote covered. The 0.25.0 vote covered the source tarball and
> {{thrift-0.25.0.exe}}, so the WinGet and Chocolatey runs of that release
> could not find the installer.
> The GitHub release carries the installer as an unsigned convenience copy,
> which the {{Windows packages}} workflow builds around the voted
> {{thrift-<version>.exe}} and attaches. Its download URL is permanent and
> needs no login. A workflow artifact offers neither: it expires, and
> downloading it requires a GitHub login.
> h2. Change
> * {{build-winget-manifests.ps1}} and {{build-chocolatey-package.ps1}} get
> {{-InstallerSource}}. It is {{archive}} by default, or {{github}} for the
> installer attached to the GitHub release. The tests cover both, and that an
> unknown source, or a source together with {{-InstallerUrl}}, is refused.
> * A manual run of the {{WinGet}} and {{Chocolatey}} workflows takes the
> source from a new {{installer_source}} input. A release run keeps using the
> archive.
> * The Chocolatey package description no longer says that the installer comes
> from the Apache archive.
> * {{doc/ReleaseManagement.md}}: when the installer was not part of the
> release candidate, it is no longer added to {{dist/release}} after the
> release. Instead, the two workflows are run with {{installer_source}} set to
> {{github}}, once the asset on the GitHub release is the one built around the
> voted compiler. That asset must not be replaced afterwards, because both
> package managers record its SHA-256. {{build/windows/README.md}} and the
> comments in {{windows-packages.yml}} say the same.
> The release run of the {{Windows packages}} workflow for 0.25.0 predates
> THRIFT-6397 and built its own compiler. The asset on the 0.25.0 GitHub
> release has therefore been replaced with the installer built around
> {{thrift-0.25.0.exe}}.
> _Drafted with AI assistance (Claude Opus 5.5)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)