Repository navigation
Fix Windows release toolchain compatibility and add archive checksums - #180
Merged
Merged
Conversation
Co-authored-by: Copilot App <[email protected]>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The locking and release-pipeline changes are consistent, scoped, and adequately validated.
Review effort: Balanced
Findings: None
What changed in this PR
Updates Windows generation locking for Rust 1.88 compatibility and adds SHA-256 sidecars to signed Windows release archives.
Changes:
- Replaces standard-library file locking with
fs2and adds lock lifecycle coverage. - Updates dependency manifests and lockfiles.
- Generates, stages, and optionally publishes architecture-specific checksum files.
| File | Description |
|---|---|
tgrep-core/src/generations/mod.rs |
Uses fs2 locking and adds regression coverage. |
tgrep-core/tests/generations.rs |
Updates process-worker locking. |
tgrep-core/Cargo.toml |
Adds the fs2 dependency. |
Cargo.lock |
Adds the core dependency edge. |
fuzz/Cargo.lock |
Resolves fs2 and WinAPI dependencies. |
.github/workflows/sign-and-release.yml |
Generates and publishes Windows checksum sidecars. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
std::fs::File::lockwithfs2::FileExt::lock_exclusive, using the samefs2 = 0.4.3dependency already used by the CLI. Update the process-worker lock and add a regression for exclusivity and release on drop..github/workflows/sign-and-release.yml, which is Azure DevOps OneBranch YAML, not a GitHub Actions workflow. Each Windows x64/arm64 job hashes the final signed ZIP with streaming .NET SHA256 and writes<zip-name>.sha256as lowercase hex, two spaces, archive filename, and LF, encoded as UTF-8 without a BOM. Scripts remain inline because OneBranch uses a partial clone.CopyFiles@2andGitHubRelease@1to that job's exact ZIP and sidecar. Preserveaction: edit,assetUploadMode: replace, the optional publish gate, andPublishToGitHub: falseby default. Microsoft's task documentation specifies thatreplacereplaces only same-name assets; the defaultdeletewould delete existing assets.The six-file diff does not create or modify
checksums.txt, change the Linux/macOSrelease.yml, or change existing build/signing steps. The root lockfile adds only the core dependency edge; the fuzz lockfile adds exactly 33 lines forfs2and its WinAPI dependencies without changing the existingtempfile/getrandomedge or package versions.Validation
Repeated in this PR worktree:
cargo metadata --locked --offline --format-version 1accepted the lockfile (194 packages); current-stable locked/offline fuzz metadata accepted its lockfile (115 packages).cargo +stable fmt --all -- --checkandgit -c core.whitespace=cr-at-eol diff --checkpassed.checksums.txt, Linux/macOS assets and the other architecture's checksum, and nonzero failure with no generated checksum for a missing archive.Previously completed by the parent session on the identical prepared patch, reused here rather than repeating a fresh full build:
cargo +1.88.0 test --locked --offline --quiet -p tgrep-core --lib --test generations: 316 unit tests and 24 integration tests passed, including process serialization and crash unlock.cargo +1.88.0 check --locked --offline --quiet --workspace --all-targetspassed.tgrep --versionreturned exactlytgrep 1.1.0\n, exit 0, and empty stderr.Release boundary
This is a new follow-up PR targeting
mainafter merged #179. No version bump, tag movement or creation, release edit/publication, workflow dispatch, or internal pipeline run is included. The publishedv1.1.0tag remains immutable and does not gain these fixes retroactively; consuming them requires a later release or explicitly selecting a source revision containing this change. Internal OneBranch execution and signing are not claimed as validated by these local checks.