Skip to content

Fix Windows release toolchain compatibility and add archive checksums - #180

Merged
Shengyu Fu (shengyfu) merged 1 commit into
mainfrom
shengyfu-windows-release-fixes
Oct 7, 2026
Merged

Shengyu Fu (shengyfu) merged 1 commit into
mainfrom
shengyfu-windows-release-fixes

Conversation

@shengyfu

Copy link
Copy Markdown
Member

Summary

  • Keep generation publication locks compatible with the internal Windows Rust toolchain by replacing std::fs::File::lock with fs2::FileExt::lock_exclusive, using the same fs2 = 0.4.3 dependency already used by the CLI. Update the process-worker lock and add a regression for exclusivity and release on drop.
  • Update .github/workflows/sign-and-release.yml, which is Azure DevOps OneBranch YAML, not a GitHub Actions workflow. Each Windows x64/arm64 job hashes the final signed ZIP with streaming .NET SHA256 and writes <zip-name>.sha256 as lowercase hex, two spaces, archive filename, and LF, encoded as UTF-8 without a BOM. Scripts remain inline because OneBranch uses a partial clone.
  • Restrict both CopyFiles@2 and GitHubRelease@1 to that job's exact ZIP and sidecar. Preserve action: edit, assetUploadMode: replace, the optional publish gate, and PublishToGitHub: false by default. Microsoft's task documentation specifies that replace replaces only same-name assets; the default delete would delete existing assets.

The six-file diff does not create or modify checksums.txt, change the Linux/macOS release.yml, or change existing build/signing steps. The root lockfile adds only the core dependency edge; the fuzz lockfile adds exactly 33 lines for fs2 and its WinAPI dependencies without changing the existing tempfile/getrandom edge or package versions.

Validation

Repeated in this PR worktree:

  • Confirmed the applied and staged diffs are byte-for-byte identical to the prepared, previously validated patch; exactly six changed files, 128 insertions and 11 deletions.
  • Rust 1.88.0 root cargo metadata --locked --offline --format-version 1 accepted the lockfile (194 packages); current-stable locked/offline fuzz metadata accepted its lockfile (115 packages).
  • cargo +stable fmt --all -- --check and git -c core.whitespace=cr-at-eol diff --check passed.
  • Extracted and executed both actual inline YAML checksum scripts under Windows PowerShell 5.1 against ZIP fixtures. Verified exact SHA256 bytes and GNU checksum format, LF/no BOM, unchanged input ZIPs, preservation of preexisting checksums.txt, Linux/macOS assets and the other architecture's checksum, and nonzero failure with no generated checksum for a missing archive.
  • Parsed YAML and verified sign → package → checksum → copy → optional publish ordering, exact disjoint asset lists, and retained edit/replace/default-false publishing behavior.

Previously completed by the parent session on the identical prepared patch, reused here rather than repeating a fresh full build:

  • Reproduced the original E0658 with Rust 1.88.0 before the fix.
  • cargo +1.88.0 test --locked --offline --quiet -p tgrep-core --lib --test generations: 316 unit tests and 24 integration tests passed, including process serialization and crash unlock.
  • cargo +1.88.0 check --locked --offline --quiet --workspace --all-targets passed.
  • Rust 1.88.0 Windows x64 release build succeeded; tgrep --version returned exactly tgrep 1.1.0\n, exit 0, and empty stderr.
  • Current-stable Clippy for the core library and generation tests passed.

Release boundary

This is a new follow-up PR targeting main after merged #179. No version bump, tag movement or creation, release edit/publication, workflow dispatch, or internal pipeline run is included. The published v1.1.0 tag remains immutable and does not gain these fixes retroactively; consuming them requires a later release or explicitly selecting a source revision containing this change. Internal OneBranch execution and signing are not claimed as validated by these local checks.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 04:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The locking and release-pipeline changes are consistent, scoped, and adequately validated.

Review effort: Balanced
Findings: None

What changed in this PR

Updates Windows generation locking for Rust 1.88 compatibility and adds SHA-256 sidecars to signed Windows release archives.

Changes:

  • Replaces standard-library file locking with fs2 and adds lock lifecycle coverage.
  • Updates dependency manifests and lockfiles.
  • Generates, stages, and optionally publishes architecture-specific checksum files.
File Description
tgrep-core/​src/​generations/​mod.rs Uses fs2 locking and adds regression coverage.
tgrep-core/​tests/​generations.rs Updates process-worker locking.
tgrep-core/​Cargo.toml Adds the fs2 dependency.
Cargo.lock Adds the core dependency edge.
fuzz/​Cargo.lock Resolves fs2 and WinAPI dependencies.
.github/​workflows/​sign-and-release.yml Generates and publishes Windows checksum sidecars.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@shengyfu
Shengyu Fu (shengyfu) merged commit 1120aca into main Oct 7, 2026
12 checks passed
@shengyfu
Shengyu Fu (shengyfu) deleted the shengyfu-windows-release-fixes branch October 7, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants