One-off: restamp workflow for the v3.4.0 archives (#2113/#2147/#2151) - #2152
erikdarlingdata wants to merge 1 commit into
Conversation
Erik-authorized: rebuilds the three plain archives from restamp-3.4.0 (= v3.4.0 tag + only the stamp fix) with a stamp-verification gate, merges checksums, and clobbers onto the existing release. Velopack chain untouched by design. Revert this commit after the run. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Closing — the branch gate correctly only allows dev→main, and there's a cleaner path: push-triggered workflows run from any branch without default-branch registration. The workflow now lives on restamp-3.4.0 with an on:push trigger scoped to that branch. |
| - name: Publish Lite | ||
| run: dotnet publish Lite/PerformanceMonitorLite.csproj -c Release -o publish/Lite | ||
|
|
||
| - name: Publish Darling Service | ||
| run: dotnet publish Darling/PerformanceMonitor.Darling.Service/PerformanceMonitor.Darling.Service.csproj -c Release -o publish/DarlingService | ||
|
|
||
| - name: Publish Darling Viewer | ||
| run: dotnet publish Darling/PerformanceMonitor.Darling.Viewer/PerformanceMonitor.Darling.Viewer.csproj -c Release -o publish/DarlingViewer | ||
|
|
||
| - name: Verify the stamp actually derives (the whole point) | ||
| shell: pwsh | ||
| run: | | ||
| $v = (Get-Item publish/Lite/PerformanceMonitorLite.dll).VersionInfo | ||
| Write-Host "Lite FileVersion=$($v.FileVersion) ProductVersion=$($v.ProductVersion)" | ||
| if ($v.FileVersion -notlike '3.4.0*') { throw "Lite still stamped $($v.FileVersion) — abort before touching the release" } | ||
| $d = (Get-Item publish/DarlingService/PerformanceMonitor.Darling.Service.dll).VersionInfo | ||
| Write-Host "Darling FileVersion=$($d.FileVersion)" | ||
| if ($d.FileVersion -notlike '3.4.0*') { throw "Darling still stamped $($d.FileVersion) — abort" } | ||
|
|
||
| - name: Cache Darling pg-runtime.zip | ||
| id: cache-pg-runtime | ||
| uses: actions/cache@v6 | ||
| with: | ||
| path: Darling/artifacts/pg-runtime.zip | ||
| key: pg-runtime-${{ runner.os }}-${{ hashFiles('Darling/tools/fetch-pg-runtime.ps1') }} | ||
|
|
||
| - name: Build Darling pg-runtime.zip | ||
| if: steps.cache-pg-runtime.outputs.cache-hit != 'true' | ||
| shell: pwsh | ||
| run: ./Darling/tools/fetch-pg-runtime.ps1 | ||
|
|
||
| - name: Package archives (plain 3.4.0 names) | ||
| shell: pwsh | ||
| run: | | ||
| New-Item -ItemType Directory -Force -Path releases | ||
| Compress-Archive -Path 'publish/Lite/*' -DestinationPath "releases/PerformanceMonitorLite-3.4.0.zip" -Force | ||
|
|
||
| $darlingDir = 'publish/Darling' | ||
| New-Item -ItemType Directory -Force -Path "$darlingDir/viewer" | Out-Null | ||
| Copy-Item 'publish/DarlingService/*' $darlingDir -Recurse | ||
| Copy-Item 'publish/DarlingViewer/*' "$darlingDir/viewer" -Recurse | ||
| Copy-Item 'Darling/artifacts/pg-runtime.zip' $darlingDir | ||
| Compress-Archive -Path 'publish/Darling/*' -DestinationPath "releases/PerformanceMonitorDarling-3.4.0.zip" -Force |
There was a problem hiding this comment.
No SignPath signing before these archives are built and clobbered onto the release.
build.yml's real release path (if: github.event_name == 'release') publishes Lite/Darling, then routes them through signpath/github-action-submit-signing-request (Sign Lite / Sign Darling, ~lines 360-411) and zips the signed output (signed/Lite/*, signed/Darling/*). This workflow publishes straight to publish/Lite / publish/DarlingService / publish/DarlingViewer and zips those directly — no signing step at all.
Since the comment block at the top says this mirrors nightly.yml "verbatim," that's consistent with nightly (which is also never signed), but nightly builds aren't uploaded as the plain-zip assets on a real numbered release. Running this as-is will clobber the currently-signed PerformanceMonitorLite-3.4.0.zip and PerformanceMonitorDarling-3.4.0.zip on the v3.4.0 release with unsigned executables — a real regression in binary trust/provenance for anyone who (re)downloads after this runs (likely triggering SmartScreen/AV warnings that the original signed release didn't have).
Worth confirming this is an intentional, accepted trade-off before running — the PR description doesn't mention it.
| - name: Verify the stamp actually derives (the whole point) | ||
| shell: pwsh | ||
| run: | | ||
| $v = (Get-Item publish/Lite/PerformanceMonitorLite.dll).VersionInfo | ||
| Write-Host "Lite FileVersion=$($v.FileVersion) ProductVersion=$($v.ProductVersion)" | ||
| if ($v.FileVersion -notlike '3.4.0*') { throw "Lite still stamped $($v.FileVersion) — abort before touching the release" } | ||
| $d = (Get-Item publish/DarlingService/PerformanceMonitor.Darling.Service.dll).VersionInfo | ||
| Write-Host "Darling FileVersion=$($d.FileVersion)" | ||
| if ($d.FileVersion -notlike '3.4.0*') { throw "Darling still stamped $($d.FileVersion) — abort" } |
There was a problem hiding this comment.
Minor: this stamp-verification gate checks publish/Lite/PerformanceMonitorLite.dll and publish/DarlingService/PerformanceMonitor.Darling.Service.dll, but not publish/DarlingViewer/PerformanceMonitor.Darling.Viewer.dll, even though the viewer ships inside PerformanceMonitorDarling-3.4.0.zip (viewer/ subfolder, packaged a few steps down). If the single-source stamp fix somehow didn't reach the Viewer project, this gate wouldn't catch it before the archive gets uploaded. Presumably low-risk since it's one shared version source, but the gate's stated purpose is "verify the stamp actually derives" for everything about to ship.
ReviewThis PR adds a single one-off, Main finding (left inline, on the packaging step): the workflow skips SignPath signing entirely. Minor (left inline): the stamp-verification gate checks Lite and Darling Service DLLs but not the Darling Viewer DLL, even though the Viewer ships inside the Darling zip. Probably fine given the single-source version stamp, but worth a second look. Checked and looks correct:
|
Erik-authorized (this morning, on the back of #2151 — the third user report from the 3.4.0 stamp): adds a workflow_dispatch-only workflow that rebuilds the three PLAIN archives from
restamp-3.4.0(= the v3.4.0 tag + only the single-source stamp fix cherry-picked, verified version-properties-only) and clobbers them + merged checksums onto the existing v3.4.0 release.workflow_dispatchrequires default-branch registration. Revert after the run.Build steps mirror nightly.yml verbatim (same publish shapes, archive layouts, pg-runtime staging), version fixed at plain 3.4.0.