Repository navigation
THRIFT-6399: Let the WinGet and Chocolatey workflows take the installer from the GitHub release - #3995
Merged
Conversation
…er from the GitHub release Client: build The WinGet manifest and the Chocolatey package download the Windows installer from archive.apache.org, where it arrives through dist/release when the release vote covered it. When the vote did not cover it, as for 0.25.0, it is not there, and dist/release is not the place to add it afterwards. The GitHub release carries it as a convenience copy, built around the voted compiler, at a permanent URL that needs no login. build-winget-manifests.ps1 and build-chocolatey-package.ps1 get -InstallerSource: archive, the default, or github for that copy. An unknown source, or a source together with -InstallerUrl, is refused, and a failed download names what to check for the source in use. The tests cover the new URL and both refusals. A manual run of the WinGet and Chocolatey workflows takes the source from a new installer_source input. A release run keeps the archive. The Chocolatey package description no longer says that the installer comes from the Apache archive. doc/ReleaseManagement.md no longer adds an installer the vote did not cover to dist/release after the release. The two workflows are run with installer_source github instead, once the copy on the GitHub release is built around the voted compiler, and that copy is not replaced afterwards, because both package managers record its SHA-256. build/windows/README.md and the comments in windows-packages.yml say the same. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
THRIFT-6399
The WinGet manifest and the Chocolatey package download the Windows installer from
archive.apache.org, where it arrives throughdist/releasewhen the release vote covered it. When the vote did not cover it, as for 0.25.0, it is not there, anddist/releaseis not the place to add it afterwards. The GitHub release carries the installer as a convenience copy, built around the voted compiler, at a permanent URL that needs no login. A workflow artifact would not do: downloading one needs a GitHub login (anonymously, the API answers 401 and the web link 404), and it expires.Changes
build-winget-manifests.ps1andbuild-chocolatey-package.ps1get-InstallerSource. It isarchiveby default, orgithub, which points athttps://github.com/apache/thrift/releases/download/v<version>/thrift-<version>-setup.exe. An unknown source, or a source together with-InstallerUrl, is refused. A failed download names what to check for the source in use: the archive's delay, or the asset on the GitHub release.winget.ymlandchocolatey.ymlget aninstaller_sourcechoice input for manual runs, passed throughenv:. A release run has no inputs and keeps the archive.The Chocolatey package description no longer says that the installer comes from the Apache archive.
doc/ReleaseManagement.md, Windows Packages: an installer the vote did not cover is no longer added todist/releaseafter the release. Instead:installer_sourceset togithub;The step that overwrites the asset with the signed file from
dist/releasenow applies only when the vote covered the installer. The Chocolatey and WinGet sections point to this section.build/windows/README.mdand two comments inwindows-packages.ymlsay the same.Verification
test-winget-manifests.ps1andtest-chocolatey-package.ps1: 23 checks each pass with pwsh 7.6, against 20 on master. On the unmodified builders the new checks fail. The suite stops at the GitHub URL check with "A parameter cannot be found that matches parameter name 'InstallerSource'", and that message matches neither refusal check.thrift-0.25.0.exe; see the ticket.build-winget-manifests.ps1 -Version 0.25.0 -InstallerSource github -ReleaseDate 2026-09-30downloads the asset and writesInstallerUrl: https://github.com/apache/thrift/releases/download/v0.25.0/thrift-0.25.0-setup.exewithInstallerSha256: 'C94286CB…FD666'.validate_manifests.pyaccepts all three manifests.build-chocolatey-package.ps1 -Version 0.25.0 -InstallerSource github -StageOnlywrites the same URL and checksum intochocolateyinstall.ps1.--persona regular, with a token) reports no findings, with the same single suppressed finding as on master.archivearchiveinstaller_source=archivearchiveinstaller_source=githubgithubAfter this is merged, 0.25.0 needs one manual run of each workflow with
installer_sourceset togithub. The WinGet run also needs the release date 2026-09-30.🤖 Generated with Claude Code