chore: release v0.6.42 — ship pipeline auto-commit - #627
Merged
Merged
Conversation
…the zip lacks The v0.6.41 WinGet submission was rejected by Microsoft's validation (microsoft/winget-pkgs#437613, Manifest-Validation-Error). Root cause: uffs-products commit 2997eee7 (2026-09-07, shipped as demo v0.1.17) hyphenated the `uffs_tui` / `uffs_gui` binaries, and its CHANGELOG records that the published asset names moved with them (`uffs_tui-demo-…` -> `uffs-tui-demo-…`). This repository was never updated, so `release.yml` kept asking for the underscore name. Nothing failed loudly, by design: the demo fetch is deliberately non-fatal so a demo-repo hiccup cannot block an engine release. The download simply started missing, and v0.6.41 shipped a zip with no `uffs-tui.exe`. The damage surfaced one step later, when the alias seeder declared `uffs-tui.exe` as a NestedInstallerFile anyway and winget rejected a manifest referencing a file that was not in the archive. The duplicate `uffs-mft.exe -> uffs-tui` entry in that manifest was the same fault seen from the other side. Two fixes, because the rename alone would only postpone the next occurrence: - `release.yml` asks for the hyphenated asset, so the demo is bundled again from the next release onward. - `winget_seed_aliases.sh` now verifies each canonical alias against the actual archive before seeding it, which is the HARD PRECONDITION `packaging/winget/nested-aliases.yaml` already documented but nothing enforced. An absent binary is skipped with a warning pointing at the bundling step instead of producing an invalid manifest. Verified against the real v0.6.41 archive: it skips `uffs-tui` and seeds nothing else. Degradable — if the archive cannot be fetched it warns and behaves as before rather than blocking a submission. The 0.6.41 manifest itself was corrected in place on the submission branch; its zip genuinely lacks the binary, so six entries now match the archive exactly. Also corrects the user manual, which told readers to run `uffs_tui`. The CHANGELOG keeps its historical spelling, and the uninstaller keeps the underscore names on purpose so it can still clean up old installs.
libc 0.2.189 -> 0.2.190, rand 0.10.2 -> 0.10.3, rmcp 3.4.0 -> 3.5.0, smallvec 1.16.1 -> 1.16.2, thiserror 2.0.20 -> 2.0.21. Every delta is audited from the real diff, not waved through. The notes in supply-chain/audits.toml say what was read: libc's full build.rs rewrite (a typed Cfg enum with a new validate_cfg that asserts each cfg only lands on its own platform) and a scan of all 9820 added lines for link/include/env/transmute tricks; rand's three fix hunks (unwrap -> Error::Overflow, a mask-polarity fix, indexing -> get); rmcp's duplicate-header rejection, header-validation tests and serde_json::Number float decoding; smallvec's panic-safe retain rewrite block by block. thiserror was covered by a fresh upstream import. Held, with reasons that still stand: zerocopy (0.8.59 does not carry the empty_enums fix; google/zerocopy#3414 and #3600 still open — #617), reqwest 0.13 (documented hold, polars-io still on 0.12), and zstd 0.14 (polars-arrow and polars-parquet pin ^0.13, so a bump would ship two zstd stacks; it also relicenses to BSD-3-Clause). cargo deny: advisories, bans, licenses, sources all ok. cargo-machete: no unused dependencies.
`cargo deny check bans` warned unmatched-skip-root on `signal-hook@0.3`, kept "because crossterm pins to 0.3.x". It no longer does: the only signal-hook in the graph is 0.4.4 via polars-error, and crossterm 0.29 (via comfy-table) pins nothing older. A skip entry that matches nothing is config drift, and the comment beside it was false. The base64 and hashbrown duplicate warnings are pre-existing transitive splits (hyper-util vs rmcp; polars) and are left as the warnings they already were.
codeql-action init and analyze 4.37.9 -> 4.38.1, release-plz/action 0.5.132 -> 0.5.138, codecov/codecov-action v6 -> v7.1.1. Supersedes dependabot PR #625. codecov v7.0.0's only changes are a GPG signing-account move and the removal of its own license workflow; the `files`, `slug` and `token` inputs tier-2.yml uses are unchanged. The cross-workflow consistency gate confirms one SHA per action.
`uffs --help` documents `--benchmark` as "Measure only, skip output", and the profile summary already treats it like `--profile`. But the stdout-suppression check honoured only `--no-output`, so a benchmark against a wide query printed every matching row and the timing line scrolled straight off the terminal. The decision moves into a pure `should_suppress_stdout` helper so it is unit-testable without a daemon, with a regression test covering both flags, flag position, a plain search, `--profile` alone, and a value that merely contains the flag text. Reported with a one-line fix in #626; landed here as a signed commit because main requires signed commits and first-contributor CI does not run without approval. Co-authored-by: GanizaniSitara <7934938+GanizaniSitara@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
just shipPhase 2 auto-commit for v0.6.42 — the[workspace.package].versionbump inCargo.toml. This PR routes that commit through branch-protection rules. Once it merges tomain, runjust release-tagto cut the signedv0.6.42tag, which firesrelease.ymland builds the cross-platform binaries + GitHub Release v0.6.42. (No auto-tag on merge — the tag step is manual on-demand, Path B.)Auto-merge
--auto --squashis queued — GitHub will merge as soon as the required status checks pass. Squash is required becausemain-protectionmandates signed commits, and GitHub's rebase-auto-merge cannot sign the rebased commit; the squash-merge commit is signed by GitHub's own key, which satisfiesrequired_signatures: true. The original author's signed commit remains verifiable in the PR branch history.After merge
The auto-commit lived only on
release/v0.6.42, so localmainnever drifted — sync it with a plaingit pull --ff-only origin main(noreset --hardneeded).