Skip to content

chore: release v0.6.42 — ship pipeline auto-commit - #627

Merged
githubrobbi merged 6 commits into
mainfrom
release/v0.6.42
Oct 2, 2026
Merged

githubrobbi merged 6 commits into
mainfrom
release/v0.6.42

Conversation

@githubrobbi

Copy link
Copy Markdown
Collaborator

Summary

just ship Phase 2 auto-commit for v0.6.42 — the [workspace.package].version bump in Cargo.toml. This PR routes that commit through branch-protection rules. Once it merges to main, run just release-tag to cut the signed v0.6.42 tag, which fires release.yml and builds the cross-platform binaries + GitHub Release v0.6.42. (No auto-tag on merge — the tag step is manual on-demand, Path B.)

Auto-merge

--auto --squash is queued — GitHub will merge as soon as the required status checks pass. Squash is required because main-protection mandates signed commits, and GitHub's rebase-auto-merge cannot sign the rebased commit; the squash-merge commit is signed by GitHub's own key, which satisfies required_signatures: true. The original author's signed commit remains verifiable in the PR branch history.

After merge

The auto-commit lived only on release/v0.6.42, so local main never drifted — sync it with a plain git pull --ff-only origin main (no reset --hard needed).

githubrobbi and others added 6 commits September 19, 2026 07:56
…the zip lacks

The v0.6.41 WinGet submission was rejected by Microsoft's validation
(microsoft/winget-pkgs#437613, Manifest-Validation-Error).

Root cause: uffs-products commit 2997eee7 (2026-09-07, shipped as demo
v0.1.17) hyphenated the `uffs_tui` / `uffs_gui` binaries, and its
CHANGELOG records that the published asset names moved with them
(`uffs_tui-demo-…` -> `uffs-tui-demo-…`). This repository was never
updated, so `release.yml` kept asking for the underscore name.

Nothing failed loudly, by design: the demo fetch is deliberately
non-fatal so a demo-repo hiccup cannot block an engine release. The
download simply started missing, and v0.6.41 shipped a zip with no
`uffs-tui.exe`. The damage surfaced one step later, when the alias
seeder declared `uffs-tui.exe` as a NestedInstallerFile anyway and
winget rejected a manifest referencing a file that was not in the
archive. The duplicate `uffs-mft.exe -> uffs-tui` entry in that manifest
was the same fault seen from the other side.

Two fixes, because the rename alone would only postpone the next
occurrence:

- `release.yml` asks for the hyphenated asset, so the demo is bundled
  again from the next release onward.
- `winget_seed_aliases.sh` now verifies each canonical alias against the
  actual archive before seeding it, which is the HARD PRECONDITION
  `packaging/winget/nested-aliases.yaml` already documented but nothing
  enforced. An absent binary is skipped with a warning pointing at the
  bundling step instead of producing an invalid manifest. Verified
  against the real v0.6.41 archive: it skips `uffs-tui` and seeds
  nothing else. Degradable — if the archive cannot be fetched it warns
  and behaves as before rather than blocking a submission.

The 0.6.41 manifest itself was corrected in place on the submission
branch; its zip genuinely lacks the binary, so six entries now match the
archive exactly.

Also corrects the user manual, which told readers to run `uffs_tui`.
The CHANGELOG keeps its historical spelling, and the uninstaller keeps
the underscore names on purpose so it can still clean up old installs.
libc 0.2.189 -> 0.2.190, rand 0.10.2 -> 0.10.3, rmcp 3.4.0 -> 3.5.0,
smallvec 1.16.1 -> 1.16.2, thiserror 2.0.20 -> 2.0.21.

Every delta is audited from the real diff, not waved through. The notes
in supply-chain/audits.toml say what was read: libc's full build.rs
rewrite (a typed Cfg enum with a new validate_cfg that asserts each cfg
only lands on its own platform) and a scan of all 9820 added lines for
link/include/env/transmute tricks; rand's three fix hunks (unwrap ->
Error::Overflow, a mask-polarity fix, indexing -> get); rmcp's
duplicate-header rejection, header-validation tests and
serde_json::Number float decoding; smallvec's panic-safe retain rewrite
block by block. thiserror was covered by a fresh upstream import.

Held, with reasons that still stand: zerocopy (0.8.59 does not carry
the empty_enums fix; google/zerocopy#3414 and #3600 still open — #617),
reqwest 0.13 (documented hold, polars-io still on 0.12), and zstd 0.14
(polars-arrow and polars-parquet pin ^0.13, so a bump would ship two
zstd stacks; it also relicenses to BSD-3-Clause).

cargo deny: advisories, bans, licenses, sources all ok. cargo-machete:
no unused dependencies.
`cargo deny check bans` warned unmatched-skip-root on
`signal-hook@0.3`, kept "because crossterm pins to 0.3.x". It no longer
does: the only signal-hook in the graph is 0.4.4 via polars-error, and
crossterm 0.29 (via comfy-table) pins nothing older. A skip entry that
matches nothing is config drift, and the comment beside it was false.
The base64 and hashbrown duplicate warnings are pre-existing transitive
splits (hyper-util vs rmcp; polars) and are left as the warnings they
already were.
codeql-action init and analyze 4.37.9 -> 4.38.1, release-plz/action
0.5.132 -> 0.5.138, codecov/codecov-action v6 -> v7.1.1.

Supersedes dependabot PR #625. codecov v7.0.0's only changes are a GPG
signing-account move and the removal of its own license workflow; the
`files`, `slug` and `token` inputs tier-2.yml uses are unchanged. The
cross-workflow consistency gate confirms one SHA per action.
`uffs --help` documents `--benchmark` as "Measure only, skip output",
and the profile summary already treats it like `--profile`. But the
stdout-suppression check honoured only `--no-output`, so a benchmark
against a wide query printed every matching row and the timing line
scrolled straight off the terminal.

The decision moves into a pure `should_suppress_stdout` helper so it is
unit-testable without a daemon, with a regression test covering both
flags, flag position, a plain search, `--profile` alone, and a value
that merely contains the flag text.

Reported with a one-line fix in #626; landed here as a signed commit
because main requires signed commits and first-contributor CI does not
run without approval.

Co-authored-by: GanizaniSitara <7934938+GanizaniSitara@users.noreply.github.com>
@githubrobbi
githubrobbi enabled auto-merge October 2, 2026 22:48
@githubrobbi
githubrobbi added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit b8c9aab Oct 2, 2026
23 checks passed
@githubrobbi
githubrobbi deleted the release/v0.6.42 branch October 2, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant