Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
53 changes: 42 additions & 11 deletions .github/workflows/winget-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,13 +32,23 @@
#
# ── Required secret ──────────────────────────────────────────────────
# `WINGET_TOKEN` — a **classic** Personal Access Token with the
# `public_repo` scope (fine-grained tokens that can fork + push to
# microsoft/winget-pkgs also work). The default `GITHUB_TOKEN` CANNOT
# `public_repo` AND `workflow` scopes. The default `GITHUB_TOKEN` CANNOT
# be used: it has no permission to fork an external repo or push the
# manifest branch. Create it under the maintainer account that owns the
# winget-pkgs fork (the same account that hand-submitted PR
# microsoft/winget-pkgs#378294 for v0.5.102), then add it at
# Settings → Secrets and variables → Actions → New repository secret.
#
# Why `workflow` too (field failure 2026-10-03, v0.6.43): the fork sync
# below fast-forwards githubrobbi/winget-pkgs over whatever upstream
# merged since the last release. Whenever that span touches a file
# under `.github/workflows/` — which microsoft/winget-pkgs does every
# few weeks — GitHub rejects the fast-forward for a PAT without the
# `workflow` scope ("refusing to allow a Personal Access Token to
# create or update workflow"). The fork then stays stale and komac
# fails with the misleading `CreateRef` permissions error. A classic
# PAT's scopes can be edited in place at https://github.com/settings/tokens
# (no rotation needed).

name: 📦 WinGet Publish

Expand Down Expand Up @@ -122,13 +132,19 @@ jobs:
# winget-pkgs moves constantly and nothing else ever pushes to the
# fork. Syncing here makes the submission self-healing.
#
# `continue-on-error`: a sync hiccup must not block the submission —
# if the fork happens to be current, komac proceeds fine regardless.
# The `||` fallback keeps the step green while still surfacing the
# reason in the log.
# Second field failure 2026-10-03 (v0.6.43): the sync itself was
# refused — upstream had merged a `.github/workflows/` change and
# GitHub will not let a PAT without the `workflow` scope fast-forward
# over it. The step was `continue-on-error` with a `||` warning, so
# the refusal scrolled past as a warning, the fork stayed 81 commits
# behind, and komac failed with the same misleading `CreateRef`
# message as in August. This step therefore FAILS HARD now, with
# the real cause, whenever the fork is not at upstream's HEAD after
# the sync: komac cannot succeed from a stale base, so letting it
# try only buries the diagnosis. A fork that was already current
# never reaches the sync call.
- name: Sync winget-pkgs fork with upstream
if: steps.token.outputs.present == 'true'
continue-on-error: true
env:
GH_TOKEN: ${{ secrets.WINGET_TOKEN }}
FORK_USER: githubrobbi
Expand All @@ -137,16 +153,31 @@ jobs:
set -uo pipefail
before="$(gh api "repos/${FORK_USER}/winget-pkgs/commits/master" --jq .sha 2>/dev/null || echo unknown)"
upstream="$(gh api repos/microsoft/winget-pkgs/commits/master --jq .sha 2>/dev/null || echo unknown)"
if [[ "$before" == "$upstream" && "$before" != unknown ]]; then
if [[ "$upstream" == unknown ]]; then
echo "::error title=Fork sync failed::Cannot read microsoft/winget-pkgs master with WINGET_TOKEN."
exit 1
fi
if [[ "$before" == "$upstream" ]]; then
echo "Fork already in sync at ${before}."
exit 0
fi
echo "Fork ${before} behind upstream ${upstream} — fast-forwarding."
gh api -X POST "repos/${FORK_USER}/winget-pkgs/merge-upstream" \
-f branch=master --jq '.message' \
|| echo "::warning title=Fork sync failed::Could not fast-forward ${FORK_USER}/winget-pkgs; komac may fail to create its manifest branch."
if ! sync_out="$(gh api -X POST "repos/${FORK_USER}/winget-pkgs/merge-upstream" -f branch=master 2>&1)"; then
echo "$sync_out"
if grep -q "refusing to allow a Personal Access Token to create or update workflow" <<<"$sync_out"; then
echo "::error title=WINGET_TOKEN lacks the workflow scope::Upstream winget-pkgs changed a .github/workflows file and GitHub refuses to fast-forward the fork with a PAT that lacks the \`workflow\` scope. Fix: edit the classic PAT at https://github.com/settings/tokens to add \`workflow\` (no rotation needed), or sync once by hand with a token that has it: gh api -X POST repos/${FORK_USER}/winget-pkgs/merge-upstream -f branch=master — then re-run this workflow for ${{ inputs.release-tag }}."
else
echo "::error title=Fork sync failed::Could not fast-forward ${FORK_USER}/winget-pkgs (see output above). komac cannot cut its manifest branch from a stale fork, so the submission stops here."
fi
exit 1
fi
echo "$sync_out" | jq -r '.message' 2>/dev/null || echo "$sync_out"
after="$(gh api "repos/${FORK_USER}/winget-pkgs/commits/master" --jq .sha 2>/dev/null || echo unknown)"
echo "Fork now at ${after} (upstream ${upstream})."
if [[ "$after" != "$upstream" ]]; then
echo "::error title=Fork still behind upstream::${FORK_USER}/winget-pkgs is at ${after}, upstream is ${upstream}. komac would fail with a misleading CreateRef permissions error; sync the fork and re-run."
exit 1
fi

- name: Submit manifest to winget-pkgs
if: steps.token.outputs.present == 'true'
Expand Down
28 changes: 23 additions & 5 deletions .github/workflows/winget-token-expiry-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
# ─────────────────────────────────────────────────────────────────────────────
# winget-token-expiry-check — weekly heads-up before WINGET_TOKEN dies.
#
# `winget-publish.yml` needs a classic PAT (`WINGET_TOKEN`, `public_repo`
# `winget-publish.yml` needs a classic PAT (`WINGET_TOKEN`, `public_repo` + `workflow`
# scope) to fork + push to microsoft/winget-pkgs. When that PAT expires
# the release-triggered WinGet submission fails — and because it runs on
# the `release: released` event (not the PR path), nobody sees the red X
Expand Down Expand Up @@ -174,9 +174,27 @@ jobs:
|| fail "cannot read microsoft/winget-pkgs master"
[[ -n "${upstream:-}" ]] || fail "upstream master SHA came back empty"

# Scope check (field failure 2026-10-03, v0.6.43): the fork sync
# is refused outright whenever upstream's pending commits touch
# `.github/workflows/` and the PAT lacks the `workflow` scope —
# a condition that comes and goes with upstream's activity, so
# the sync-then-branch probe below can pass one week and the
# release fail the next. Reading the scopes is deterministic.
scopes="$(gh api -i user 2>/dev/null | grep -i '^x-oauth-scopes:' | cut -d: -f2- | tr -d ' \r')"
if [[ -n "$scopes" ]] && ! grep -qw workflow <<<"$scopes"; then
fail "WINGET_TOKEN lacks the workflow scope (has: ${scopes}); the fork sync is refused whenever microsoft/winget-pkgs changes a workflow file. Edit the classic PAT at https://github.com/settings/tokens to add workflow."
fi

# Fast-forward the fork, mirroring what the publish workflow does.
gh api -X POST "repos/${FORK_USER}/winget-pkgs/merge-upstream" \
-f branch=master >/dev/null 2>&1 || true
if ! sync_out="$(gh api -X POST "repos/${FORK_USER}/winget-pkgs/merge-upstream" -f branch=master 2>&1)"; then
if grep -q "refusing to allow a Personal Access Token to create or update workflow" <<<"$sync_out"; then
fail "fork sync refused: WINGET_TOKEN lacks the workflow scope and upstream has pending workflow changes"
fi
fail "fork sync failed: ${sync_out}"
fi
fork_head="$(gh api "repos/${FORK_USER}/winget-pkgs/commits/master" --jq .sha 2>/dev/null || true)"
[[ "$fork_head" == "$upstream" ]] \
|| fail "fork still behind after sync (fork ${fork_head:-?}, upstream ${upstream})"

# The real test: create the kind of ref komac creates, then remove
# it. A unique name keeps concurrent runs from colliding.
Expand Down Expand Up @@ -277,11 +295,11 @@ jobs:
`Check, in this order, before assuming the token is at fault:`,
`1. Does the fork \`githubrobbi/winget-pkgs\` still exist and is it writable?`,
`2. Is it far behind \`microsoft/winget-pkgs\`? (Publishing self-heals this, but a failing sync will not.)`,
`3. Only then suspect the token — and note the action requires a **classic** PAT; fine-grained PATs are unsupported and cannot open the cross-fork PR.`,
`3. Only then suspect the token — and note the action requires a **classic** PAT with the \`public_repo\` **and** \`workflow\` scopes; without \`workflow\` the fork sync is refused whenever upstream touched a workflow file, and fine-grained PATs are unsupported (they cannot open the cross-fork PR).`,
``,
] : []),
`### How to rotate`,
`1. Create a new **classic** PAT at https://github.com/settings/tokens — scope \`public_repo\` only, ~1-year expiry.`,
`1. Create a new **classic** PAT at https://github.com/settings/tokens — scopes \`public_repo\` + \`workflow\`, ~1-year expiry.`,
`2. \`gh secret set WINGET_TOKEN --repo ${owner}/${repo}\` and paste it.`,
`3. Run the **🔑 WinGet Token Expiry Check** workflow manually (\`workflow_dispatch\`) to confirm healthy — it will auto-close this issue.`,
``,
Expand Down
19 changes: 18 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,22 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.6.44] - 2026-10-03

### Added

- cli: make --benchmark measure output production; -v shows the rows

### Changed

- daemon: never force a tier change on memory pressure

### Fixed

- client: report the client's own deadline as Timeout, never as a warm-up retry
- daemon: surface search timeouts as errors and cancel the orphaned scan
- daemon: log the per-tick USN refresh at debug, not info

## [0.6.43] - 2026-10-03

### Added
Expand Down Expand Up @@ -2880,7 +2896,8 @@ thin clients over a unified `uffsd` process.
### Fixed
- Various MFT parsing edge cases

[Unreleased]: https://github.com/skyllc-ai/UltraFastFileSearch/compare/v0.6.43...HEAD
[Unreleased]: https://github.com/skyllc-ai/UltraFastFileSearch/compare/v0.6.44...HEAD
[0.6.44]: https://github.com/skyllc-ai/UltraFastFileSearch/compare/v0.6.43...v0.6.44
[0.6.43]: https://github.com/skyllc-ai/UltraFastFileSearch/compare/v0.6.42...v0.6.43
[0.6.42]: https://github.com/skyllc-ai/UltraFastFileSearch/compare/v0.6.41...v0.6.42
[0.6.41]: https://github.com/skyllc-ai/UltraFastFileSearch/compare/v0.6.40...v0.6.41
Expand Down
52 changes: 26 additions & 26 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading