Give the signed ARM64 smoke test the vendored manifest - #201
Merged
Merged
Conversation
The job asserted every installed binary carries our certificate. Two do not and must not: mfc140.dll and vcruntime140.dll stay signed by Microsoft, and runtime-vendored.txt is what names them. The job never downloaded it, so both read as wrongly signed and the first signing dispatch failed there. It downloads the ARM64 payload for that file now. It also skips the crash-report check, as the other two legs do, because an installed tree ships no PDBs. Found by running the job for the first time. Ordinary CI cannot reach it: it needs a tag or a dispatch asking to sign. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Xavier Roche <roche@httrack.com>
The comment opened with a fragment and then restated what the input's own description already says at its definition in smoke-test/action.yml. Only the reason this job needs its own copy is new here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Xavier Roche <roche@httrack.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The first signing dispatch failed in signed-runtime-arm64. The job asserted that every installed binary carries our certificate, but mfc140.dll and vcruntime140.dll stay signed by Microsoft. runtime-vendored.txt names them, and the job never downloaded it.
It downloads the ARM64 payload for that file now. It also skips the crash-report check, as the x64 and x86 legs do, because an installed tree ships no PDBs.
Ordinary CI cannot exercise this. The job needs a tag, or a dispatch asking to sign, so this PR going green says nothing about the fix. Verifying it costs one more set of signatures.
Run 36712976637 is where it failed. Signing itself worked there, and the other two legs passed.