Skip to content

Fix release CI payload isolation, ConPTY starvation, and signed NuGet payloads - #49

Merged
Marc-André Moreau (mamoreau-devolutions) merged 4 commits into
masterfrom
copilot/release-ci-repair
Sep 30, 2026
Merged

Marc-André Moreau (mamoreau-devolutions) merged 4 commits into
masterfrom
copilot/release-ci-repair

Conversation

@mamoreau-devolutions

Copy link
Copy Markdown
Contributor

Problem

The release workflow kept failing in the same two places across several attempted fixes:

  1. Release payload isolation — packaging jobs picked up cross-RID/unsigned artifacts, so packages were assembled from the wrong or unverified payloads.
  2. ConPTY worker starvation — the connection path could starve its worker and blow past deadlines, producing intermittent hangs/timeouts in CI.

While verifying the fix, a third issue surfaced: release NuGet packages shipped unsigned native payloads even though the MSI/macOS signing jobs had produced signed binaries.

Changes

  • Isolate release payloads per RID and remove the silent unsigned fallback; NuGet publication is now gated on the signing jobs for release events.
  • Fix ConPTY worker scheduling so connection deadlines are met (regression tests in ConPtySchedulingTests).
  • Release NuGets now consume the signed native payloads: MSI-verified Windows binaries and standalone Developer ID–signed macOS code, with entitlements/runtime/team/timestamp guards.
  • Added Test-WindowsPayloadSignatures.ps1 plus regression coverage, and native macOS NuGet signature/layout gates that inspect the actual .nupkg contents.
  • Flat NuGet layout preserved; debug symbols (.pdb/.dbg/.dSYM) excluded.

Validation

  • Full branch CI green at 422a6f9, including both native macOS NuGet signature jobs.
  • Downloaded the run's NuGet artifacts, verified digests, layout (11-file flat macOS contract), symbol exclusion, and all 7 consumer restores/builds.
  • Windows signature enforcement passes with real production-signed MSI bytes and rejects the previously shipped unsigned payloads.

Follow-up

This run was credential-free. A prod signed dry run is still needed to exercise the protected signing path end to end.

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

Exclude Windows ConPTY hosts at the final Unix publish boundary, validate nested macOS code, and exercise the release signer on both actual NativeAOT bundles in ordinary CI without credentials. Preserve uploaded payloads and checksums.

Use cancellable asynchronous host-side pipes and registered process-exit waits so idle sessions and blocked input cannot exhaust the worker pool. Add an isolated constrained-worker regression verified to fail against the old implementation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Route NuGet packaging through the Windows MSI signing layouts and standalone Developer ID-signed macOS payloads. Preserve the flat runtime contract by signing macOS native code outside the app bundle with runtime entitlements. Gate publication on signatures verified from actual restored/extracted nupkgs; fail instead of falling back to unsigned release code.

Keep ordinary CI and unsigned dry runs credential-free, exclude native debug symbols, and validate both Windows signature failures and macOS standalone layout behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
macOS26 system tools are universal x86_64/arm64e, not arm64. Compile the tiny fixture for the actual test RID instead of accepting the wrong architecture or weakening payload validation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Recent codesign versions default to a human-readable dictionary dump. Ask for XML explicitly so the native NuGet signature gate can validate required entitlements without loosening its assertions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) merged commit e617dcd into master Sep 30, 2026
27 checks passed
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) deleted the copilot/release-ci-repair branch September 30, 2026 20:16

This branch was successfully deployed

1 active deployment
publish-dry-run — 422a6f92 Deployed Sep 30, 2026 by mamoreau-devolutions via MSI packages #294
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant