Skip to content

fix(ci): preserve quoted Windows signing commands - #2918

Merged
openai0229 merged 2 commits into
mainfrom
fix/community-windows-signing-argv
Sep 16, 2026
Merged

openai0229 merged 2 commits into
mainfrom
fix/community-windows-signing-argv

Conversation

@openai0229

Copy link
Copy Markdown
Contributor

Related issue

N/A — maintainer-requested recovery of Community Windows Beta packaging.

Summary

Windows signing fails before SSH authentication because PowerShell native argument quoting makes WinSCP parse the session URL as a host named \scp. Pass the command batch through a UTF-8 BOM script file so URL, host-key and filesystem-path quotes reach WinSCP intact. Remove the temporary command file in finally, and retain the existing Authenticode validation before replacing the original installer.

Add regression coverage for MSI and EXE, escaped URL credentials, Unicode paths, failed transfers, invalid signatures, and temporary-file cleanup. Windows CI also runs the actual WinSCP client against a temporary loopback TCP listener to verify URL parsing without signing credentials or an external server.

Affected surfaces

  • Frontend / Web
  • Backend / API / Storage
  • Database plugin / Driver
  • JCEF / Desktop packaging
  • CI / Build / Release
  • Documentation only

Verification

  • Commands and results:
    • PowerShell 7.6.6: pwsh -NoLogo -NoProfile -File script/package/tests/windows-signing-test.ps1 passed locally. The test fails against the previous /command implementation.
    • Ruby YAML parsing of .github/workflows/ci.yml and git diff --check passed.
    • Actual native WinSCP parser coverage runs in the Windows CI job; its current result must be checked before merge.
  • Manual verification: Community Beta attempt 2, Windows job reproduced Host "\scp" does not exist after all six signing secrets were supplied. This patch does not claim a successful signed installer until the updated packaging workflow runs.
  • UI evidence: N/A — packaging script only.

Risk and compatibility

  • Public API or stored data: N/A — no product API or storage changes.
  • Database or driver compatibility: N/A.
  • Network, privacy, or security: preserve the pinned SSH host key, both signing passes, and Authenticode validation. The temporary command file contains connection credentials and is removed on success or failure; it is not added to logs or artifacts.
  • Community / Local / Pro boundary: Community packaging only.
  • Backward compatibility: preserve all six existing signing environment variables and the remote signer CLI. Failed transport/signature verification leaves the original local installer unchanged.

Reviewer map

  • Start here: script/package/sign_windows_package.ps1; then script/package/tests/windows-signing-test.ps1 and the Windows CI step.
  • Failure condition: transport errors and invalid Authenticode status remain fatal.
  • Rollback or disable path: revert this small patch. This changes the workflow helpers on main, so a new workflow dispatch is needed after merge; rerunning an older run would retain the old helper revision.

Contributor declaration

  • I linked the Issue that defines this change.
  • I tested the affected behavior and reported the actual results above.
  • I did not include credentials, private data, or generated build output.
  • I disclosed substantial AI assistance below, or this PR contains no substantial AI-generated code.

AI assistance: implementation and verification performed with Codex.

@openai0229
openai0229 merged commit 5fb214a into main Sep 16, 2026
17 of 19 checks passed
@openai0229
openai0229 deleted the fix/community-windows-signing-argv branch September 16, 2026 12:42
@openai0229 openai0229 moved this from In Review to Done in Chat2DB Community Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant