Repository navigation
fix(hidi): retain signed assembly in official tool package - #903
Open
Gavin Barron (gavinbarron) wants to merge 2 commits into
Open
Gavin Barron (gavinbarron) wants to merge 2 commits into
Gavin Barron (gavinbarron) wants to merge 2 commits into
Conversation
Replace the SDK tool publish input with the exact ESRP-signed staging assembly and verify payload provenance before NuGet signing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 61e122e7-9a38-4455-8cb1-343245120242
Use the workflow-provided token for the existing metadata GET to avoid shared runner anonymous API-rate-limit failures, without changing branch outputs, permissions or publishing conditions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 61e122e7-9a38-4455-8cb1-343245120242
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Root cause
Official publish-disabled build 248625 succeeded at DLL/exe and NuGet signing, but its packaged Hidi DLL was
NotSigned: SHA256802BF99693EC73418790E0FA1EAC5F730854355FAA4AE6E8A2C7F8597100E42Fexactly matched the pre-signing DLL. The SDK's no-build tool pack runs Publish, selectsIntermediateAssemblyfromobjintoResolvedFileToPublish, then packagesPublishDir. Overwritingbintherefore does not select the signed payload.Correction
HidiSignedAssemblyPathreplaces only the uniquely selected Hidi publish item afterComputeFilesToPublish, using the exact ESRP staging DLL andCopyToPublishDirectory=Always. Missing or ambiguous inputs fail closed; normal local/Docker builds remain unchanged.Validation
28b6c5136dfb133009122761a31df57e0779f836; Hidi 3.10.2 / OData 3.2.1 / core+YamlReader 3.10.2 unchanged.binoverlay ignored by normal pack; opt-in package DLL exactly matches synthetic staging SHA256, while originalobjstays unchanged. All other nupkg and snupkg entry bytes match; Hidi/OData portable PDBs retained.NotSigned; no claim of real local signing.--help, and ZIP/exe hash equality pass; opt-in target skipsPackAsTool=false.Readiness boundary
Normal review/merge only; no auto-merge, package/container publication, release-PR merge, or resource grants. This corrects packing but does not establish final signed-artifact readiness: the coordinator must run a fresh publish-disabled official build after normal merge and verify downloaded nupkg DLL signing/provenance, NuGet/exe signatures, ZIP bytes, symbols, and public-only Docker context. Support/v2 has a separate corrective PR.