mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
yesterday 91fcddb2d3bc7be859d60c062089ed947f480dd1
.github/workflows/deploy.yml
@@ -76,10 +76,17 @@
      #
      # This only works because the Makefile passes /Brepro to both cl and link: the output
      # is a function of the sources, not of the build time. Without it every run would
      # produce different bytes and this would commit on every push. An MSVC toolchain bump
      # on the runner image does change them, and that refresh commit is correct - the
      # committed binary then matches what CI verifies. Pushes made with GITHUB_TOKEN do
      # not start new workflow runs, so this cannot loop; a PAT would break that.
      # produce different bytes and this would commit on every push. The inputs it hashes
      # include the build numbers of the tools, though, so a Visual Studio patch release
      # on the runner image changes the stamp of the files - Rich header, REPRO hash,
      # timestamps, checksum, header padding - while the code comes out the same. GitHub
      # rolls a new image out over days, and while old and new both serve windows-latest
      # the launchers were refreshed back and forth on every push (a8a18f000d, then
      # c6919eaaf4, which undid it). refresh-launchers.sh compares the files with that
      # stamp left out (same-pe-code.py), so only a change of the code, data or resources
      # is committed - from a source change or from a toolchain that really generates
      # different code. Pushes made with GITHUB_TOKEN do not start new workflow runs, so
      # this cannot loop; a PAT would break that.
      - name: Download the launchers built by the triggering Build run
        continue-on-error: true
        uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
@@ -103,7 +110,13 @@
            echo "::warning title=No launcher binaries from the Build run::windows-exe-11 could not be downloaded, leaving opendj-server-legacy/lib/*.exe as committed."
            exit 0
          fi
          cp "$BUILT"/*.exe opendj-server-legacy/lib/
          # A checked-out branch that predates the script (sustaining/4.10.x, say) takes
          # the rebuilt files as they are, which is the old behaviour.
          if [ -f .github/scripts/refresh-launchers.sh ]; then
            bash .github/scripts/refresh-launchers.sh "$BUILT" opendj-server-legacy/lib
          else
            cp "$BUILT"/*.exe opendj-server-legacy/lib/
          fi
          # status --porcelain, not diff: it reports a brand-new launcher that was never
          # git-added just as well as a modified one.
          if [ -z "$(git status --porcelain -- opendj-server-legacy/lib)" ]; then