From 91fcddb2d3bc7be859d60c062089ed947f480dd1 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Sun, 27 Sep 2026 08:55:51 +0000
Subject: [PATCH] Refresh the Windows launchers only when their code changes, not their toolchain stamp (#1103)

---
 .github/workflows/deploy.yml |   23 ++++++++++++++++++-----
 1 files changed, 18 insertions(+), 5 deletions(-)

diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml
index f1baf9d..6d4b5bb 100644
--- a/.github/workflows/deploy.yml
+++ b/.github/workflows/deploy.yml
@@ -76,10 +76,17 @@
       #
       # This only works because the Makefile passes /Brepro to both cl and link: the output
       # is a function of the sources, not of the build time. Without it every run would
-      # produce different bytes and this would commit on every push. An MSVC toolchain bump
-      # on the runner image does change them, and that refresh commit is correct - the
-      # committed binary then matches what CI verifies. Pushes made with GITHUB_TOKEN do
-      # not start new workflow runs, so this cannot loop; a PAT would break that.
+      # produce different bytes and this would commit on every push. The inputs it hashes
+      # include the build numbers of the tools, though, so a Visual Studio patch release
+      # on the runner image changes the stamp of the files - Rich header, REPRO hash,
+      # timestamps, checksum, header padding - while the code comes out the same. GitHub
+      # rolls a new image out over days, and while old and new both serve windows-latest
+      # the launchers were refreshed back and forth on every push (a8a18f000d, then
+      # c6919eaaf4, which undid it). refresh-launchers.sh compares the files with that
+      # stamp left out (same-pe-code.py), so only a change of the code, data or resources
+      # is committed - from a source change or from a toolchain that really generates
+      # different code. Pushes made with GITHUB_TOKEN do not start new workflow runs, so
+      # this cannot loop; a PAT would break that.
       - name: Download the launchers built by the triggering Build run
         continue-on-error: true
         uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
@@ -103,7 +110,13 @@
             echo "::warning title=No launcher binaries from the Build run::windows-exe-11 could not be downloaded, leaving opendj-server-legacy/lib/*.exe as committed."
             exit 0
           fi
-          cp "$BUILT"/*.exe opendj-server-legacy/lib/
+          # A checked-out branch that predates the script (sustaining/4.10.x, say) takes
+          # the rebuilt files as they are, which is the old behaviour.
+          if [ -f .github/scripts/refresh-launchers.sh ]; then
+            bash .github/scripts/refresh-launchers.sh "$BUILT" opendj-server-legacy/lib
+          else
+            cp "$BUILT"/*.exe opendj-server-legacy/lib/
+          fi
           # status --porcelain, not diff: it reports a brand-new launcher that was never
           # git-added just as well as a modified one.
           if [ -z "$(git status --porcelain -- opendj-server-legacy/lib)" ]; then

--
Gitblit v1.10.0