Repository navigation
ci: cache vcpkg binary packages in the Windows build - #2683
Merged
Merged
Conversation
SourceForge occasionally serves GitHub runners a body that fails the pthreads source hash check, breaking the Windows build. Restore built vcpkg packages from the Actions cache so sources are only downloaded when the runner image or manifest changes.
Caching vcpkg's default archives directory removes the custom binary source. Tag builds publish release assets, so they skip the cache restore, matching setup-go and satisfying zizmor's cache-poisoning audit.
Scheduled and versioned workflow_dispatch runs upload release assets too, not only tag pushes. Gate both caches on REF, which is set for all three. zizmor only recognizes the tag-ref expression, so its cache-poisoning finding is ignored on the vcpkg step.
Scheduled static builds publish release binaries without a tag ref, and the release workflow commits a PGO profile built on the runner. Disable the Go cache for both, as already done for the Windows build.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Windows build failed on main because vcpkg's download of the
pthreadssources from SourceForge failed its hash check on every mirror (https://github.com/php/frankenphp/actions/runs/36826386435). The same file downloads with the correct hash outside GitHub Actions, so SourceForge is likely serving runners something other than the archive.This PR saves vcpkg's built packages in the Actions cache. The cache key includes the runner image version and
vcpkg.json. Sources are now downloaded only when the runner image or the manifest changes a package's hash, instead of on every run.Release runs (tag pushes, scheduled builds, and versioned
workflow_dispatchruns) now skip both the vcpkg and Go caches, so published binaries never come from restored cache entries. The same applies to the static macOS build and the release workflow.