From cd8205a7201b4a35e3c7bdff2806a24e891a3f90 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=A9vin=20Dunglas?= Date: Thu, 1 Oct 2026 11:48:55 +0200 Subject: [PATCH 1/4] ci: cache vcpkg binary packages in the Windows build SourceForge occasionally serves GitHub runners a body that fails the pthreads source hash check, breaking the Windows build. Restore built vcpkg packages from the Actions cache so sources are only downloaded when the runner image or manifest changes. --- .github/workflows/windows.yaml | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/.github/workflows/windows.yaml b/.github/workflows/windows.yaml index 804147612f..cabaf3da8d 100644 --- a/.github/workflows/windows.yaml +++ b/.github/workflows/windows.yaml @@ -80,9 +80,23 @@ jobs: with: working-directory: frankenphp + - name: Determine runner image + id: image + run: '"version=$env:ImageVersion" >> $env:GITHUB_OUTPUT' + + # SourceForge sometimes serves runners a non-archive body for pthreads sources + - name: Cache Vcpkg Packages + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: ${{ github.workspace }}\vcpkg-cache + key: vcpkg-${{ runner.os }}-${{ steps.image.outputs.version }}-${{ hashFiles('frankenphp/vcpkg.json') }} + restore-keys: vcpkg-${{ runner.os }}- + - name: Install Vcpkg Libraries working-directory: frankenphp - run: "vcpkg install" + run: | + New-Item -ItemType Directory -Force "$env:GITHUB_WORKSPACE\vcpkg-cache" | Out-Null + vcpkg install --binarysource="clear;files,$env:GITHUB_WORKSPACE\vcpkg-cache,readwrite" - name: Download Watcher run: | From abaf08d9fdac4fc2e7fe924b8ca529be731a77f3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=A9vin=20Dunglas?= Date: Thu, 1 Oct 2026 12:03:08 +0200 Subject: [PATCH 2/4] ci: use vcpkg's default binary cache and skip restore on tag builds Caching vcpkg's default archives directory removes the custom binary source. Tag builds publish release assets, so they skip the cache restore, matching setup-go and satisfying zizmor's cache-poisoning audit. --- .github/workflows/windows.yaml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/.github/workflows/windows.yaml b/.github/workflows/windows.yaml index cabaf3da8d..876780036d 100644 --- a/.github/workflows/windows.yaml +++ b/.github/workflows/windows.yaml @@ -88,15 +88,14 @@ jobs: - name: Cache Vcpkg Packages uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: - path: ${{ github.workspace }}\vcpkg-cache + path: ~\AppData\Local\vcpkg\archives key: vcpkg-${{ runner.os }}-${{ steps.image.outputs.version }}-${{ hashFiles('frankenphp/vcpkg.json') }} restore-keys: vcpkg-${{ runner.os }}- + lookup-only: ${{ startsWith(github.ref, 'refs/tags/') }} - name: Install Vcpkg Libraries working-directory: frankenphp - run: | - New-Item -ItemType Directory -Force "$env:GITHUB_WORKSPACE\vcpkg-cache" | Out-Null - vcpkg install --binarysource="clear;files,$env:GITHUB_WORKSPACE\vcpkg-cache,readwrite" + run: "vcpkg install" - name: Download Watcher run: | From cc4947bd4c81935ebac1d116016044197829730d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=A9vin=20Dunglas?= Date: Thu, 1 Oct 2026 12:05:49 +0200 Subject: [PATCH 3/4] ci: skip Go and vcpkg caches on every Windows release run Scheduled and versioned workflow_dispatch runs upload release assets too, not only tag pushes. Gate both caches on REF, which is set for all three. zizmor only recognizes the tag-ref expression, so its cache-poisoning finding is ignored on the vcpkg step. --- .github/actions/setup-go/action.yaml | 6 +++++- .github/workflows/windows.yaml | 7 ++++--- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/.github/actions/setup-go/action.yaml b/.github/actions/setup-go/action.yaml index a6541bffc2..1c1026b3d8 100644 --- a/.github/actions/setup-go/action.yaml +++ b/.github/actions/setup-go/action.yaml @@ -5,6 +5,10 @@ inputs: description: Path prefix for go.mod / go.sum files (used when the repo is checked out into a subdirectory) required: false default: "." + cache: + description: Whether to cache Go modules and build outputs + required: false + default: "true" runs: using: composite steps: @@ -14,5 +18,5 @@ runs: cache-dependency-path: | ${{ inputs.working-directory }}/go.sum ${{ inputs.working-directory }}/caddy/go.sum - cache: ${{ !startsWith(github.ref, 'refs/tags/') }} + cache: ${{ inputs.cache == 'true' && !startsWith(github.ref, 'refs/tags/') }} check-latest: true diff --git a/.github/workflows/windows.yaml b/.github/workflows/windows.yaml index 876780036d..6b31919fca 100644 --- a/.github/workflows/windows.yaml +++ b/.github/workflows/windows.yaml @@ -79,19 +79,20 @@ jobs: uses: ./frankenphp/.github/actions/setup-go with: working-directory: frankenphp + cache: ${{ !env.REF }} - name: Determine runner image id: image run: '"version=$env:ImageVersion" >> $env:GITHUB_OUTPUT' - # SourceForge sometimes serves runners a non-archive body for pthreads sources - - name: Cache Vcpkg Packages + # SourceForge sometimes serves runners a non-archive body for pthreads sources; release runs skip the cache + - name: Cache Vcpkg Packages # zizmor: ignore[cache-poisoning] + if: ${{ !env.REF }} uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ~\AppData\Local\vcpkg\archives key: vcpkg-${{ runner.os }}-${{ steps.image.outputs.version }}-${{ hashFiles('frankenphp/vcpkg.json') }} restore-keys: vcpkg-${{ runner.os }}- - lookup-only: ${{ startsWith(github.ref, 'refs/tags/') }} - name: Install Vcpkg Libraries working-directory: frankenphp From 8335018255c0de31bf45b2704e013d3a16208eba Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=A9vin=20Dunglas?= Date: Thu, 1 Oct 2026 12:47:34 +0200 Subject: [PATCH 4/4] ci: skip the Go cache on every release build Scheduled static builds publish release binaries without a tag ref, and the release workflow commits a PGO profile built on the runner. Disable the Go cache for both, as already done for the Windows build. --- .github/workflows/release.yaml | 2 ++ .github/workflows/static.yaml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index e0d0d1dbf5..3ea099d2ff 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -157,6 +157,8 @@ jobs: fi - if: steps.state.outputs.resume != 'true' uses: ./.github/actions/setup-go + with: + cache: "false" - if: steps.state.outputs.resume != 'true' uses: ./.github/actions/setup-php - if: steps.state.outputs.resume != 'true' diff --git a/.github/workflows/static.yaml b/.github/workflows/static.yaml index 29d5452dbd..f8f229460f 100644 --- a/.github/workflows/static.yaml +++ b/.github/workflows/static.yaml @@ -447,6 +447,8 @@ jobs: ref: ${{ needs.prepare.outputs.ref }} persist-credentials: false - uses: ./.github/actions/setup-go + with: + cache: ${{ !(needs.prepare.outputs.ref || github.ref_type == 'tag') }} - id: version uses: ./.github/actions/version with: