fix(firewall): cache the Windows binary as sfw.exe so the shims can run it - #24
Draft
Julian Gruber (juliangruber) wants to merge 1 commit into
Draft
Julian Gruber (juliangruber) wants to merge 1 commit into
Julian Gruber (juliangruber) wants to merge 1 commit into
Conversation
…un it Since the shims landed (bad87d6, Aug 4) every Windows install through this action with the default `shims: true` has failed: the binary is cached as `.../sfw` with no suffix, and the `.cmd` shims run it through cmd.exe, which does not execute a suffix-less file ("is not recognized as an internal or external command"). Bash on a Windows runner does, so `sfw npm install` typed in a workflow started fine; it then resolved `npm` to the shim, and the shim failed. The CI simulation on main showed 0 of 10 installs succeeding on windows-2025 and windows-11-arm against 10 of 10 for the pre-shim v1.3.2 action. Cache the file under FIREWALL_EXEC_FILE, `sfw.exe` on Windows and `sfw` elsewhere, the way PATCH_EXEC_NAME already does, and point the binary path and therefore the shims at it. FIREWALL_EXEC_NAME stays the bare name the release asset names are built from.
Julian Gruber (juliangruber)
force-pushed
the
ci/simulation-results-via-annotations
branch
from
September 30, 2026 13:42
f706ec9 to
64040f1
Compare
Julian Gruber (juliangruber)
force-pushed
the
fix/windows-exe-binary
branch
from
September 30, 2026 13:42
4ba8fc2 to
fecefa2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Found by the first dispatch of the CI simulation on
main(run 36721798455): every Windows install through the current action failed, deterministically, while the pre-shimv1.3.2action passed.main)main)main)The install log:
The binary is cached as
sfwwith no suffix. The.cmdshims the action writes run it throughcmd.exe, which does not execute a suffix-less file, and neither does PowerShell. Bash on a Windows runner does, which is whysfw npm installtyped in a workflow started fine: it then resolvednpmto the shim, and the shim failed. So with the defaultshims: true, every Windows install viamainhas been broken since the shims landed inbad87d6on Aug 4. Nobody hit it because no release has been tagged since March and current customer pins predate the shims.What
Cache the file under
FIREWALL_EXEC_FILE,sfw.exeon Windows andsfwelsewhere, the wayPATCH_EXEC_NAMEalready does, and point the binary path (and therefore the shims) at it.FIREWALL_EXEC_NAMEstays the bare name the release asset names are built from. One unit test.dist/rebuilt.Stacked on #23 so that dispatching the simulation on this branch produces a report.
Verification
Run 36723011554, the simulation dispatched on this branch, 3 iterations per runner:
Windows goes from 0 of 10 on
mainto 3 of 3 here with only the file-name change.🤖 Generated with Claude Code