Skip to content

ci: add reproducible Windows validation - #29

Merged
MarsSall merged 7 commits into
mainfrom
ci/windows-ci
Aug 21, 2026
Merged

MarsSall merged 7 commits into
mainfrom
ci/windows-ci

Conversation

@MarsSall

@MarsSall MarsSall commented Aug 20, 2026 •

Copy link
Copy Markdown
Owner

Closes #28

PR Type

  • Bug fix
  • New feature
  • Documentation only
  • Code refactoring
  • Maintenance/tooling
  • Breaking change

Summary

  • Adds reproducible Windows Server 2022 validation for .NET and YASB.
  • Pins the .NET SDK and Pester package with fail-closed integrity checks.
  • Hardens packaging recovery tests with a dedicated native process harness for timeout, cancellation, stream-drain, descendant-ownership, and cleanup scenarios.

Changes

File Change
.github/workflows/ci.yml Adds least-privilege .NET and YASB jobs with immutable action pins.
global.json Pins .NET SDK 8.0.408 with roll-forward disabled.
yasb/tests/read-aibar-quota.Tests.ps1 Migrates 11 scenarios to supported Pester 5 syntax.
tests/AIBar.Packaging.ProcessHarness/ Adds a built native apphost for deterministic child and descendant process scenarios.
tests/AIBar.Domain.Tests/PackagingRecoveryTests.cs Uses bounded asynchronous drains and identity-aware cleanup against the native harness.
AIBar.sln and test project Build the harness in normal Debug and Release solution configurations without linking it into the test assembly.

Test Plan

  • dotnet restore AIBar.sln --nologo
  • dotnet build AIBar.sln --no-restore --configuration Debug --nologo — 0 errors
  • PackagingRecoveryTests — 25/25 passed
  • Full .NET suite — 584/584 passed
  • Pester 5.7.1 YASB suite — 11/11 passed
  • Workflow parsed with PyYAML and passed security diagnostics
  • PowerShell AST parsed with exactly 11 It blocks
  • git diff --check
  • No attributable harness, testhost, vstest, or dotnet child process survived local verification

Security and Reproducibility

  • Workflow permissions are contents: read.
  • Checkout credentials are not persisted.
  • Actions are pinned to immutable commit SHAs.
  • Pester nupkg SHA-256 is verified before extraction/import.
  • Process cleanup requires identity evidence and preserves roots when ownership is incomplete.
  • No secrets, live services, private data, or real AIBar/YASB processes are used.
  • Failed test diagnostics are retained for seven days; successful runs upload nothing.

Contributor Checklist

  • Linked approved issue Add reproducible Windows CI and modernize YASB tests #28.
  • Exactly one PR type selected and type:chore applied.
  • Tests and workflow validated locally.
  • Documentation impact is contained in workflow names and commands.
  • Conventional commit format and GitHub noreply identity.
  • No Co-Authored-By trailers.

@MarsSall MarsSall added the type:chore Maintenance and test-only changes label Aug 20, 2026
@MarsSall
MarsSall merged commit a09c535 into main Aug 21, 2026
2 checks passed
@MarsSall
MarsSall deleted the ci/windows-ci branch August 21, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:chore Maintenance and test-only changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add reproducible Windows CI and modernize YASB tests

1 participant