Skip to content

ci(packaging): install-test the Chocolatey package on a throwaway runner - #46

Merged
jpicklyk merged 2 commits into
mainfrom
feat/chocolatey-ci-verify
Sep 23, 2026
Merged

jpicklyk merged 2 commits into
mainfrom
feat/chocolatey-ci-verify

Conversation

@jpicklyk

Copy link
Copy Markdown
Owner

Summary

There's no local sandbox for the pre-push install test of the Chocolatey package, so this uses a fresh windows-latest runner as the sandbox: a throwaway VM with choco preinstalled and admin rights. This PR's own CI run is that test, against v0.13.3.

  • scripts/verify-chocolatey.ps1 runs five checks. Every check runs even after an earlier one fails; the script prints the full list of failures at the end:
    1. Install: exit 0; the app is at C:\Program Files\LogTapper\log-tapper.exe with logtapper-mcp.exe beside it; Add/Remove Programs shows LogTapper with publisher Jeff Picklyk and the right version; .lts and .ltw are registered.
    2. Reinstall over a running app with --force: exit 0, and the installer closes the app instead of stopping on it. If a headless runner won't keep the GUI running, the log says so as a warning rather than silently passing.
    3. Uninstall: exit 0; the app and its Add/Remove Programs entry are gone within 60 s; no leftover sidecar process. It also records whether files were still present when choco returned, which settles whether the NSIS uninstaller runs detached (the plan's open _?= question).
    4. Uninstall after the app was already removed by hand: choco uninstall exits 0 through the script's "nothing to uninstall" path.
    5. Tampered checksum: an install from a package with one checksum digit changed fails and installs nothing.
  • "Settings shows the normal update controls" needs no UI check. The unit test nsis_install_is_not_managed in src-tauri/src/commands/app_update.rs pins exactly C:/Program Files/LogTapper/log-tapper.exe as not package-managed, so check 1's install path covers it.
  • .github/workflows/verify-chocolatey.yml runs the script:
    • on PRs touching the package, the renderer, the script or the workflow;
    • on workflow_dispatch (defaults to the latest release);
    • via workflow_call.
      It renders with dummy DMG hashes (only the NSIS hash matters here), packs, tests, and uploads the tested .nupkg. There's a 30-minute timeout in case an installer dialog hangs, and it needs no secrets.
  • publish-packages.yml: a new chocolatey-verify job calls that workflow for the version being released, and the chocolatey push job now depends on it. A package that doesn't install, reinstall and uninstall cleanly never reaches moderation.

Test plan

  • Both workflows parse (js-yaml); every PowerShell block in them, plus the script and chocolateyuninstall.ps1, parses with the pwsh 7.6 AST parser (10 files, 0 errors)
  • The tamper regex, run against a real render: exactly one character of checksum64 changes, for both a leading 0 and a leading letter; the rest of the file is identical
  • This PR's Verify Chocolatey package run passes against v0.13.3. That run is the sandbox test for the first push.
  • After merge: gh workflow run publish-packages.yml -f version=0.13.3 pushes the first version, with chocolatey-verify running before it

🤖 Generated with Claude Code

jpicklyk and others added 2 commits September 23, 2026 09:51
There is no local sandbox for the pre-push install test, so a fresh
windows-latest runner (choco preinstalled, admin) stands in for one.

scripts/verify-chocolatey.ps1 installs the locally packed package and checks
the install path, the Add/Remove Programs entry, the .lts/.ltw associations
and the sidecar. It then reinstalls over a running app, uninstalls (recording
whether the NSIS uninstaller detaches), runs choco uninstall after a manual
uninstall, and confirms a tampered checksum aborts. The install path is also
the "Settings shows the normal update controls" check: app_update.rs's
nsis_install_is_not_managed pins exactly that path as unmanaged.

verify-chocolatey.yml runs it on packaging PRs, on dispatch, and as the
chocolatey-verify job that publish-packages' push now depends on. No API key.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rors

Get-UninstallRegistryKey returns $null when no key matches, and @($null) is a
one-element array, so the "nothing to uninstall" guard never fired. The loop
then passed an empty path to Uninstall-ChocolateyPackage, which threw
GetFullPath "The path is not of a legal form". This hit anyone who removed
LogTapper from Settings > Apps before running choco uninstall. Caught by
verify-chocolatey step 4 on its first CI run.

Also makes the tamper step independent of the earlier ones (--force), since a
failed uninstall left logtapper listed as installed and choco answered
"already installed" without reaching the checksum. It now also asserts the
failure mentions the checksum.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jpicklyk
jpicklyk merged commit 1d5964f into main Sep 23, 2026
1 check passed
@jpicklyk
jpicklyk deleted the feat/chocolatey-ci-verify branch September 25, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant