Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
5606131
Implemented the worker/UI completion refactor
mzagozda Aug 9, 2026
89680aa
Implemented atomic file-operation cancellation
mzagozda Aug 9, 2026
0d92539
Implemented transactional overwrite handling
mzagozda Aug 9, 2026
a28dd19
Implemented the durable copy commit boundary
mzagozda Aug 9, 2026
9e4f271
Implemented cross-volume move protection
mzagozda Aug 9, 2026
a8362e0
Implemented recoverable journaling for native multi-item operations
mzagozda Aug 9, 2026
74eefb5
Implemented file-identity revalidation
mzagozda Aug 9, 2026
797b723
Implemented the legacy file-size/seek modernization
mzagozda Aug 9, 2026
655b980
Implemented the HTTPS crash-uploader change
mzagozda Aug 9, 2026
c8e3008
Implemented crash-upload hardening and updated the transmission docum…
mzagozda Aug 9, 2026
da9df4e
Implemented the SChannel migration for FTP/FTPS
mzagozda Aug 9, 2026
93df44e
Implemented DLL search-path hardening
mzagozda Aug 9, 2026
69258bd
Implemented the initial out-of-process parser boundary
mzagozda Aug 9, 2026
228471f
Implemented plug-in entry safety
mzagozda Aug 9, 2026
44c6d07
Implemented plug-in callback failure containment
mzagozda Aug 9, 2026
adde861
Implemented transactional automatic configuration persistence
mzagozda Aug 9, 2026
c045380
Implemented configuration schema hardening
mzagozda Aug 9, 2026
625ce45
Implemented configuration crash-recovery coverage
mzagozda Aug 9, 2026
ad307a2
Implemented the planning seam
mzagozda Aug 9, 2026
047cee6
Implemented the native file-operation characterization coverage
mzagozda Aug 9, 2026
c0e7a7c
Implemented crash-consistency fault-injection seams
mzagozda Aug 9, 2026
61ce029
Added NTFS/ReFS/FAT/SMB metadata contract and loss tracking in the na…
mzagozda Aug 9, 2026
a9d8c35
Added executable-level ADS scenarios
mzagozda Aug 9, 2026
f369098
Implemented ACL/ownership privilege handling
mzagozda Aug 9, 2026
7221046
Exercise junction, symlink, mount-point, and cloud-placeholder cases
mzagozda Aug 9, 2026
20e5a6d
Implemented dynamic wide-path handling
mzagozda Aug 9, 2026
78bb326
Implemented dynamic wide-path handling
mzagozda Aug 9, 2026
d5cdcf6
Replace fixed buffers at trust boundaries first
mzagozda Aug 9, 2026
b7b0b26
Implemented checked arithmetic across the active upload and parser IP…
mzagozda Aug 9, 2026
55b105a
Implemented explicit operation results for durable copy verification …
mzagozda Aug 9, 2026
383fe89
Added scoped_kernel_handle.h, a non-copyable RAII owner that preserve…
mzagozda Aug 9, 2026
b4e97fa
Adopt RAII for memory, mappings, and critical sections
mzagozda Aug 9, 2026
d3352c1
Standardize thread creation and ownership
mzagozda Aug 10, 2026
03648f8
Define bounded shutdown deadlines without unsafe escalation
mzagozda Aug 10, 2026
6d73197
Implemented monotonic 64-bit plug-in filesystem timers
mzagozda Aug 10, 2026
17eaf47
Implemented: replace `Sleep` polling with signaled waits
mzagozda Aug 10, 2026
d6bc597
Document and verify lock ordering
mzagozda Aug 10, 2026
46fa8c1
Reduce unowned global mutable state
mzagozda Aug 10, 2026
7641a49
Protect window and callback lifetimes
mzagozda Aug 10, 2026
d3b3689
Bound background work queues
mzagozda Aug 10, 2026
77c4ec3
Set resource budgets for directory enumeration
mzagozda Aug 10, 2026
1fc21ce
Reserve memory for graceful out-of-memory handling
mzagozda Aug 10, 2026
744516a
Remove modal UI and retry loops from the global allocation handler
mzagozda Aug 10, 2026
2916edb
Add a bounded release-build diagnostic ring buffer
mzagozda Aug 10, 2026
8a97cbb
Assign correlation IDs to operations and workers
mzagozda Aug 10, 2026
5d68c72
Preserve the first actionable error and its context
mzagozda Aug 10, 2026
01acf91
Preserve the first actionable error and its context
mzagozda Aug 10, 2026
53f2417
Apply deadlines and cancellation to all network operations
mzagozda Aug 10, 2026
854f89b
Make FTP transfers transactional and resumable safely
mzagozda Aug 10, 2026
bd049d7
Strengthen FTP certificate exception storage
mzagozda Aug 10, 2026
1cf76c2
Upgrade the bundled 7-Zip code
mzagozda Aug 10, 2026
8b60b34
Implemented new UI icons and bumped version number to 6
mzagozda Aug 10, 2026
5be116b
Upgrade SQLite and define database recovery behavior
mzagozda Aug 10, 2026
04f2fcd
Upgrade zlib
mzagozda Aug 10, 2026
aed3359
Upgrade cmark-gfm and harden rendered-content defaults
mzagozda Aug 10, 2026
2ffaf11
Upgrade bzip2
mzagozda Aug 10, 2026
1b840bb
Implemented the 7‑Zip task-dispatch hardening
mzagozda Aug 11, 2026
6f62228
Implemented the crash-compression hardening
mzagozda Aug 11, 2026
60b6edb
Implemented fluent design specification and assets
mzagozda Aug 11, 2026
66c38e6
Implemented the four plug-in reader migrations
mzagozda Aug 11, 2026
0c58195
Apply checked 64-bit file-size handling to active plug-in readers
mzagozda Aug 12, 2026
7039bfe
Updated readme.md
mzagozda Aug 14, 2026
0b9745c
Poweshell requirements added
mzagozda Aug 14, 2026
9c9b102
Improved testing process
mzagozda Aug 14, 2026
668f0d5
Updated tests and Added new
PatrykLs98 Aug 14, 2026
b3722dd
Resolved conflicts
PatrykLs98 Aug 14, 2026
32f6fd8
Revert "Resolved conflicts"
PatrykLs98 Aug 21, 2026
527c6d6
Revert "Updated tests and Added new"
PatrykLs98 Aug 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion .github/workflows/auto-label-author.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,8 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Label PRs from bellus869 and Lemi257
uses: actions/github-script@v7
# Pin the privileged pull_request_target action to a reviewed commit.
uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7
with:
script: |
const labelName = "comments translation";
Expand Down
191 changes: 150 additions & 41 deletions .github/workflows/build-installer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ on:
workflow_dispatch:

permissions:
contents: write
# Release write access is granted only to the protected publish job below.
contents: read

env:
# Opt JavaScript actions (actions/checkout, microsoft/setup-msbuild,
Expand All @@ -17,9 +18,94 @@ env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"

jobs:
release-tests:
name: Complete automated release gate
# Every UI fixture mutates profile state, so the release gate uses the same
# dedicated unlocked desktop as the existing Application Verifier lane.
runs-on: [self-hosted, windows, filemanager-ui]
permissions:
contents: read

env:
BUILD_CONFIGURATION: Debug
SOLUTION_PATH: 'src\vcxproj\salamand.sln'
PLATFORM_TOOLSET: v145
OPENSAL_BUILD_DIR: '${{ github.workspace }}\build_stage\'
FILEMANAGER_UI_ISOLATED: '1'
FILEMANAGER_UI_CONFIG_FAULT_INJECTION: '1'
FILEMANAGER_UI_RECYCLE_BIN: '1'
# Dedicated-volume roots and the runtime FTP command are configured as
# repository variables; strict skip handling blocks release if any is absent.
FILEMANAGER_UI_CROSS_VOLUME_ROOT: '${{ vars.FILEMANAGER_UI_CROSS_VOLUME_ROOT }}'
FILEMANAGER_UI_ADS_UNSUPPORTED_TARGET_ROOT: '${{ vars.FILEMANAGER_UI_ADS_UNSUPPORTED_TARGET_ROOT }}'
FILEMANAGER_UI_FTP_ORGANIZE_COMMAND: '${{ vars.FILEMANAGER_UI_FTP_ORGANIZE_COMMAND }}'

steps:
- name: Checkout complete history
# Pin actions by reviewed commit to keep the release input graph immutable.
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
fetch-depth: 0

- name: Setup MSBuild
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2

- name: Setup MSVC Developer Command Prompt (x64 toolchain)
uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1
with:
arch: x64

- name: Build Debug x64 test artifacts
shell: pwsh
run: |
New-Item -ItemType Directory -Force -Path $env:OPENSAL_BUILD_DIR | Out-Null
msbuild $env:SOLUTION_PATH /m /t:Build /p:Configuration=$env:BUILD_CONFIGURATION /p:Platform=x64 /p:PlatformToolset=$env:PLATFORM_TOOLSET /p:PreferredToolArchitecture=x64 /nr:false

- name: Resolve strict runner inputs
shell: pwsh
env:
PUSH_BASE_COMMIT: '${{ github.event.before }}'
run: |
# Push events provide the exact pre-push revision; manual releases
# compare with the first parent of the explicitly selected revision.
$baseCommit = $env:PUSH_BASE_COMMIT
if ([string]::IsNullOrWhiteSpace($baseCommit) -or $baseCommit -match '^0+$') {
$baseCommit = 'HEAD^'
}
git rev-parse --verify "$baseCommit^{commit}" | Out-Null

$sqlite = Get-ChildItem $env:OPENSAL_BUILD_DIR -Filter sqlite.dll -Recurse |
Where-Object { $_.FullName -like '*Debug_x64*' } | Select-Object -First 1
$executable = Get-ChildItem $env:OPENSAL_BUILD_DIR -Filter salamand.exe -Recurse |
Where-Object { $_.FullName -like '*Debug_x64*' } | Select-Object -First 1
if ($null -eq $sqlite -or $null -eq $executable) {
throw 'The strict release runner requires Debug x64 sqlite.dll and salamand.exe artifacts.'
}

"RELEASE_BASE_COMMIT=$baseCommit" | Out-File $env:GITHUB_ENV -Encoding utf8 -Append
"SQLITE_TEST_DLL=$($sqlite.FullName)" | Out-File $env:GITHUB_ENV -Encoding utf8 -Append
"FILEMANAGER_UI_EXE=$($executable.FullName)" | Out-File $env:GITHUB_ENV -Encoding utf8 -Append

- name: Run every automated test without skips
shell: pwsh
run: .\runtests.ps1 -BaseCommit $env:RELEASE_BASE_COMMIT -SqliteDll $env:SQLITE_TEST_DLL -FailOnSkipped

- name: Upload Application Verifier logs
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: release-application-verifier-logs
path: TestResults\application-verifier-logs
if-no-files-found: warn

build:
name: Build Installer (x64 Release)
# Publishing cannot begin until the unified runner has executed every test
# and rejected both failures and missing prerequisites.
needs: release-tests
runs-on: windows-2022
permissions:
contents: read

env:
BUILD_CONFIGURATION: Release
Expand All @@ -37,52 +123,42 @@ jobs:

steps:
- name: Checkout
uses: actions/checkout@v4
# Pin actions by reviewed commit to keep the release input graph immutable.
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Setup MSBuild in PATH (VS2022)
uses: microsoft/setup-msbuild@v2

- name: Download OpenSSL Libraries
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'

$opensslZip = Join-Path $env:RUNNER_TEMP "openssl.zip"
$uri = "https://intelitech.home.pl/install/openssl-1.0.2u-x64_86-win64.zip"

$resp = Invoke-WebRequest -Uri $uri -OutFile $opensslZip -MaximumRedirection 10 -PassThru
Write-Host "HTTP status: $($resp.StatusCode)"
Write-Host "Content-Type: $($resp.Headers.'Content-Type')"
Write-Host "Downloaded bytes: $((Get-Item $opensslZip).Length)"

# Validate: ZIP files start with 'PK' (0x50 0x4B).
$bytes = [System.IO.File]::ReadAllBytes($opensslZip)
if ($bytes.Length -lt 2) {
throw "OpenSSL download is unexpectedly short."
}

if ($bytes[0] -ne 0x50 -or $bytes[1] -ne 0x4B) {
Write-Host "First bytes: $('{0:X2} {1:X2}' -f $bytes[0], $bytes[1])"
Write-Host "File head (as text):"
Get-Content -Path $opensslZip -TotalCount 20 | ForEach-Object { $_ }
throw "OpenSSL download is not a ZIP (likely received HTML). URL may have changed or requires different source."
}

Expand-Archive -Path $opensslZip -DestinationPath "utils" -Force
Remove-Item $opensslZip
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2

- name: Build Solution (Release | x64)
run: |
New-Item -ItemType Directory -Force -Path $env:OPENSAL_BUILD_DIR
# We do NOT pass /p:OutDir here, we let the project props use OPENSAL_BUILD_DIR
msbuild $env:SOLUTION_PATH /m /t:Build /p:Configuration=$env:BUILD_CONFIGURATION /p:Platform=x64 /p:PlatformToolset=$env:PLATFORM_TOOLSET /p:PreferredToolArchitecture=x64

- name: Install Inno Setup
- name: Install pinned Inno Setup
shell: pwsh
run: |
choco install innosetup -y --no-progress
# Add Inno Setup to PATH
$innoPath = "C:\Program Files (x86)\Inno Setup 6"
echo "$innoPath" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append
# The lock file makes a tool update an explicit reviewed source change.
$input = (Get-Content tools\release-inputs.json -Raw | ConvertFrom-Json).inputs.innoSetup
$installer = Join-Path $env:RUNNER_TEMP 'innosetup-installer.exe'
Invoke-WebRequest -Uri $input.url -OutFile $installer
$actualHash = (Get-FileHash -LiteralPath $installer -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actualHash -ne $input.sha256) {
throw "Pinned Inno Setup SHA-256 mismatch: expected $($input.sha256), got $actualHash."
}
$signature = Get-AuthenticodeSignature -LiteralPath $installer
if ($signature.Status -ne 'Valid' -or $signature.SignerCertificate.Subject -notlike "*CN=$($input.publisher)*") {
throw "Pinned Inno Setup Authenticode verification failed: $($signature.Status) $($signature.SignerCertificate.Subject)"
}
& $installer /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
if ($LASTEXITCODE -ne 0) { throw "Inno Setup installation failed with exit code $LASTEXITCODE." }
$innoPath = 'C:\Program Files (x86)\Inno Setup 6'
$iscc = Join-Path $innoPath 'ISCC.exe'
if (-not (Test-Path -LiteralPath $iscc)) { throw "Pinned Inno Setup did not install $iscc." }
if ((Get-Item -LiteralPath $iscc).VersionInfo.ProductVersion -notmatch '^6\.7\.3') {
throw "Installed Inno Setup version does not match the locked version $($input.version)."
}
$innoPath | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append

- name: Prepare Installer Files
run: |
Expand All @@ -107,12 +183,45 @@ jobs:
$sourcePath = Split-Path -Leaf $env:INSTALLER_STAGING_DIR
iscc.exe /DSourcePath="$sourcePath" /DBuildNumber=${{ github.run_number }} "Installer\setup.iss"

- name: Preserve verified installer for the publish job
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
# Artifact immutability prevents publish from receiving a rebuilt installer.
name: release-installer-${{ github.sha }}
path: Installer\Output\OpenSalamander_6.0.${{ github.run_number }}.exe
if-no-files-found: error

- name: Preserve private symbols for crash analysis
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
# Keep PDBs out of the public release while retaining exact-build diagnostics.
name: private-symbols-${{ github.sha }}
path: ${{ env.OPENSAL_BUILD_DIR }}\**\*.pdb
if-no-files-found: error
retention-days: 180

publish:
name: Publish verified installer
needs: build
runs-on: windows-2022
environment: production
permissions:
contents: write

steps:
- name: Retrieve the immutable installer
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: release-installer-${{ github.sha }}
path: Installer\Output

- name: Create Release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@e5f48c3b7b613b7a911e58a617b757074c4c790d # v2.0.2
with:
tag_name: 5.0.${{ github.run_number }}
name: Open Salamander 5.0.${{ github.run_number }}
files: Installer\Output\OpenSalamander_5.0.${{ github.run_number }}.exe
# Keep the release-managed major separate from GitHub's automatic run number.
tag_name: 6.0.${{ github.run_number }}
name: Open Salamander 6.0.${{ github.run_number }}
files: Installer\Output\OpenSalamander_6.0.${{ github.run_number }}.exe
draft: false
prerelease: false
env:
Expand Down
78 changes: 78 additions & 0 deletions .github/workflows/nightly-lock-stress.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
name: Nightly Lock Stress

on:
schedule:
- cron: '17 2 * * *'
workflow_dispatch:

permissions:
contents: read

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
BUILD_CONFIGURATION: Debug
SOLUTION_PATH: 'src\\vcxproj\\salamand.sln'
PLATFORM_TOOLSET: v145
OPENSAL_BUILD_DIR: '${{ github.workspace }}\\build_stage\\'

jobs:
verifier-lock-stress:
# FlaUI needs an unlocked desktop and an isolated profile; this label is deliberately not a hosted runner.
runs-on: [self-hosted, windows, filemanager-ui]

steps:
- name: Checkout
# Pin actions by reviewed commit to keep the nightly diagnostic lane reproducible.
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Setup MSBuild
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2

- name: Setup MSVC Developer Command Prompt (x64 toolchain)
uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1
with:
arch: x64

- name: Build Debug x64 executable
shell: pwsh
run: |
msbuild $env:SOLUTION_PATH /m /t:Build /p:Configuration=$env:BUILD_CONFIGURATION /p:Platform=x64 /p:PlatformToolset=$env:PLATFORM_TOOLSET /p:PreferredToolArchitecture=x64 /nr:false

- name: Run Application Verifier and PageHeap UI suite
shell: pwsh
run: |
$appVerifier = Get-Command appverif.exe -ErrorAction SilentlyContinue
if ($null -eq $appVerifier) {
$appVerifier = Get-ChildItem 'C:\Program Files (x86)\Windows Kits\10\Debuggers' -Filter appverif.exe -Recurse -ErrorAction SilentlyContinue |
Select-Object -First 1
}
if ($null -eq $appVerifier) {
throw 'Application Verifier is required on the filemanager-ui runner.'
}
$appVerifierPath = if ($appVerifier -is [System.Management.Automation.CommandInfo]) {
$appVerifier.Source
} else {
$appVerifier.FullName
}

$executable = Get-ChildItem $env:OPENSAL_BUILD_DIR -Filter salamand.exe -Recurse |
Where-Object { $_.FullName -like '*Debug_x64*' } |
Select-Object -First 1
if ($null -eq $executable) {
throw 'The Debug x64 salamand.exe build output was not found.'
}

# The self-hosted runner account is dedicated to this lane, which makes profile-mutating UI tests safe.
$env:FILEMANAGER_UI_ISOLATED = '1'
$env:FILEMANAGER_UI_EXE = $executable.FullName
.\tools\run-lock-verifier-stress.ps1 -ExecutablePath $executable.FullName `
-TestProject '.\tests\FileManager.UiTests\FileManager.UiTests.csproj' -AppVerifierPath $appVerifierPath `
-LogOutputDirectory '.\application-verifier-logs' -VerifierProfile Full -TestFilter 'TestCategory=UI'

- name: Upload Application Verifier logs
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: application-verifier-pageheap-logs
path: application-verifier-logs
if-no-files-found: warn
4 changes: 2 additions & 2 deletions .github/workflows/pr-comments-guard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,8 @@ jobs:

- name: Checkout PR
if: steps.label_check.outputs.should-skip != 'true'
uses: actions/checkout@v4
# Pin checkout because this pull_request_target job reads untrusted PR content.
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ github.event.pull_request.head.sha }}
fetch-depth: 0
Expand Down Expand Up @@ -206,7 +207,6 @@ jobs:
'src/plugins/automation/generated',
'src/plugins/shared/lukas',
'src/plugins/ftp',
'src/plugins/ftp/openssl',
'src/plugins/ieviewer/cmark-gfm/build/src',
'src/plugins/ieviewer/cmark-gfm/build/extensions',
'src/plugins/ieviewer/cmark-gfm/extensions',
Expand Down
Loading
Loading