Skip to content

Release v1.3.0: macOS/Linux support and archive fixes - #20

Merged
rozx merged 7 commits into
mainfrom
release/v1.3
Sep 24, 2026
Merged

rozx merged 7 commits into
mainfrom
release/v1.3

Conversation

@rozx

@rozx rozx commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

Release 1.3.0 adds native macOS and Linux support alongside Windows and updates the bundled 7-Zip engines to 26.03. Platform assets now live in separate directories, including 7z/windows-x64/.

  • Read and save the global password book beside the executable (project root for source runs), with a warning if saving fails. Personal password books are no longer embedded in builds.
  • Collect matching sibling volumes, including cloaked names, when a single multipart file is supplied, clean the full set on success, and retain source parts on extraction or password failure.
  • Use UTF-8 for redirected Windows output and exit without waiting for Enter when output is redirected.
  • Add five-platform CI and releases triggered by a labeled release/* PR merging into main, using version-matched notes from ReleaseNotes/ and verified download checksums.
  • Include bilingual 1.3.0 release notes, updated READMEs, and synced OpenSpec documentation.

Validation

  • 300 tests passed on macOS ARM64 with Python 3.11.14.
  • poetry run build produced the macOS ARM64 standalone executable.
  • Source and standalone smoke tests passed: nested archives, encrypted archives, Unicode filenames/passwords, password-book lookup, and directory/single-file multipart inputs, including cloaked volumes.
  • Version consistency, release notes, bundled engine checksums, and workflow lint checks passed.
  • GitHub CI matrix for this revision: Windows x64, macOS x64/ARM64, and Linux x64/ARM64.

Fixes #17
Fixes #18
Fixes #19

Windows chmod does not set POSIX execute bits. Assert that tar packaging preserves the source file mode on each host.

@kilo-code-bot kilo-code-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review pass at commit 3840073

Comment thread .github/workflows/release.yml Outdated
Comment thread scripts/publish_release.cjs
Comment thread complex_unzip_tool_v2/main.py Outdated
Comment thread complex_unzip_tool_v2/modules/file_utils.py Outdated
Comment thread complex_unzip_tool_v2/modules/file_utils.py Outdated
Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/release.yml
Comment thread tests/test_release.py Outdated
Comment thread tests/test_password_book.py
@kilo-code-bot

kilo-code-bot Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: 1 Issue Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 1

Fix these issues in Kilo Cloud

Issue Details (click to expand)

SUGGESTION

File Line Issue
scripts/publish_release.cjs 78 Comment claims Latest is chosen "by creation date and semantic version", but make_latest: 'legacy' is creation-date only (that description matches smart); fix the wording or switch to smart
Files Reviewed (17 files, incremental since 3840073)
  • scripts/publish_release.cjs - 1 issue
  • complex_unzip_tool_v2/modules/file_utils.py, complex_unzip_tool_v2/main.py - clean; cloaked-sibling preview is read-only, detector load cannot throw, OSError guard and missing-engine pause verified
  • .github/workflows/ci.yml, .github/workflows/release.yml - clean; concurrency design (inputs.ref valid via workflow_call) and GITHUB_WORKSPACE require verified
  • scripts/smoke_test.py, tests/test_multipart_file_input.py, tests/test_password_book.py, tests/test_platform_cli.py, tests/test_publish_release.py, tests/test_release.py - clean; new coverage verified against implementation (sorted SHA256SUMS matches verify_assets, save_passwords no-ops when clean)
  • README.md, README.en.md, AGENTS.md, ReleaseNotes/RELEASE_NOTES_v1.3.0.md, openspec/specs/cross-platform-runtime/spec.md, openspec/specs/github-release-ci/spec.md - clean; docs match behavior

All 9 previously reported findings were addressed: 7 fixed in ed0f823, duplicate release builds documented as an intentional tradeoff, and make_latest: 'legacy' kept intentionally (residual wording issue filed above).

Previous Review Summary (commit 3840073)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 3840073)

Status: 9 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 4
SUGGESTION 5

Fix these issues in Kilo Cloud

Issue Details (click to expand)

WARNING

File Line Issue
.github/workflows/release.yml 88 require('./scripts/publish_release.cjs') in actions/github-script resolves against the action's dist/ bundle, not the workspace — publish job fails with MODULE_NOT_FOUND; use process.env.GITHUB_WORKSPACE absolute path
scripts/publish_release.cjs 79 make_latest: 'legacy' keeps the previous release as Latest; v1.3.0 would not be marked Latest (should be true/smart)
complex_unzip_tool_v2/main.py 195 Missing-engine exit path skips the TTY-gated Windows pause, so frozen double-click users cannot read the 7-Zip-not-found error
complex_unzip_tool_v2/modules/file_utils.py 186 Sibling-volume scan runs before uncloaking; cloaked continuation parts (e.g. name.7z.00删1) are never collected for single-file multipart inputs

SUGGESTION

File Line Issue
complex_unzip_tool_v2/modules/file_utils.py 182 New os.scandir can raise uncaught OSError in read_dir; wrap in try/except to keep graceful errors
.github/workflows/ci.yml 1 No concurrency: group — superseded five-platform matrix runs are not cancelled
.github/workflows/release.yml 53 Release merges trigger duplicate five-platform builds (reusable run + ci.yml push on main)
tests/test_release.py 129 SHA256SUMS assertion checks line count only, not digests/names that publish_release.cjs strictly parses
tests/test_password_book.py 37 No coverage for documented multi-encoding passwords.txt reading (GBK/UTF-16/BOM)
Files Reviewed (72 changed files; engine binaries excluded)
  • complex_unzip_tool_v2/main.py, __init__.py, classes/PasswordBook.py, modules/rich_utils.py - 1 issue
  • complex_unzip_tool_v2/modules/file_utils.py, modules/archive_utils.py, modules/seven_zip_runtime.py - 2 issues
  • scripts/build.py, scripts/release.py, scripts/smoke_test.py, scripts/publish_release.cjs - 1 issue
  • .github/workflows/ci.yml, .github/workflows/release.yml - 2 issues
  • tests/test_build.py, test_file_utils.py, test_multipart_file_input.py, test_password_book.py, test_platform_cli.py, test_publish_release.py, test_release.py, test_seven_zip_runtime.py - 2 issues
  • README.md, README.en.md, AGENTS.md, CLAUDE.md, ReleaseNotes/*, 7z/README.md, 7z/manifest.json, openspec/**, pyproject.toml, .bumpversion.cfg, .gitattributes, .gitignore - clean; README/engine-path/version/CI claims all verified against code

Reviewed by glm-5.3 · Input: 0 · Output: 0 · Cached: 0

throw new Error('Uploaded asset checksums differ; keeping the release as a draft');
}
await assertTag();
// Let GitHub choose Latest by creation date and semantic version, rather than

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: Comment describes smart semantics, but make_latest: 'legacy' selects Latest by creation date only

Per the linked docs, legacy marks the release with the most recent creation date as Latest; "creation date and semantic version" is the definition of smart (the API default). The legacy choice itself is sound here — a resumed publish of an older version cannot steal Latest because its draft was created earlier — but the comment justifies it with behavior legacy does not have. The practical difference: under legacy, a later-finishing older release (e.g. a v1.2.x backport) would take the Latest badge from v1.3.0; smart would not. Either fix the wording or switch to 'smart' (and update the pinned assertion in tests/test_publish_release.py).

Suggested change
// Let GitHub choose Latest by creation date and semantic version, rather than
// Let GitHub choose Latest by the most recent creation date, rather than

Reply with @kilocode-bot fix it to have Kilo Code address this issue.

@rozx
rozx merged commit 872709f into main Sep 24, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Publish a versioned release when a release branch is merged into main

Projects

None yet

1 participant