Skip to content

Update third-party dependencies to their latest stable releases - #163

Merged
themuffinator merged 7 commits into
mainfrom
deps/refresh-2026-09
Sep 13, 2026
Merged

themuffinator merged 7 commits into
mainfrom
deps/refresh-2026-09

Conversation

@themuffinator

Copy link
Copy Markdown
Owner

Refreshes every third-party dependency that has a newer stable release, plus
the repository housekeeping that fell out of the audit.

Dependencies

Dependency Before After
Vulkan-Headers / Volk SDK 1.4.313.1 (header 313) SDK 1.4.357.0 (header 357)
VulkanMemoryAllocator 3.2.1 3.4.0
SDL3 (bundled wrap) 3.4.10 3.4.16
OpenAL Soft (pinned build) 1.25.1 1.25.2
actions/checkout, setup-python, upload-artifact v6 v7
actions/download-artifact v5 v8
actions/setup-node v6 v7

Deliberately not bumped:

  • MoltenVK stays at v1.4.1. v1.4.2 raises the runtime floor to macOS 12
    and openQ4 targets 11.0; the pin is documented in
    tools/build/prepare_macos_moltenvk.sh.
  • GLEW is already on upstream's newest release (2.3.1) and stb_vorbis
    matches upstream master (v1.22)
    , so neither has anything to take.
  • The NuGet openal.soft fallback package is still 1.23.1 upstream.

Housekeeping

  • GLEW gains the provenance README the other vendored trees already have, and
    src/external/glew/glew.c is resynced with the copy that actually compiles
    (it was missing two OPENQ4_GLEW_SDL3_LOADER guards).
  • a.cpp, a one-line compile probe, is removed from the repository root.

Unrelated work carried along

  • Weapon Kick settings row (g_weaponMuzzleKick), which was already in the
    working tree.

Verification

  • python tools/validation/openq4_validate.py push --skip-python-tests --no-clean --build-dir builddir passes in 252s: all six binaries (client,
    ded, game-sp, game-mp, renderer-gl, renderer-vk) build against the new SDL3,
    Vulkan headers, Volk and VMA, and 12/12 Meson native tests pass.
  • Full tools/tests/*.py sweep: the pin tests covering these changes
    (macos_openal_provider_policy, macos_metal_bridge,
    macos_universal2_assembly, linux_sdl3_glew_loader,
    release_tooling_safety, settings_menu_coverage) all pass. The remaining
    local failures are environmental: Linux/macOS-only smokes, harnesses that
    need CLI arguments, and cross-repo tests reading a local openQ4-game at
    GAME_API_VERSION 48 while CI pins a tree at 46.

🤖 Generated with Claude Code

themuffinator and others added 7 commits September 13, 2026 17:51
Refresh the Vulkan C headers, Volk and VMA from Vulkan SDK 1.4.357.0:
header version 313 -> 357, Volk 313 -> 357 and VMA 3.2.1 -> 3.4.0. The
357 vulkan_core.h includes the VP9 video-codec headers, so vendor those
two alongside the existing vk_video set, and record the new SDK version
in each provenance README.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Move the SDL3 fallback wrap from 3.4.10 to 3.4.16 with a verified
archive hash, and match the bundled Meson port's project version so the
built library reports the right SDL version. 3.4.16 only adds two
Vulkan renderer headers over 3.4.10, so the port's source lists are
unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Move the checksum-pinned macOS OpenAL Soft build and the Windows
source-build default from 1.25.1 to 1.25.2, with the new archive digest,
and follow the version through the packaging scripts, release
validation, provider-policy tests and docs. The vendored AL headers are
refreshed from the same tag; upstream only changed their regeneration
timestamp, so the API surface is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Bump checkout, setup-python and upload-artifact to v7, download-artifact
to v8 and setup-node to v7 across every workflow, and follow the
upload-artifact pin in the release tooling safety test. None of the
breaking changes apply here: no workflow uses pull_request_target,
workflow_run or self-hosted runners, setup-python is only given
python-version, and the download inputs in use are still supported.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
GLEW is already on upstream's newest release, 2.3.1, so this only
documents it: a README recording the release, the local GLEW_STATIC and
include-path tweaks, the OPENQ4_GLEW_SDL3_LOADER patch, and the fact
that upstream's own generated glew.h defines GLEW_VERSION_MICRO 4 in the
2.3.1 release so nobody "fixes" it again.

src/external/glew/glew.c had also drifted from the copy that actually
compiles: it was missing the two SDL3-loader guards that keep the GLX
loader out of the build. Bring it back in line with
subprojects/glew/src/glew.c, which the loader test pins as its mirror.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
a.cpp was a one-line "int main(){return 0;}" toolchain probe committed
to the repository root; nothing in the build or tooling references it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Expose g_weaponMuzzleKick as a choice row under Settings > Game Options
> View Weapon, with the hover text, localized label, scroll extent and
registry/structure entries the settings menu contract requires, and
extend the coverage test to the new row.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-13T17:00:49.496015Z 526cb33 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 526cb3397c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

# OpenAL Soft source and license

openQ4 macOS packages include the dynamically linked [OpenAL Soft](https://openal-soft.org/) runtime, version 1.25.1. OpenAL Soft is distributed under the GNU Library General Public License, version 2 or (at your option) any later version; see `COPYING` in this directory. Notices for the incorporated PFFFT, fmt, and Microsoft GSL components are provided as `LICENSE-pffft`, `LICENSE-fmt`, and `LICENSE-gsl`.
openQ4 macOS packages include the dynamically linked [OpenAL Soft](https://openal-soft.org/) runtime, version 1.25.2. OpenAL Soft is distributed under the GNU Library General Public License, version 2 or (at your option) any later version; see `COPYING` in this directory. Notices for the incorporated PFFFT, fmt, and Microsoft GSL components are provided as `LICENSE-pffft`, `LICENSE-fmt`, and `LICENSE-gsl`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the dependency table for OpenAL Soft 1.25.2

The active dependency table in TECHNICAL.md still identifies OpenAL Soft as version 1.25.1, so this bump leaves developers with contradictory version and provenance documentation. Update that table alongside the package and build-script references.

AGENTS.md reference: AGENTS.md:L34-L34

Useful? React with 👍 / 👎.

@themuffinator
themuffinator merged commit 10bcab0 into main Sep 13, 2026
32 of 33 checks passed
@themuffinator
themuffinator deleted the deps/refresh-2026-09 branch September 13, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant