From 15b2c4f9d35cde3a2c3baf14ecb48b11eb5376a4 Mon Sep 17 00:00:00 2001 From: cabbage Date: Fri, 11 Sep 2026 09:16:58 +0000 Subject: [PATCH] fix: map release staging into toolchain workspace --- docs/operations-runbook.md | 4 +++- scripts/release | 10 ++++++++-- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/docs/operations-runbook.md b/docs/operations-runbook.md index 540abc0..569e0f9 100644 --- a/docs/operations-runbook.md +++ b/docs/operations-runbook.md @@ -89,7 +89,9 @@ For a Windows-signed release, provide an executable host-side signing hook via Windows executable path and version, then records `windows_signed: true` in the manifest. Without that hook the manifest deliberately declares the artifact unsigned; this is suitable for CI/test evidence but not a signed public -release. The wrapper never overwrites a final bundle, so correcting a failed +release. `--output` is intentionally constrained beneath this repository's +ignored `dist/` tree so the pinned build container always sees the exact output +mount. The wrapper never overwrites a final bundle, so correcting a failed candidate requires choosing a new version/output or deliberately removing that exact ignored `dist/` directory after preserving any evidence. diff --git a/scripts/release b/scripts/release index 0eac5e5..437af8e 100755 --- a/scripts/release +++ b/scripts/release @@ -18,7 +18,8 @@ Builds a fresh immutable bundle containing: SHA256SUMS manifest.json -The default output is dist/rvbox-VERSION. VERSION must be a safe release label +The default output is dist/rvbox-VERSION. --output must remain below this +repository's ignored dist/ tree. VERSION must be a safe release label ([0-9A-Za-z][0-9A-Za-z._+-]{0,63}); an existing final output is never replaced. Artifacts are built inside the pinned Docker toolchain with that exact version embedded in `--version`. The optional signing hook is a regular executable run @@ -60,6 +61,10 @@ case $output in /*) ;; *) output=$repo_root/$output ;; esac +case $output in + "$repo_root"/dist/*) ;; + *) fail "--output must be below $repo_root/dist" ;; +esac parent=$(dirname -- "$output") [ ! -e "$output" ] || fail "refusing to replace existing output $output" [ -d "$parent" ] || mkdir -p "$parent" @@ -75,6 +80,7 @@ partial=$parent/.rvbox-$version.partial-$$ mkdir "$partial" || fail "could not create private release staging directory" cleanup() { rm -rf -- "$partial"; } trap cleanup EXIT HUP INT TERM +container_partial=/workspace/${partial#"$repo_root"/} commit=$(git -C "$repo_root" rev-parse HEAD) dirty=$(git -C "$repo_root" status --porcelain) @@ -88,7 +94,7 @@ docker compose -f "$compose_file" run --rm toolchain sh -ec ' CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "$flags" -o "$out/rvbox-server-linux-amd64" ./cmd/rvbox-server CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "$flags" -o "$out/rvc-linux-amd64" ./cmd/rvc CGO_ENABLED=0 GOOS=windows GOARCH=amd64 go build -trimpath -ldflags "-H=windowsgui $flags" -o "$out/rvbox-windows-amd64.exe" ./cmd/rvbox -' sh "$version" "$partial" +' sh "$version" "$container_partial" signed=false if [ -n "$sign_hook" ]; then