fix: map release staging into toolchain workspace

This commit is contained in:
2026-09-11 09:16:58 +00:00
parent cc31f6cb67
commit 15b2c4f9d3
2 changed files with 11 additions and 3 deletions
+3 -1
View File
@@ -89,7 +89,9 @@ For a Windows-signed release, provide an executable host-side signing hook via
Windows executable path and version, then records `windows_signed: true` in the Windows executable path and version, then records `windows_signed: true` in the
manifest. Without that hook the manifest deliberately declares the artifact manifest. Without that hook the manifest deliberately declares the artifact
unsigned; this is suitable for CI/test evidence but not a signed public unsigned; this is suitable for CI/test evidence but not a signed public
release. The wrapper never overwrites a final bundle, so correcting a failed release. `--output` is intentionally constrained beneath this repository's
ignored `dist/` tree so the pinned build container always sees the exact output
mount. The wrapper never overwrites a final bundle, so correcting a failed
candidate requires choosing a new version/output or deliberately removing that candidate requires choosing a new version/output or deliberately removing that
exact ignored `dist/` directory after preserving any evidence. exact ignored `dist/` directory after preserving any evidence.
+8 -2
View File
@@ -18,7 +18,8 @@ Builds a fresh immutable bundle containing:
SHA256SUMS SHA256SUMS
manifest.json manifest.json
The default output is dist/rvbox-VERSION. VERSION must be a safe release label The default output is dist/rvbox-VERSION. --output must remain below this
repository's ignored dist/ tree. VERSION must be a safe release label
([0-9A-Za-z][0-9A-Za-z._+-]{0,63}); an existing final output is never replaced. ([0-9A-Za-z][0-9A-Za-z._+-]{0,63}); an existing final output is never replaced.
Artifacts are built inside the pinned Docker toolchain with that exact version Artifacts are built inside the pinned Docker toolchain with that exact version
embedded in `--version`. The optional signing hook is a regular executable run embedded in `--version`. The optional signing hook is a regular executable run
@@ -60,6 +61,10 @@ case $output in
/*) ;; /*) ;;
*) output=$repo_root/$output ;; *) output=$repo_root/$output ;;
esac esac
case $output in
"$repo_root"/dist/*) ;;
*) fail "--output must be below $repo_root/dist" ;;
esac
parent=$(dirname -- "$output") parent=$(dirname -- "$output")
[ ! -e "$output" ] || fail "refusing to replace existing output $output" [ ! -e "$output" ] || fail "refusing to replace existing output $output"
[ -d "$parent" ] || mkdir -p "$parent" [ -d "$parent" ] || mkdir -p "$parent"
@@ -75,6 +80,7 @@ partial=$parent/.rvbox-$version.partial-$$
mkdir "$partial" || fail "could not create private release staging directory" mkdir "$partial" || fail "could not create private release staging directory"
cleanup() { rm -rf -- "$partial"; } cleanup() { rm -rf -- "$partial"; }
trap cleanup EXIT HUP INT TERM trap cleanup EXIT HUP INT TERM
container_partial=/workspace/${partial#"$repo_root"/}
commit=$(git -C "$repo_root" rev-parse HEAD) commit=$(git -C "$repo_root" rev-parse HEAD)
dirty=$(git -C "$repo_root" status --porcelain) dirty=$(git -C "$repo_root" status --porcelain)
@@ -88,7 +94,7 @@ docker compose -f "$compose_file" run --rm toolchain sh -ec '
CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "$flags" -o "$out/rvbox-server-linux-amd64" ./cmd/rvbox-server CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "$flags" -o "$out/rvbox-server-linux-amd64" ./cmd/rvbox-server
CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "$flags" -o "$out/rvc-linux-amd64" ./cmd/rvc CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "$flags" -o "$out/rvc-linux-amd64" ./cmd/rvc
CGO_ENABLED=0 GOOS=windows GOARCH=amd64 go build -trimpath -ldflags "-H=windowsgui $flags" -o "$out/rvbox-windows-amd64.exe" ./cmd/rvbox CGO_ENABLED=0 GOOS=windows GOARCH=amd64 go build -trimpath -ldflags "-H=windowsgui $flags" -o "$out/rvbox-windows-amd64.exe" ./cmd/rvbox
' sh "$version" "$partial" ' sh "$version" "$container_partial"
signed=false signed=false
if [ -n "$sign_hook" ]; then if [ -n "$sign_hook" ]; then