build: add reproducible release bundles

This commit is contained in:
2026-09-11 09:13:36 +00:00
parent 2cf563d88e
commit cc31f6cb67
7 changed files with 180 additions and 0 deletions
+24
View File
@@ -69,6 +69,30 @@ false and records an incident; do not delete segments to force readiness.
and full data directory, then start the known-good version. Preserve logs
and the failed copy for diagnosis.
## Release bundle
Build a release candidate only from a clean, committed worktree. The
containerized release wrapper embeds the supplied version in all three binaries,
creates an immutable `dist/rvbox-VERSION` directory, and writes `SHA256SUMS`
plus `manifest.json` only after the Windows executable has optionally been
signed:
```sh
scripts/release build --version 1.0.0-rc.1
sha256sum -c dist/rvbox-1.0.0-rc.1/SHA256SUMS
dist/rvbox-1.0.0-rc.1/rvbox-server-linux-amd64 --version
dist/rvbox-1.0.0-rc.1/rvc-linux-amd64 --version
```
For a Windows-signed release, provide an executable host-side signing hook via
`--sign-windows-hook /absolute/path/to/hook`. The wrapper invokes it with the
Windows executable path and version, then records `windows_signed: true` in the
manifest. Without that hook the manifest deliberately declares the artifact
unsigned; this is suitable for CI/test evidence but not a signed public
release. The wrapper never overwrites a final bundle, so correcting a failed
candidate requires choosing a new version/output or deliberately removing that
exact ignored `dist/` directory after preserving any evidence.
## Common incidents
- **No client / stale session:** verify nginx has WebSocket `101` entries for