From 77b11a8c29b5ca3435fdd962717f8e8285abe972 Mon Sep 17 00:00:00 2001 From: Cole Speelman Date: Sat, 10 Oct 2026 04:00:52 -0400 Subject: [PATCH] Keep package targets explicit and reject existing archive symlinks --- CHANGELOG.md | 6 ++++++ scripts/check-release.sh | 7 +++++++ scripts/release.sh | 4 ++-- 3 files changed, 15 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 74df2ea..c431669 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] ### Fixed +- Include the executable before creating release archives. Use explicit host + targets, build provenance and checksums; refuse existing outputs and symlinks. +- Replace stale installation links and unavailable package-manager claims with + verified Gitea availability and explicit source-build instructions. - Count hard-link allocation once in a deterministic traversal order while retaining apparent sizes per pathname. Filtered comparison has independent allocation ownership, including when the first link is ignored. @@ -17,6 +21,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 symlinks as scan targets and distinguish special files from directories. ### Added +- Host archive extraction/executable checks on macOS and in Linux CI, plus + the Sized project page and its connection to SizeQueen's scanning core. - A scanner module with structured reports, file identities, progress counters, cooperative cancellation, and per-scan thread pools. - Optional `-x` / `--one-file-system` boundary handling. Partial CLI reports diff --git a/scripts/check-release.sh b/scripts/check-release.sh index 4fea86d..71b6fa2 100755 --- a/scripts/check-release.sh +++ b/scripts/check-release.sh @@ -29,4 +29,11 @@ if "$repo_root/scripts/release.sh" --output-dir "$check_root/bundle" > "$check_r exit 1 fi grep -q 'Refusing to replace' "$check_root/repeat.log" +ln -s "$check_root/untouched" "$check_root/linked.tar.gz" +if "$repo_root/scripts/release.sh" --output-dir "$check_root/linked" > "$check_root/linked.log" 2>&1; then + printf 'Packaging unexpectedly followed an existing archive symlink.\n' >&2 + exit 1 +fi +grep -q 'Refusing to replace' "$check_root/linked.log" +test ! -e "$check_root/untouched" printf 'Archive contents, checksum, extracted CLI and overwrite guard passed.\n' diff --git a/scripts/release.sh b/scripts/release.sh index d2c7b21..93c9f0a 100755 --- a/scripts/release.sh +++ b/scripts/release.sh @@ -16,12 +16,12 @@ elif [[ $# != 0 ]]; then fi [[ $destination == /* ]] || { printf 'Output directory must be absolute.\n' >&2; exit 2; } for output in "$destination" "$destination.tar.gz" "$destination.tar.gz.sha256"; do - [[ ! -e $output ]] || { printf 'Refusing to replace %s\n' "$output" >&2; exit 1; } + [[ ! -e $output && ! -L $output ]] || { printf 'Refusing to replace %s\n' "$output" >&2; exit 1; } done target_dir=${CARGO_TARGET_DIR:-"$repo_root/target"} [[ $target_dir == /* ]] || target_dir="$repo_root/$target_dir" -cargo build --locked --release --target "$target" +cargo build --locked --release --target "$target" --target-dir "$target_dir" binary="$target_dir/$target/release/sized" mkdir -p "$destination" install -m 755 "$binary" "$destination/sized"