diff --git a/scripts/package-source.sh b/scripts/package-source.sh index 2e8110b..38631c7 100755 --- a/scripts/package-source.sh +++ b/scripts/package-source.sh @@ -26,6 +26,17 @@ Developer ID signing/notarization requires your own identity and is separate. BUILD (cd "$source_dir" && CARGO_HOME="$destination/empty-cargo-home" CARGO_TARGET_DIR="$destination/check-target" cargo check --locked --offline --workspace --all-targets) (cd "$source_dir" && python3 scripts/check-core.py) -tar -czf "$destination/sized-v2.0.0-source.tar.gz" -C "$destination" sized-source +COPYFILE_DISABLE=1 tar --no-xattrs -czf "$destination/sized-v2.0.0-source.tar.gz" -C "$destination" sized-source +# Reject platform metadata sidecars before any publication or Linux rebuild. +python3 - "$destination/sized-v2.0.0-source.tar.gz" <<'PY_CHECK' +import sys, tarfile +from pathlib import PurePosixPath +with tarfile.open(sys.argv[1]) as archive: + for entry in archive: + if any(part.startswith('._') for part in PurePosixPath(entry.name).parts): + raise SystemExit(f'Unexpected AppleDouble metadata: {entry.name}') + if any('xattr' in key.lower() for key in entry.pax_headers): + raise SystemExit(f'Unexpected extended attributes: {entry.name}') +PY_CHECK printf '%s\n' "$revision" > "$destination/SOURCE-REVISION.txt" echo "Verified offline source: $destination/sized-v2.0.0-source.tar.gz" diff --git a/scripts/release.sh b/scripts/release.sh index ee19eb0..70aa821 100755 --- a/scripts/release.sh +++ b/scripts/release.sh @@ -46,7 +46,7 @@ python3 scripts/package-notices.py "$destination" --revision "$revision" printf 'Unsigned host build; not a notarized Mac application.\n' } > "$destination/BUILD-INFO.txt" -tar -czf "$destination.tar.gz" -C "$destination" . +COPYFILE_DISABLE=1 tar --no-xattrs -czf "$destination.tar.gz" -C "$destination" . ( cd "$(dirname "$destination")" archive="$(basename "$destination").tar.gz"