Keep source and binary archives free of macOS metadata
Sized Linux checks / Linux AMD64 / Rust 1.88.0 (pull_request) Successful in 5m2s
Sized Linux checks / Linux AMD64 / Rust 1.88.0 (push) Successful in 4m54s

This commit was merged in pull request #2.
This commit is contained in:
2026-10-10 13:14:43 -04:00
parent e0707447ad
commit 9f36122e37
2 changed files with 13 additions and 2 deletions
+12 -1
View File
@@ -26,6 +26,17 @@ Developer ID signing/notarization requires your own identity and is separate.
BUILD BUILD
(cd "$source_dir" && CARGO_HOME="$destination/empty-cargo-home" CARGO_TARGET_DIR="$destination/check-target" cargo check --locked --offline --workspace --all-targets) (cd "$source_dir" && CARGO_HOME="$destination/empty-cargo-home" CARGO_TARGET_DIR="$destination/check-target" cargo check --locked --offline --workspace --all-targets)
(cd "$source_dir" && python3 scripts/check-core.py) (cd "$source_dir" && python3 scripts/check-core.py)
tar -czf "$destination/sized-v2.0.0-source.tar.gz" -C "$destination" sized-source COPYFILE_DISABLE=1 tar --no-xattrs -czf "$destination/sized-v2.0.0-source.tar.gz" -C "$destination" sized-source
# Reject platform metadata sidecars before any publication or Linux rebuild.
python3 - "$destination/sized-v2.0.0-source.tar.gz" <<'PY_CHECK'
import sys, tarfile
from pathlib import PurePosixPath
with tarfile.open(sys.argv[1]) as archive:
for entry in archive:
if any(part.startswith('._') for part in PurePosixPath(entry.name).parts):
raise SystemExit(f'Unexpected AppleDouble metadata: {entry.name}')
if any('xattr' in key.lower() for key in entry.pax_headers):
raise SystemExit(f'Unexpected extended attributes: {entry.name}')
PY_CHECK
printf '%s\n' "$revision" > "$destination/SOURCE-REVISION.txt" printf '%s\n' "$revision" > "$destination/SOURCE-REVISION.txt"
echo "Verified offline source: $destination/sized-v2.0.0-source.tar.gz" echo "Verified offline source: $destination/sized-v2.0.0-source.tar.gz"
+1 -1
View File
@@ -46,7 +46,7 @@ python3 scripts/package-notices.py "$destination" --revision "$revision"
printf 'Unsigned host build; not a notarized Mac application.\n' printf 'Unsigned host build; not a notarized Mac application.\n'
} > "$destination/BUILD-INFO.txt" } > "$destination/BUILD-INFO.txt"
tar -czf "$destination.tar.gz" -C "$destination" . COPYFILE_DISABLE=1 tar --no-xattrs -czf "$destination.tar.gz" -C "$destination" .
( (
cd "$(dirname "$destination")" cd "$(dirname "$destination")"
archive="$(basename "$destination").tar.gz" archive="$(basename "$destination").tar.gz"