From d876fdeee133c4e1bbb76f0799f4bd2934c93c70 Mon Sep 17 00:00:00 2001 From: Kat Suricata Date: Wed, 12 Aug 2026 15:23:25 -0400 Subject: [PATCH] ci: fix pages publish paths + add fakeroot dep cp globs stayed correct only while cwd never left the repo root; after cd-ing into the deploy clone they must be resolved via . --tag-sha now comes from TANGLED_SHA (the sheaf commit), not the pages checkout. Also set -e on make-pkg so a fakeroot gap fails the right step. --- .tangled/workflows/release.yml | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/.tangled/workflows/release.yml b/.tangled/workflows/release.yml index 6561a21..f16c842 100644 --- a/.tangled/workflows/release.yml +++ b/.tangled/workflows/release.yml @@ -50,6 +50,7 @@ dependencies: # packaging & publishing - upx - zstd + - fakeroot # make-pkg.sh: files inside .pkg.tar.zst must be root-owned - jq - openssh - git @@ -125,6 +126,7 @@ steps: command: | # nixos has no makepkg/pacman; scripts/make-pkg.sh assembles # .pkg.tar.zst from the freshly built amd64 binary + packaging/linux. + set -e cd /workspace/repo VERSION=$(cat .release/VERSION) bash scripts/make-pkg.sh "$VERSION" build/bin/sheaf .release/dist @@ -147,9 +149,9 @@ steps: chmod 600 "$WORK/ssh/id" export GIT_SSH_COMMAND="ssh -i $WORK/ssh/id -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new" git clone --depth 1 "$PAGES_REPO_SSH" "$DEPLOY" - cd "$DEPLOY" - REL_DIR="sheaf/v${VERSION}" + # copy from the sheaf checkout ($WORK still points into /workspace/repo) + REL_DIR="$DEPLOY/sheaf/v${VERSION}" mkdir -p "$REL_DIR" cp "$WORK/dist"/sheaf-linux-* "$WORK/dist"/SHA256SUMS \ "$WORK/dist"/sheaf-"${VERSION}"-source.tar.gz \ @@ -157,12 +159,13 @@ steps: # regenerate every index.html (root, /sheaf/, /sheaf/vX.Y.Z/) from the # on-disk tree + deploy-history meta, so indexes always match reality. - python3 "$OLDPWD/scripts/make-indexes.py" \ + python3 scripts/make-indexes.py \ --repo-root "$DEPLOY" \ --project sheaf \ --version "v${VERSION}" \ - --tag-sha "$(git rev-parse HEAD)" \ + --tag-sha "$TANGLED_SHA" \ --source-url "https://tangled.org/katsuricata.com/Sheaf" + cd "$DEPLOY" git config user.email "spindle@katsuricata.com" git config user.name "sheaf release pipeline" -- 2.51.2