build: remove dist/ when a release build fails (closes #333)
A failed release build no longer leaves a complete, loadable debug bundle in dist/ whose every wallet uses the publicly committed test recovery phrase. Each step of the release build runs through script/discard-dist-on-failure, which removes dist/ on failure, says on stderr that it did and why, and returns the step's own status. build-debug is deliberately unwrapped. script/verify-build is untouched.
This commit was merged in pull request #341.
This commit is contained in:
18
Makefile
18
Makefile
@@ -60,19 +60,31 @@ hooks:
|
||||
# scrubbed from the build itself: with AUTISTMASK_DEBUG=1 exported, this target
|
||||
# compiles a debug bundle and then fails on it, loudly, rather than quietly
|
||||
# handing back something other than the release build that was asked for.
|
||||
#
|
||||
# Every step of this target is wrapped in script/discard-dist-on-failure, so a
|
||||
# release build that fails removes dist/ instead of leaving a complete, loadable
|
||||
# debug bundle there for whoever runs the build, sees it fail, and loads
|
||||
# dist/chrome/ anyway. A step that succeeds removes nothing, and build-debug is
|
||||
# deliberately not wrapped.
|
||||
build:
|
||||
@echo "Building extension..."
|
||||
@set -eu; \
|
||||
receipt="$$(mktemp "$${TMPDIR:-/tmp}/autistmask-build-receipt.XXXXXX")"; \
|
||||
trap 'rm -f "$$receipt"' EXIT INT TERM; \
|
||||
AUTISTMASK_BUILD_RECEIPT="$$receipt" yarn run build 2>&1; \
|
||||
env -u AUTISTMASK_DEBUG script/verify-build --expect release \
|
||||
script/discard-dist-on-failure \
|
||||
env AUTISTMASK_BUILD_RECEIPT="$$receipt" yarn run build 2>&1; \
|
||||
script/discard-dist-on-failure \
|
||||
env -u AUTISTMASK_DEBUG script/verify-build --expect release \
|
||||
--receipt "$$receipt"
|
||||
@script/check-censored --require-dist
|
||||
@script/discard-dist-on-failure script/check-censored --require-dist
|
||||
|
||||
# Development-only build: enables the red DEBUG / INSECURE banner and makes
|
||||
# the hardcoded test recovery phrase the output of wallet creation. Never
|
||||
# distribute the artifacts this produces.
|
||||
#
|
||||
# No discard-dist-on-failure here, on purpose: a debug build that fails is not
|
||||
# producing an artifact anyone could mistake for a release one, and its dist/ is
|
||||
# the evidence of what went wrong.
|
||||
build-debug:
|
||||
@echo "Building extension (DEBUG)..."
|
||||
@set -eu; \
|
||||
|
||||
Reference in New Issue
Block a user