build: remove dist/ when a release build fails (closes #333)
With AUTISTMASK_DEBUG=1 exported in the calling shell, make build compiled a debug bundle and failed on it in script/verify-build, but left the bundle in dist/: loadable, with every wallet it creates using the publicly committed test recovery phrase from src/shared/constants.js. A failed release build that leaves a loadable debug build behind is the trap the verifier exists to close. Every step of make build now runs through script/discard-dist-on-failure, which removes dist/ when its step fails and says on stderr that it did and why, then returns the step's own exit status. A removal it cannot complete is reported as loudly as one it can, naming what is still on disk. A step that succeeds removes nothing, including the final check-censored --require-dist pass. It composes with the existing receipt trap: the receipt is still deleted on the way out. make build-debug is deliberately not wrapped. A debug build that failed is not producing an artifact mistakable for a release one, and its dist/ is the evidence of what went wrong. script/test-verify-build asserts the state of dist/ on disk after a failing and a succeeding step rather than the exit status alone, plus a step that fails with no dist/ and a wrapper handed no command, and reads make -n to check the wrapper is on the release path and absent from the debug one. Both directions were also run end to end: AUTISTMASK_DEBUG=1 make build fails and leaves no dist/, plain make build passes with all 15 emitted files intact, and a debug build failed mid-write keeps its dist/. verify-build itself is unchanged; this is only what happens after it says no.
This commit is contained in:
78
script/discard-dist-on-failure
Executable file
78
script/discard-dist-on-failure
Executable file
@@ -0,0 +1,78 @@
|
||||
#!/bin/sh
|
||||
# script/discard-dist-on-failure: run one step of the RELEASE build, and if that
|
||||
# step fails, remove dist/ before returning its exit status. Our own extension
|
||||
# to scripts-to-rule-them-all, wrapped around every step of make build.
|
||||
#
|
||||
# Why: with AUTISTMASK_DEBUG=1 exported in the calling shell, make build
|
||||
# compiles a debug bundle and then fails on it in script/verify-build — but the
|
||||
# bundle is already written. It is loadable, and every wallet it creates gets
|
||||
# the publicly committed test recovery phrase from src/shared/constants.js. A
|
||||
# failed release build that leaves that behind is a smaller version of the trap
|
||||
# the verifier exists to close, and "the failure was loud" only works on an
|
||||
# operator who does not load dist/chrome/ anyway. Removing the artifact does not
|
||||
# depend on that.
|
||||
#
|
||||
# Two things this deliberately does not do. It does not wrap make build-debug: a
|
||||
# debug build that failed is not a mistakable artifact, and its output is the
|
||||
# evidence of what went wrong. And it never removes anything on a step that
|
||||
# SUCCEEDS, including the final check-censored --require-dist pass.
|
||||
#
|
||||
# The removal is never silent: it says dist/ is gone and why, on stderr, above
|
||||
# the build's own failure.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
DIST="$ROOT/dist"
|
||||
|
||||
usage() {
|
||||
echo "usage: discard-dist-on-failure COMMAND [ARG...]" >&2
|
||||
}
|
||||
|
||||
# Remove dist/, and say so. A removal that could not be completed is reported as
|
||||
# loudly as one that was: the artifact is still on disk, and reporting nothing
|
||||
# would leave the operator believing it is not.
|
||||
discard_dist() {
|
||||
if [ ! -e "$DIST" ] && [ ! -h "$DIST" ]; then
|
||||
echo "discard-dist-on-failure: the release build failed. There was no" \
|
||||
"dist/ to remove." >&2
|
||||
return 0
|
||||
fi
|
||||
|
||||
rm -rf "$DIST" || true
|
||||
|
||||
if [ -e "$DIST" ] || [ -h "$DIST" ]; then
|
||||
echo "discard-dist-on-failure: the release build failed and dist/" \
|
||||
"COULD NOT BE REMOVED, so it is still on disk. Do not load it:" \
|
||||
"a release build that failed may hold a complete debug bundle," \
|
||||
"whose wallets all use the publicly committed test recovery" \
|
||||
"phrase. Remove it by hand (make clean)." >&2
|
||||
return 0
|
||||
fi
|
||||
|
||||
echo "discard-dist-on-failure: the release build failed, so dist/ WAS" \
|
||||
"REMOVED and no longer exists. A release build that fails has often" \
|
||||
"already emitted a complete, loadable debug bundle — every wallet it" \
|
||||
"creates gets the publicly committed test recovery phrase — so the" \
|
||||
"failed build is not left behind to be loaded. Fix the failure and" \
|
||||
"re-run make build, or run make build-debug if a debug build is what" \
|
||||
"was wanted; that target keeps its output." >&2
|
||||
}
|
||||
|
||||
main() {
|
||||
[ "$#" -ge 1 ] || {
|
||||
usage
|
||||
echo "discard-dist-on-failure: no command given, so no build step ran" \
|
||||
"and nothing was removed." >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
_status=0
|
||||
"$@" || _status=$?
|
||||
|
||||
[ "$_status" -ne 0 ] || return 0
|
||||
|
||||
discard_dist
|
||||
exit "$_status"
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user