diff --git a/.github/scripts/nfpm/build-client-packages.sh b/.github/scripts/nfpm/build-client-packages.sh index 5088861..95c275e 100755 --- a/.github/scripts/nfpm/build-client-packages.sh +++ b/.github/scripts/nfpm/build-client-packages.sh @@ -544,6 +544,11 @@ verify_rpm() { local metadata="$WORK_DIR/rpm.metadata-$BIN_NAME" [[ -f "$pkg" ]] || { echo "missing RPM output: $pkg" >&2; exit 1; } + # The payload extraction below runs from inside $tmp, so a relative + # package path would resolve against it and report the package as + # missing seconds after nFPM created it (seal run 36171579110). Anchor + # the path before any cd, exactly as docker_rpm_tool already does. + pkg="$(realpath "$pkg")" mkdir -p "$tmp" : > "$metadata" diff --git a/.github/scripts/nfpm/tests/test_client_nfpm_native.sh b/.github/scripts/nfpm/tests/test_client_nfpm_native.sh index 03aec0e..1673420 100755 --- a/.github/scripts/nfpm/tests/test_client_nfpm_native.sh +++ b/.github/scripts/nfpm/tests/test_client_nfpm_native.sh @@ -228,6 +228,10 @@ inspect_rpm() { metadata="$extract.metadata" expected_sha="$(sha256sum "$binary" | awk '{print $1}')" mkdir -p "$extract" + # The extraction below runs from inside $extract; anchor the package + # path so a relative $rpm_pkg cannot resolve against it (callers pass + # absolute paths today; this keeps that a guarantee, not an accident). + rpm_pkg="$(realpath "$rpm_pkg")" if command -v rpm2cpio >/dev/null 2>&1 && command -v rpm >/dev/null 2>&1 && command -v cpio >/dev/null 2>&1; then # --no-absolute-filenames keeps absolute RPM payload member names