From 7f8dd6329139130b5730701527206ed909a1465a Mon Sep 17 00:00:00 2001 From: Alex Date: Fri, 25 Sep 2026 19:54:13 +0100 Subject: [PATCH] fix(release): anchor RPM package paths before extraction cd Seal run 36171579110: the managed-package lifecycle gates passed (the previous rpm2cpio payload-judgement fix worked), which let the "Build managed DEB/RPM packages" step run for the first time - and it failed with "RPM payload extraction produced no terraphim-agent" seconds after nFPM created the file. Root cause: verify_rpm's host branch extracts with `cd "$tmp" && rpm2cpio "$pkg"`, and the workflow invokes the producer with a relative --out-dir, so the relative package path resolved inside $tmp and rpm2cpio reported the package as missing. docker_rpm_tool already anchored its path with realpath; the host branch now does the same, and inspect_rpm in the native gate anchors its package path for the same guarantee. Verified locally against the exact production invocation shape (producer + relative --out-dir): pre-fix reproduces the hosted ENOENT failure byte-for-byte; post-fix the producer passes end-to-end (DEB and RPM for both binaries, host rpm2cpio extraction, docker lintian/rpmlint policies, inventory assembly, atomic publish rename). Wrong-arch, REQUIRE_INSTALL policy, canonical-input strip, and inspect_rpm repro suites all green. Refs #337 --- .github/scripts/nfpm/build-client-packages.sh | 5 +++++ .github/scripts/nfpm/tests/test_client_nfpm_native.sh | 4 ++++ 2 files changed, 9 insertions(+) diff --git a/.github/scripts/nfpm/build-client-packages.sh b/.github/scripts/nfpm/build-client-packages.sh index 5088861..95c275e 100755 --- a/.github/scripts/nfpm/build-client-packages.sh +++ b/.github/scripts/nfpm/build-client-packages.sh @@ -544,6 +544,11 @@ verify_rpm() { local metadata="$WORK_DIR/rpm.metadata-$BIN_NAME" [[ -f "$pkg" ]] || { echo "missing RPM output: $pkg" >&2; exit 1; } + # The payload extraction below runs from inside $tmp, so a relative + # package path would resolve against it and report the package as + # missing seconds after nFPM created it (seal run 36171579110). Anchor + # the path before any cd, exactly as docker_rpm_tool already does. + pkg="$(realpath "$pkg")" mkdir -p "$tmp" : > "$metadata" diff --git a/.github/scripts/nfpm/tests/test_client_nfpm_native.sh b/.github/scripts/nfpm/tests/test_client_nfpm_native.sh index 03aec0e..1673420 100755 --- a/.github/scripts/nfpm/tests/test_client_nfpm_native.sh +++ b/.github/scripts/nfpm/tests/test_client_nfpm_native.sh @@ -228,6 +228,10 @@ inspect_rpm() { metadata="$extract.metadata" expected_sha="$(sha256sum "$binary" | awk '{print $1}')" mkdir -p "$extract" + # The extraction below runs from inside $extract; anchor the package + # path so a relative $rpm_pkg cannot resolve against it (callers pass + # absolute paths today; this keeps that a guarantee, not an accident). + rpm_pkg="$(realpath "$rpm_pkg")" if command -v rpm2cpio >/dev/null 2>&1 && command -v rpm >/dev/null 2>&1 && command -v cpio >/dev/null 2>&1; then # --no-absolute-filenames keeps absolute RPM payload member names