Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/scripts/nfpm/build-client-packages.sh
Original file line number Diff line number Diff line change
Expand Up @@ -544,6 +544,11 @@ verify_rpm() {
local metadata="$WORK_DIR/rpm.metadata-$BIN_NAME"

[[ -f "$pkg" ]] || { echo "missing RPM output: $pkg" >&2; exit 1; }
# The payload extraction below runs from inside $tmp, so a relative
# package path would resolve against it and report the package as
# missing seconds after nFPM created it (seal run 36171579110). Anchor
# the path before any cd, exactly as docker_rpm_tool already does.
pkg="$(realpath "$pkg")"
mkdir -p "$tmp"
: > "$metadata"

Expand Down
4 changes: 4 additions & 0 deletions .github/scripts/nfpm/tests/test_client_nfpm_native.sh
Original file line number Diff line number Diff line change
Expand Up @@ -228,6 +228,10 @@ inspect_rpm() {
metadata="$extract.metadata"
expected_sha="$(sha256sum "$binary" | awk '{print $1}')"
mkdir -p "$extract"
# The extraction below runs from inside $extract; anchor the package
# path so a relative $rpm_pkg cannot resolve against it (callers pass
# absolute paths today; this keeps that a guarantee, not an accident).
rpm_pkg="$(realpath "$rpm_pkg")"

if command -v rpm2cpio >/dev/null 2>&1 && command -v rpm >/dev/null 2>&1 && command -v cpio >/dev/null 2>&1; then
# --no-absolute-filenames keeps absolute RPM payload member names
Expand Down
Loading