Skip to content

fix(release): refuse build output in the source archive - #65

Merged
leoisadev1 merged 1 commit into
mainfrom
cursor/source-archive-no-target-b3b2
Oct 7, 2026
Merged

leoisadev1 merged 1 commit into
mainfrom
cursor/source-archive-no-target-b3b2

Conversation

@leoisadev1

@leoisadev1 leoisadev1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

Linux dry run 37607929480 on 9aa85ff compared two independent builds: AppImage, .deb, .rpm, linux tar.gz and source-audit.json were byte-identical. The source tarball was not. compare.py named 2943 differing members, every one under convt-source/target/ (target/.rustc_info.json, target/release/.fingerprint/aho-corasick-…, cc, const-oid). Manifests failed only because they record that tarball hash.

source.py archive() packs the frozen tree after linux-source-scope.py runs cargo build --release in that tree (and after cargo tree / license-map). Those commands write a host target/ next to the sources. The tarball exclude list covered __pycache__ and .cache but not target/, so Cargo output shipped as corresponding source and naturally differed between builds.

#64 already excludes <tree>/target. This PR keeps that exclude, then inspects the packed member list and fails immediately if any Cargo or __pycache__ output is still present. A source archive should never contain target/ regardless of how it got there.

Fixes CNV-44

Evidence

python3 -m unittest discover -s scripts/release -p 'test_*.py' -v
Ran 16 tests in 0.081s
OK
  • The leaked CI paths (convt-source/target/.rustc_info.json, .fingerprint/aho-corasick-…) are classified as build output; src/target.rs is not.
  • Packing a tree that contains target/ and __pycache__ drops both and keeps sources.
  • Two packs of the same tree with different target/ contents are byte-identical.
  • A tarball that still contains target/ raises source archive contains build output (N members): ….
  • CI job Release scripts runs that member-list check on every PR (no 1h45m Linux release run).

Do not cancel Release 37565192300. Eng Convt squash-merges when CI is green and redispatches Build release linux.

Merge Danger

Door: two-way.

Blast radius: Linux source-archive packing (fail-fast if build output leaks). New CI job runs existing scripts/release unit tests plus the member-list guard. Does not change Windows release or published v0.2.0 assets.

Open in Web Open in Cursor 

Devin Review

#64 excluded convt-source/target from the tarball. Pack now inspects
members and fails if Cargo or __pycache__ output is still present, and
CI runs that member-list check in under a second.

Co-authored-by: Leo <leoisadev1@users.noreply.github.com>

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Adds build validation to the release workflow and source archive packing.

The PR appears safe to merge; no actionable defects were found.

What we checked:

  • Build output reaches the archive: pack_source_archive excludes the tree’s top-level target directory. The final check also rejects any remaining member under that directory.

Summary

The PR keeps the existing archive exclusions and adds a final check that rejects leaked Cargo or Python build output.

  • Moves packing into pack_source_archive.
  • Adds tests for excluded files, matching archive hashes, and rejected members.
  • Adds a CI job for the release-script unit tests.

No actionable issues were found. This review inspected code; it did not run the tests.

Reviews (1) · Last reviewed commit: "fix(release): refuse build output in the..." · Reviewed by Greptile

@leoisadev1
leoisadev1 merged commit 985f3f3 into main Oct 7, 2026
10 checks passed
@leoisadev1
leoisadev1 deleted the cursor/source-archive-no-target-b3b2 branch October 7, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants