From 2f7b209b62f82cecfb123d0dcc72cd6f85f16749 Mon Sep 17 00:00:00 2001 From: kami Date: Wed, 26 Aug 2026 23:50:02 +0400 Subject: [PATCH] Build stamped binaries in a throwaway worktree of HEAD This checkout is shared with another session. Its uncommitted Go changes must neither be compiled into a binary stamped with a commit revision nor block a deploy, and a dirty-tree refusal does both jobs badly. deploy/build.sh now builds in a detached worktree of the revision it stamps, and the container image is built the same way rather than from the live checkout. Co-Authored-By: Claude Opus 5 --- deploy/build.sh | 26 +++++++++++++++----------- 1 file changed, 15 insertions(+), 11 deletions(-) diff --git a/deploy/build.sh b/deploy/build.sh index aa5c50a..4e8e7aa 100755 --- a/deploy/build.sh +++ b/deploy/build.sh @@ -5,18 +5,22 @@ # worker's registration, which is what makes deployed identity evidence rather # than assumption. # -# Usage: deploy/build.sh [outdir] +# The build runs in a throwaway git worktree of HEAD, not in the checkout. This +# repository is shared: another session may have uncommitted Go changes in it, +# and those must neither be compiled into a stamped binary nor block a deploy. +# +# Usage: deploy/build.sh [outdir] [revision] set -eu -out=${1:-./build} -cd "$(dirname "$0")/.." -if ! git diff --quiet || ! git diff --cached --quiet; then - echo "refusing to stamp a dirty tree with a commit revision" >&2 - exit 1 -fi -rev=$(git rev-parse HEAD) -built=$(git show -s --format=%cI HEAD) +repo=$(cd "$(dirname "$0")/.." && pwd) +out=${1:-$repo/build} +rev=$(git -C "$repo" rev-parse "${2:-HEAD}") +built=$(git -C "$repo" show -s --format=%cI "$rev") +tree=$(mktemp -d) +cleanup() { git -C "$repo" worktree remove --force "$tree" >/dev/null 2>&1 || rm -rf "$tree"; } +trap cleanup EXIT +git -C "$repo" worktree add --detach --quiet "$tree" "$rev" flags="-s -w -X orchestra/internal/buildinfo.Revision=$rev -X orchestra/internal/buildinfo.Time=$built -X orchestra/internal/buildinfo.Dirty=false" mkdir -p "$out" -go build -trimpath -ldflags="$flags" -o "$out/orchestra" ./cmd/orchestra -go build -trimpath -ldflags="$flags" -o "$out/orchestra-worker" ./cmd/orchestra-worker +(cd "$tree" && go build -trimpath -ldflags="$flags" -o "$out/orchestra" ./cmd/orchestra) +(cd "$tree" && go build -trimpath -ldflags="$flags" -o "$out/orchestra-worker" ./cmd/orchestra-worker) echo "$rev"