Require reproducible production deploy sources
This commit is contained in:
@@ -123,6 +123,7 @@ ensure_local_deploy_dirs() {
|
||||
# metadata fast: short SHA/branch always; unstaged dirty scans are skipped on
|
||||
# slow filesystems and otherwise hard-timeout'd.
|
||||
git_metadata_timeout_seconds="${GIT_METADATA_TIMEOUT_SECONDS:-8}"
|
||||
clean_git_timeout_seconds="${CLEAN_GIT_TIMEOUT_SECONDS:-60}"
|
||||
|
||||
git_workdir_is_slow() {
|
||||
case "$local_folder" in
|
||||
@@ -192,6 +193,65 @@ detect_git_dirty_fast() {
|
||||
return 2
|
||||
}
|
||||
|
||||
deploy_path_is_rsync_excluded() {
|
||||
local path="${1#./}"
|
||||
path="${path%/}"
|
||||
|
||||
case "$path" in
|
||||
.git|.git/*|.deploy|.deploy/*|.cursor|.cursor/*|.venv|.venv/*|.vscode|.vscode/*|node_modules|node_modules/*|vendor|vendor/*|storage|storage/*|tests|tests/*|playwright-report|playwright-report/*|test-results|test-results/*|public/build|public/build/*|public/files|public/files/*|public/storage|public/storage/*|resources/lang|resources/lang/*|bootstrap/cache|bootstrap/cache/*|var/deploy|var/deploy/*|var/php-tmp|var/php-tmp/*|var/php-sessions|var/php-sessions/*|.cache|.cache/*|.config|.config/*|.composer|.composer/*|.npm|.npm/*|.local|.local/*|.copilot|.copilot/*|oldSite|oldSite/*|.phpintel|.phpintel/*)
|
||||
return 0
|
||||
;;
|
||||
public/hot|public/sitemap.xml|public/sitemaps/*|.env|.env.*|.phpunit.result.cache)
|
||||
return 0
|
||||
;;
|
||||
*)
|
||||
return 1
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
# Returns: 0 deployable changes, 1 no deployable changes, 2 unable to prove.
|
||||
# Unlike detect_git_dirty_fast(), this is intentionally conservative: a
|
||||
# production clean-git gate must inspect untracked files and may not silently
|
||||
# skip the worktree scan on WSL/network filesystems.
|
||||
detect_deployable_git_dirty() {
|
||||
local status_output=""
|
||||
local rc=0
|
||||
local line=""
|
||||
local status_code=""
|
||||
local path=""
|
||||
|
||||
run_git_with_timeout "$clean_git_timeout_seconds" diff --cached --quiet >/dev/null 2>&1 || rc=$?
|
||||
if [[ "$rc" -eq 1 ]]; then
|
||||
return 0
|
||||
fi
|
||||
if [[ "$rc" -ne 0 ]]; then
|
||||
return 2
|
||||
fi
|
||||
|
||||
rc=0
|
||||
status_output="$(run_git_with_timeout "$clean_git_timeout_seconds" -c core.untrackedCache=false status --porcelain=v1 --untracked-files=all 2>/dev/null)" || rc=$?
|
||||
if [[ "$rc" -ne 0 ]]; then
|
||||
return 2
|
||||
fi
|
||||
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] || continue
|
||||
status_code="${line:0:2}"
|
||||
path="${line:3}"
|
||||
|
||||
# Untracked files in paths excluded by the deployment rsync are not
|
||||
# deployable. Tracked changes remain dirty even when their path is
|
||||
# excluded, so accidental edits cannot be hidden by this allowance.
|
||||
if [[ "$status_code" == "??" ]] && deploy_path_is_rsync_excluded "$path"; then
|
||||
continue
|
||||
fi
|
||||
return 0
|
||||
done <<< "$status_output"
|
||||
|
||||
return 1
|
||||
}
|
||||
|
||||
collect_git_metadata() {
|
||||
local dirty_rc=1
|
||||
|
||||
|
||||
Reference in New Issue
Block a user