Require reproducible production deploy sources

This commit is contained in:
test
2026-08-30 09:33:36 +02:00
parent 7c38ffff57
commit 6a6900435c
3 changed files with 210 additions and 27 deletions
+60
View File
@@ -123,6 +123,7 @@ ensure_local_deploy_dirs() {
# metadata fast: short SHA/branch always; unstaged dirty scans are skipped on
# slow filesystems and otherwise hard-timeout'd.
git_metadata_timeout_seconds="${GIT_METADATA_TIMEOUT_SECONDS:-8}"
clean_git_timeout_seconds="${CLEAN_GIT_TIMEOUT_SECONDS:-60}"
git_workdir_is_slow() {
case "$local_folder" in
@@ -192,6 +193,65 @@ detect_git_dirty_fast() {
return 2
}
deploy_path_is_rsync_excluded() {
local path="${1#./}"
path="${path%/}"
case "$path" in
.git|.git/*|.deploy|.deploy/*|.cursor|.cursor/*|.venv|.venv/*|.vscode|.vscode/*|node_modules|node_modules/*|vendor|vendor/*|storage|storage/*|tests|tests/*|playwright-report|playwright-report/*|test-results|test-results/*|public/build|public/build/*|public/files|public/files/*|public/storage|public/storage/*|resources/lang|resources/lang/*|bootstrap/cache|bootstrap/cache/*|var/deploy|var/deploy/*|var/php-tmp|var/php-tmp/*|var/php-sessions|var/php-sessions/*|.cache|.cache/*|.config|.config/*|.composer|.composer/*|.npm|.npm/*|.local|.local/*|.copilot|.copilot/*|oldSite|oldSite/*|.phpintel|.phpintel/*)
return 0
;;
public/hot|public/sitemap.xml|public/sitemaps/*|.env|.env.*|.phpunit.result.cache)
return 0
;;
*)
return 1
;;
esac
}
# Returns: 0 deployable changes, 1 no deployable changes, 2 unable to prove.
# Unlike detect_git_dirty_fast(), this is intentionally conservative: a
# production clean-git gate must inspect untracked files and may not silently
# skip the worktree scan on WSL/network filesystems.
detect_deployable_git_dirty() {
local status_output=""
local rc=0
local line=""
local status_code=""
local path=""
run_git_with_timeout "$clean_git_timeout_seconds" diff --cached --quiet >/dev/null 2>&1 || rc=$?
if [[ "$rc" -eq 1 ]]; then
return 0
fi
if [[ "$rc" -ne 0 ]]; then
return 2
fi
rc=0
status_output="$(run_git_with_timeout "$clean_git_timeout_seconds" -c core.untrackedCache=false status --porcelain=v1 --untracked-files=all 2>/dev/null)" || rc=$?
if [[ "$rc" -ne 0 ]]; then
return 2
fi
while IFS= read -r line; do
[[ -n "$line" ]] || continue
status_code="${line:0:2}"
path="${line:3}"
# Untracked files in paths excluded by the deployment rsync are not
# deployable. Tracked changes remain dirty even when their path is
# excluded, so accidental edits cannot be hidden by this allowance.
if [[ "$status_code" == "??" ]] && deploy_path_is_rsync_excluded "$path"; then
continue
fi
return 0
done <<< "$status_output"
return 1
}
collect_git_metadata() {
local dirty_rc=1