Conversation
a26609d to
8eb792c
Compare
Co-Authored-By: Claude <noreply@anthropic.com>
8eb792c to
e613925
Compare
ValidationmacOS arm64, goreleaser v2.18.2, Homebrew 7.0.4, quarantine not disabled ( The
|
Arg in .goreleaser.yaml |
Result |
|---|---|
"{{ "{{staged_path}}" }}" (this PR) |
emits "{{staged_path}}" |
"{{staged_path}}" |
release fails: function "staged_path" not defined |
"{{ .StagedPath }}" |
release fails: map has no entry for key "StagedPath" |
Row 2 shows the escape is required, not cosmetic. Row 3 confirms the field #6873 adds does not exist on the pinned ~> v2. Both failures print the pass-2 input containing GoReleaser's own unevaluated desc {{ "…" }}, which is the same escaping trick applied to the same pass.
Generated stanza
cask "lstk" do
postflight_steps do
on_macos do
run "/usr/bin/xattr", args: ["-dr", "com.apple.quarantine", "{{staged_path}}"]
end
endInstall
Generated cask pointed at the published v1.1.0 archives — only version and sha256 substituted, and the arm64 sha matches the published tap cask — then installed from a throwaway local tap:
| Cask | Deprecation warning | Quarantine on staged lstk |
lstk --version |
|---|---|---|---|
Published (postflight) |
3× | cleared | lstk 1.1.0 |
| Control, hook removed | none | present | (no output — killed) |
This PR (postflight_steps) |
none | cleared | lstk 1.1.0 |
The control confirms the step is load-bearing: without it Gatekeeper kills the binary. -dr also recurses as #477 intends — across all 43 staged files the control leaves every one quarantined, and this PR leaves every one clear.
brew style in tap layout: 1 Cask/InstallSteps before, 12 Cask/StanzaOrder after, matching the trade-off described above.
Two follow-ups for #511
- Assert exactly one
postflight_steps. Homebrew silently loads two and runs both, so addinghooks.post.install_stepson v2.19 without droppingcustom_blockwould pass the current check. - Pipe the rendered cask through
ruby -c.custom_blockis unvalidated raw Ruby, so a syntax error would otherwise surface at install time.
Motivation
Every
brewoperation that loadslocalstack/tap/lstktells the user to file a bug against our tap:Homebrew 7.0 deprecated the raw-Ruby flight blocks (Homebrew/brew#23366), and
hooks.post.installrenders into one. Reported as localstack/homebrew-tap#7, and still present on the published 1.1.0 cask.Solution
The replacement option,
hooks.post.install_steps, arrives in GoReleaser v2.19 (goreleaser/goreleaser#6873, still open). On the pinned~> v2it fails outright:So
custom_blockwrites the stanza instead, escaping{{staged_path}}past GoReleaser's template pass. The step still clears quarantine on the whole staged dir, as #477 made it, so the bundled-extensions binary besidelstkkeeps running:On goreleaser v2.18.2 and Homebrew 7.0.4 the cask loads as
Cask::Artifact::PostflightSteps, prints no warning, and serializes the step with itson_macosguard.One cost:
custom_blockrenders first in the cask, sobrew stylereports 12Cask/StanzaOrderoffences in place of 1Cask/InstallSteps. Nothing gates on that — the tap has no CI, andbrew installnever runs rubocop. Moving back underhookson v2.19 drops both the offences and the escape.#511 adds a CI guard so this cannot silently regress. It stacks on this branch, since the check fails against
main.Docs
Nothing to document. lstk's commands, flags, env vars and output are unchanged. Users see one difference:
brew install --cask localstack/tap/lstkstops printing a deprecation warning. The cask itself is generated and carries a DO-NOT-EDIT header.Review
Human review advised: this changes the published cask's structure and takes a different route than DEVX-1124 proposed.
Todo
hooks.post.install_stepson GoReleaser v2.19 (feat(cask): add hooks install_steps, deprecate raw Ruby hooks goreleaser/goreleaser#6873)Towards DEVX-1124
🤖 Generated with Claude Code