Files
玉澜 f37bb1cee6 fix(release): validate every universal slice in the Darwin SG_READ_ONLY gate
Review on #1446 flagged that the publication gate parsed only the first
__DATA_CONST flags word of an otool -l capture, so a universal library
with a healthy first slice and a broken later slice would still ship.
Replace the inline one-shot awk with scripts/release/extract-data-const-
flags.awk, a state machine that emits one flags word per __DATA_CONST
segment in every slice (segname is only honored directly after cmdsize,
so section entries can never contribute), and fail closed if any entry
lacks SG_READ_ONLY.

Add a regression test driven by real otool captures: broken/healthy
v1.0.62 thin binaries, the vendored universal runtime dylib, and a
universal sample whose last slice is broken — the exact case the old
parser wrongly passed. Also remove MACOSX_DEPLOYMENT_TARGET from the
--exec ambient pass-through so the container always receives the single
unconditional 11.0 pin from compiler_env.
2026-09-23 16:49:05 +08:00

19 lines
717 B
Awk

# Print the flags word of every LC_SEGMENT_64 named __DATA_CONST found in
# `otool -l` output, one per line, across every slice of a universal binary.
#
# A segname line is only honored when it directly follows a cmdsize line, so
# section entries (sectname/segname pairs without a preceding cmdsize) can
# never contribute a flags word. Each captured segment resets its state after
# the flags line for the same reason.
$1 == "cmd" { is_data_const = 0 }
$1 == "cmdsize" { expect_segname = 1; next }
expect_segname && $1 == "segname" {
expect_segname = 0
if ($2 == "__DATA_CONST") {
is_data_const = 1
}
next
}
expect_segname { expect_segname = 0 }
is_data_const && $1 == "flags" { print $2; is_data_const = 0 }