fix: keep a packed file's executable bit

Pinning every member's metadata made packs reproducible and took the
executable bit with it. The RetroDECK pack ships the two Voxatron engine
binaries, and extracted at 644 they cannot be run.

Git records the bit, so reading it from the source file keeps a pack the
same from any clone. Nothing else about the source's mode reaches the
archive: 2569 members ship at 644 and 942 at 755, which is what the
builder produced before the pinning.

Nothing caught this. The comparison that proved the pinning inert
checked member names, CRCs and sizes, and mode is none of those. A test
now builds a runnable payload and asserts it survives extraction.

RetroDECK rebuilds to the same bytes twice and passes its integrity
check, 2008/2008 baseline and 1551/1551 cores.
This commit is contained in:
Abdessamad Derraz committed 2026-08-23 07:58:23 +02:00
1 parent 593b277bc4
commit 8b404e500f
3 files changed
+72 -2

No files matched your search

+9 -2
View File
@@ -94,8 +94,15 @@ def _add_pack_member(zf: zipfile.ZipFile, source_path: str, arcname: str) -> Non
"""
info = zipfile.ZipInfo(filename=arcname, date_time=_FIXED_DATE_TIME)
info.compress_type = zipfile.ZIP_DEFLATED
info.external_attr = 0o100644 << 16
size = os.path.getsize(source_path)
# The executable bit is the one permission worth carrying: the RetroDECK
# pack ships the two Voxatron engine binaries, and a user who extracts
# them at 644 cannot run them. Git records the bit, so reading it from
# the source keeps the pack the same from any clone. Nothing else about
# the source's mode reaches the archive.
stat_result = os.stat(source_path)
mode = 0o755 if stat_result.st_mode & 0o111 else 0o644
info.external_attr = (0o100000 | mode) << 16
size = stat_result.st_size
info.file_size = size
with open(source_path, "rb") as source, zf.open(
info, "w", force_zip64=size >= 1 << 31