scripts: use end-of-options marker in cd, mkdir, mv, sha256sum commands

Where missing. To avoid passing an option by accident.

End-of-option marker (`--`) is not POSIX, but most of these scripts are
internal and/or CI-focused, where this is fine. `maketgz` and
`verify-release` are meant for public use, and I asses this is fine too,
but let us know if this causes issues in real world envs.

Also:
- maketgz: pass args with `:?` to `rm -rf`, where missing.
  Cannot cause an actual issue with current code.
- verified `cp`, `rm` instances too, but none were affected.
- tests/cmake/test.sh: replace `$PWD` with `$(pwd)` for sturdiness.
- appveyor.sh: replace `$PWD` with `$(pwd)` for sturdiness.

Assisted-by: Dan Fandrich
Follow-up to 6aab1dc263 #19450

Closes #22150
This commit is contained in:
Viktor Szakats 2026-06-23 23:14:24 +02:00
parent fbcce4da85
commit ccf19d59e7
No known key found for this signature in database
11 changed files with 21 additions and 21 deletions

View file

@ -63,7 +63,7 @@ mkdir -p _tarballs
rm -rf _tarballs/*
# checksum the original tarball to compare with later
sha256sum "$tarball" >_tarballs/checksum
sha256sum -- "$tarball" >_tarballs/checksum
# extract version number from file name
tarver=$(echo "$tarball" | sed 's/curl-\([0-9.]*\)\..*/\1/')
@ -85,7 +85,7 @@ if test "$withgit" = 0; then
tar xf "$tarball"
# move away the original tarball
mv "$tarball" "_tarballs/orig-$tarball"
mv -- "$tarball" "_tarballs/orig-$tarball"
pwd=$(pwd)
cd "curl-$curlver"
@ -101,7 +101,7 @@ else
echo "*** Use git tag $tag"
# move away the original tarball
mv "$tarball" "_tarballs/orig-$tarball"
mv -- "$tarball" "_tarballs/orig-$tarball"
prevtag=$(git symbolic-ref -q --short HEAD || git rev-parse HEAD)
git checkout -f "$tag"