Description
The `Flatten artifacts and generate checksums` step in `.github/workflows/release.yml` fails with:
```
mv: cannot overwrite directory './vaultctl-linux-amd64' with non-directory
```
The PyInstaller binary jobs build the artifacts successfully, but the publishing step can't flatten them. As a result, the v1.2.1 release has only Python wheel/tarball assets — no `vaultctl-linux-amd64` / `vaultctl-macos-arm64` / `checksums.sha256`. The README's `curl .../releases/latest/download/vaultctl-linux-amd64` install command currently 404s.
Root Cause
`actions/download-artifact@v4` places each artifact under `binaries//`. Both names are `vaultctl-linux-amd64`, so the structure is:
```
binaries/
├── vaultctl-linux-amd64/
│ └── vaultctl-linux-amd64 (file)
└── vaultctl-macos-arm64/
└── vaultctl-macos-arm64 (file)
```
The flatten loop runs `mv vaultctl-linux-amd64/* .`, which expands to `mv vaultctl-linux-amd64/vaultctl-linux-amd64 .` — destination is the directory itself, hence the conflict.
This bug was latent until v1.2.1: prior releases skipped the binary jobs (semantic-release re-runs flagging `released: false`), so the broken publish step never ran.
Fix
`actions/download-artifact@v4` supports `merge-multiple: true`, which places artifact files directly into the target directory without per-artifact subdirs:
```yaml
- name: Download all artifacts
uses: actions/download-artifact@v4
with:
path: binaries
merge-multiple: true
```
After that change, `binaries/` directly contains the two binaries, and the flatten loop can be removed entirely. Only the checksum generation stays.
Followup
After merging, manually re-run the v1.2.1 release workflow (or wait for the next release) and verify the binaries land. If they do, also add the v1.2.1 binaries to the existing release manually so the README install command works.
Files
- `.github/workflows/release.yml` — `Download all artifacts` and `Flatten artifacts` steps
Priority
P1 — README's install command is broken for the latest release.
Description
The `Flatten artifacts and generate checksums` step in `.github/workflows/release.yml` fails with:
```
mv: cannot overwrite directory './vaultctl-linux-amd64' with non-directory
```
The PyInstaller binary jobs build the artifacts successfully, but the publishing step can't flatten them. As a result, the v1.2.1 release has only Python wheel/tarball assets — no `vaultctl-linux-amd64` / `vaultctl-macos-arm64` / `checksums.sha256`. The README's `curl .../releases/latest/download/vaultctl-linux-amd64` install command currently 404s.
Root Cause
`actions/download-artifact@v4` places each artifact under `binaries//`. Both names are `vaultctl-linux-amd64`, so the structure is:
```
binaries/
├── vaultctl-linux-amd64/
│ └── vaultctl-linux-amd64 (file)
└── vaultctl-macos-arm64/
└── vaultctl-macos-arm64 (file)
```
The flatten loop runs `mv vaultctl-linux-amd64/* .`, which expands to `mv vaultctl-linux-amd64/vaultctl-linux-amd64 .` — destination is the directory itself, hence the conflict.
This bug was latent until v1.2.1: prior releases skipped the binary jobs (semantic-release re-runs flagging `released: false`), so the broken publish step never ran.
Fix
`actions/download-artifact@v4` supports `merge-multiple: true`, which places artifact files directly into the target directory without per-artifact subdirs:
```yaml
uses: actions/download-artifact@v4
with:
path: binaries
merge-multiple: true
```
After that change, `binaries/` directly contains the two binaries, and the flatten loop can be removed entirely. Only the checksum generation stays.
Followup
After merging, manually re-run the v1.2.1 release workflow (or wait for the next release) and verify the binaries land. If they do, also add the v1.2.1 binaries to the existing release manually so the README install command works.
Files
Priority
P1 — README's install command is broken for the latest release.