test(release): strengthen repository verification
This commit is contained in:
+35
-4
@@ -1,15 +1,46 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
# req: distribution/001, distribution/002, distribution/003, distribution/005, distribution/006, distribution/008 test
|
||||
|
||||
root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
||||
ink=$root/channels/main/ink
|
||||
set=$root/channels/main/toolset
|
||||
manifest=$set/ink-toolset-main-x86_64-linux-musl.manifest.tsv
|
||||
tmp=${TMPDIR:-/tmp}/ink-releases-proof.$$
|
||||
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
||||
mkdir -p "$tmp"
|
||||
|
||||
test -f "$root/SPEC.md" && test ! -e "$root/REQUIREMENTS.md" # req: governance/001 test
|
||||
grep -q '`SPEC.md` is the sole current-state authority' "$root/AGENTS.md" # req: governance/002 test
|
||||
grep -q 'update `SPEC.md` before' "$root/AGENTS.md" # req: governance/002 test
|
||||
(cd "$root" && redgate list >/dev/null && redgate refs >/dev/null && redgate lint >/dev/null && redgate check >/dev/null) # req: governance/003 test
|
||||
|
||||
allowed=$(git -C "$root" ls-files | grep -Ev '^(AGENTS.md|LICENSE|README.md|SPEC.md|install.sh|channels/main/(ink|toolset)/|releases/[^/]+/(ink|toolset)/)' || true)
|
||||
test -z "$allowed" # req: distribution/001 test req: distribution/002 test req: distribution/003 test req: distribution/004 test
|
||||
find "$root/channels" "$root/releases" -type f \( -name '*.zig' -o -name 'build.zig' -o -name 'build.zig.zon' \) -print | grep . && exit 1 || : # req: distribution/001 test
|
||||
for identity in "$root"/releases/*; do
|
||||
test -d "$identity" || continue
|
||||
find "$identity" -mindepth 1 -maxdepth 1 -type d -printf '%f\n' | grep -Ev '^(ink|toolset)$' | grep . && exit 1 || : # req: distribution/003 test req: distribution/004 test
|
||||
done
|
||||
|
||||
git clone -q --depth 1 https://git.tmk241.com/tmk241/ink.git "$tmp/ink"
|
||||
git clone -q --depth 1 https://git.tmk241.com/tmk241/ink-toolset.git "$tmp/toolset"
|
||||
for workflow in "$tmp/ink/.gitea/workflows/publish.yml" "$tmp/toolset/.gitea/workflows/publish.yml"; do
|
||||
grep -q 'Runtime proof on Void Linux musl' "$workflow"
|
||||
grep -q 'RELEASE_DEPLOY_KEY' "$workflow"
|
||||
grep -q 'git diff --cached --quiet && exit 0' "$workflow"
|
||||
grep -q 'git pull --rebase origin main && git push origin HEAD:main && exit 0' "$workflow"
|
||||
done # req: distribution/007 test
|
||||
|
||||
if command -v tea >/dev/null 2>&1; then
|
||||
protection=$(tea api -r tmk241/ink-releases '/repos/{owner}/{repo}/branch_protections/main')
|
||||
printf '%s' "$protection" | grep -q '"enable_push_whitelist":true'
|
||||
printf '%s' "$protection" | grep -q '"push_whitelist_deploy_keys":true'
|
||||
printf '%s' "$protection" | grep -q '"push_whitelist_usernames":\[\]' # req: governance/004 test
|
||||
fi
|
||||
|
||||
(cd "$ink" && sha256sum -c ink-SHA256SUMS >/dev/null)
|
||||
(cd "$set" && sha256sum -c ink-toolset-SHA256SUMS >/dev/null)
|
||||
file "$ink/ink-x86_64-linux-musl" | grep -q 'statically linked'
|
||||
file "$ink/ink-x86_64-linux-musl" | grep -q 'statically linked' # req: distribution/005 test
|
||||
|
||||
awk -F '\t' '
|
||||
NR == 1 {
|
||||
@@ -18,7 +49,7 @@ NR == 1 {
|
||||
}
|
||||
$1 != "tmk241/ink-toolset" || $2 !~ /^[0-9a-f]{40}$/ || $5 != "x86_64-linux-musl" || $6 !~ /^[0-9]+$/ || $7 !~ /^[0-9a-f]{64}$/ || $8 == "" { exit 1 }
|
||||
END { if (NR < 2) exit 1 }
|
||||
' "$manifest"
|
||||
' "$manifest" # req: distribution/006 test
|
||||
|
||||
while IFS="$(printf '\t')" read -r source commit name group target bytes digest asset; do
|
||||
[ "$source" = source_repository ] && continue
|
||||
@@ -28,7 +59,7 @@ while IFS="$(printf '\t')" read -r source commit name group target bytes digest
|
||||
file "$set/$asset" | grep -q 'statically linked'
|
||||
done < "$manifest"
|
||||
|
||||
podman run --rm -v "$root/channels/main:/release:ro" ghcr.io/void-linux/void-musl:latest /bin/sh -c '
|
||||
podman run --rm -v "$root/channels/main:/release:ro" ghcr.io/void-linux/void-musl:latest /bin/sh -c ' # req: distribution/008 test
|
||||
set -eu
|
||||
/release/ink/ink-x86_64-linux-musl --help >/dev/null
|
||||
count=0
|
||||
|
||||
Reference in New Issue
Block a user