#!/bin/sh set -eu root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd) ink=$root/channels/main/ink set=$root/channels/main/toolset manifest=$set/ink-toolset-main-x86_64-linux-musl.manifest.tsv tmp=${TMPDIR:-/tmp}/ink-releases-proof.$$ trap 'rm -rf "$tmp"' EXIT HUP INT TERM mkdir -p "$tmp" test -f "$root/SPEC.md" && test ! -e "$root/REQUIREMENTS.md" # req: governance/001 test grep -q '`SPEC.md` is the sole current-state authority' "$root/AGENTS.md" # req: governance/002 test grep -q 'update `SPEC.md` before' "$root/AGENTS.md" # req: governance/002 test (cd "$root" && redgate list >/dev/null && redgate refs >/dev/null && redgate lint >/dev/null && redgate check >/dev/null) # req: governance/003 test allowed=$(git -C "$root" ls-files | grep -Ev '^(AGENTS.md|LICENSE|README.md|SPEC.md|install.sh|channels/main/(ink|toolset)/|releases/[^/]+/(ink|toolset)/)' || true) test -z "$allowed" # req: distribution/001 test req: distribution/002 test req: distribution/003 test req: distribution/004 test find "$root/channels" "$root/releases" -type f \( -name '*.zig' -o -name 'build.zig' -o -name 'build.zig.zon' \) -print | grep . && exit 1 || : # req: distribution/001 test for identity in "$root"/releases/*; do test -d "$identity" || continue find "$identity" -mindepth 1 -maxdepth 1 -type d -printf '%f\n' | grep -Ev '^(ink|toolset)$' | grep . && exit 1 || : # req: distribution/003 test req: distribution/004 test done git clone -q --depth 1 https://git.tmk241.com/tmk241/ink.git "$tmp/ink" git clone -q --depth 1 https://git.tmk241.com/tmk241/ink-toolset.git "$tmp/toolset" for workflow in "$tmp/ink/.gitea/workflows/publish.yml" "$tmp/toolset/.gitea/workflows/publish.yml"; do grep -q 'Runtime proof on Void Linux musl' "$workflow" grep -q 'RELEASE_DEPLOY_KEY' "$workflow" grep -q 'git diff --cached --quiet && exit 0' "$workflow" grep -q 'git pull --rebase origin main && git push origin HEAD:main && exit 0' "$workflow" done # req: distribution/007 test if command -v tea >/dev/null 2>&1; then protection=$(tea api -r tmk241/ink-releases '/repos/{owner}/{repo}/branch_protections/main') printf '%s' "$protection" | grep -q '"enable_push_whitelist":true' printf '%s' "$protection" | grep -q '"push_whitelist_deploy_keys":true' printf '%s' "$protection" | grep -q '"push_whitelist_usernames":\[\]' # req: governance/004 test fi (cd "$ink" && sha256sum -c ink-SHA256SUMS >/dev/null) (cd "$set" && sha256sum -c ink-toolset-SHA256SUMS >/dev/null) file "$ink/ink-x86_64-linux-musl" | grep -q 'statically linked' # req: distribution/005 test awk -F '\t' ' NR == 1 { if ($0 != "source_repository\tsource_commit\texecutable\tset\ttarget\tbytes\tsha256\tasset") exit 1 next } $1 != "tmk241/ink-toolset" || $2 !~ /^[0-9a-f]{40}$/ || $5 != "x86_64-linux-musl" || $6 !~ /^[0-9]+$/ || $7 !~ /^[0-9a-f]{64}$/ || $8 == "" { exit 1 } END { if (NR < 2) exit 1 } ' "$manifest" # req: distribution/006 test while IFS="$(printf '\t')" read -r source commit name group target bytes digest asset; do [ "$source" = source_repository ] && continue [ -f "$set/$asset" ] [ "$(wc -c < "$set/$asset" | tr -d ' ')" = "$bytes" ] [ "$(sha256sum "$set/$asset" | cut -d ' ' -f 1)" = "$digest" ] file "$set/$asset" | grep -q 'statically linked' done < "$manifest" podman run --rm -v "$root/channels/main:/release:ro" ghcr.io/void-linux/void-musl:latest /bin/sh -c ' # req: distribution/008 test set -eu /release/ink/ink-x86_64-linux-musl --help >/dev/null count=0 for asset in /release/toolset/*-x86_64-linux-musl; do "$asset" --help >/dev/null count=$((count+1)) done [ "$count" -gt 0 ] '