72 lines
3.6 KiB
Bash
Executable File
72 lines
3.6 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
|
ink=$root/channels/main/ink
|
|
set=$root/channels/main/toolset
|
|
manifest=$set/ink-toolset-main-x86_64-linux-musl.manifest.tsv
|
|
tmp=${TMPDIR:-/tmp}/ink-releases-proof.$$
|
|
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
|
mkdir -p "$tmp"
|
|
|
|
test -f "$root/SPEC.md" && test ! -e "$root/REQUIREMENTS.md" # req: governance/001 test
|
|
grep -q '`SPEC.md` is the sole current-state authority' "$root/AGENTS.md" # req: governance/002 test
|
|
grep -q 'update `SPEC.md` before' "$root/AGENTS.md" # req: governance/002 test
|
|
(cd "$root" && redgate list >/dev/null && redgate refs >/dev/null && redgate lint >/dev/null && redgate check >/dev/null) # req: governance/003 test
|
|
|
|
allowed=$(git -C "$root" ls-files | grep -Ev '^(AGENTS.md|LICENSE|README.md|SPEC.md|install.sh|channels/main/(ink|toolset)/|releases/[^/]+/(ink|toolset)/)' || true)
|
|
test -z "$allowed" # req: distribution/001 test req: distribution/002 test req: distribution/003 test req: distribution/004 test
|
|
find "$root/channels" "$root/releases" -type f \( -name '*.zig' -o -name 'build.zig' -o -name 'build.zig.zon' \) -print | grep . && exit 1 || : # req: distribution/001 test
|
|
for identity in "$root"/releases/*; do
|
|
test -d "$identity" || continue
|
|
find "$identity" -mindepth 1 -maxdepth 1 -type d -printf '%f\n' | grep -Ev '^(ink|toolset)$' | grep . && exit 1 || : # req: distribution/003 test req: distribution/004 test
|
|
done
|
|
|
|
git clone -q --depth 1 https://git.tmk241.com/tmk241/ink.git "$tmp/ink"
|
|
git clone -q --depth 1 https://git.tmk241.com/tmk241/ink-toolset.git "$tmp/toolset"
|
|
for workflow in "$tmp/ink/.gitea/workflows/publish.yml" "$tmp/toolset/.gitea/workflows/publish.yml"; do
|
|
grep -q 'Runtime proof on Void Linux musl' "$workflow"
|
|
grep -q 'RELEASE_DEPLOY_KEY' "$workflow"
|
|
grep -q 'git diff --cached --quiet && exit 0' "$workflow"
|
|
grep -q 'git pull --rebase origin main && git push origin HEAD:main && exit 0' "$workflow"
|
|
done # req: distribution/007 test
|
|
|
|
if command -v tea >/dev/null 2>&1; then
|
|
protection=$(tea api -r tmk241/ink-releases '/repos/{owner}/{repo}/branch_protections/main')
|
|
printf '%s' "$protection" | grep -q '"enable_push_whitelist":true'
|
|
printf '%s' "$protection" | grep -q '"push_whitelist_deploy_keys":true'
|
|
printf '%s' "$protection" | grep -q '"push_whitelist_usernames":\[\]' # req: governance/004 test
|
|
fi
|
|
|
|
(cd "$ink" && sha256sum -c ink-SHA256SUMS >/dev/null)
|
|
(cd "$set" && sha256sum -c ink-toolset-SHA256SUMS >/dev/null)
|
|
file "$ink/ink-x86_64-linux-musl" | grep -q 'statically linked' # req: distribution/005 test
|
|
|
|
awk -F '\t' '
|
|
NR == 1 {
|
|
if ($0 != "source_repository\tsource_commit\texecutable\tset\ttarget\tbytes\tsha256\tasset") exit 1
|
|
next
|
|
}
|
|
$1 != "tmk241/ink-toolset" || $2 !~ /^[0-9a-f]{40}$/ || $5 != "x86_64-linux-musl" || $6 !~ /^[0-9]+$/ || $7 !~ /^[0-9a-f]{64}$/ || $8 == "" { exit 1 }
|
|
END { if (NR < 2) exit 1 }
|
|
' "$manifest" # req: distribution/006 test
|
|
|
|
while IFS="$(printf '\t')" read -r source commit name group target bytes digest asset; do
|
|
[ "$source" = source_repository ] && continue
|
|
[ -f "$set/$asset" ]
|
|
[ "$(wc -c < "$set/$asset" | tr -d ' ')" = "$bytes" ]
|
|
[ "$(sha256sum "$set/$asset" | cut -d ' ' -f 1)" = "$digest" ]
|
|
file "$set/$asset" | grep -q 'statically linked'
|
|
done < "$manifest"
|
|
|
|
podman run --rm -v "$root/channels/main:/release:ro" ghcr.io/void-linux/void-musl:latest /bin/sh -c ' # req: distribution/008 test
|
|
set -eu
|
|
/release/ink/ink-x86_64-linux-musl --help >/dev/null
|
|
count=0
|
|
for asset in /release/toolset/*-x86_64-linux-musl; do
|
|
"$asset" --help >/dev/null
|
|
count=$((count+1))
|
|
done
|
|
[ "$count" -gt 0 ]
|
|
'
|