fix: harden thothctl diagnostics
This commit is contained in:
Executable
+27
@@ -0,0 +1,27 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
repository_root=$(cd "$(dirname "$0")/.." && pwd)
|
||||
dockerfile="$repository_root/docker/thothctl.Dockerfile"
|
||||
builder_image=$(awk '$1 == "FROM" && $3 == "AS" && $4 == "build" { print $2; exit }' "$dockerfile")
|
||||
|
||||
if [[ ! "$builder_image" =~ ^golang:1\.24@sha256:[0-9a-f]{64}$ ]]; then
|
||||
echo "thothctl builder must use a readable golang:1.24 tag with an immutable digest" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
manifest=$(docker buildx imagetools inspect "$builder_image")
|
||||
printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/amd64'
|
||||
printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/arm64'
|
||||
|
||||
temporary_output=$(mktemp -d)
|
||||
trap 'rm -rf "$temporary_output"' EXIT HUP INT TERM
|
||||
docker build --file "$dockerfile" --output "type=local,dest=$temporary_output" "$repository_root" >/dev/null
|
||||
|
||||
test -s "$temporary_output/thothctl-windows-amd64.exe"
|
||||
test -s "$temporary_output/thothctl-darwin-amd64"
|
||||
test -s "$temporary_output/thothctl-darwin-arm64"
|
||||
test -s "$temporary_output/thothctl-linux-amd64"
|
||||
test -s "$temporary_output/thothctl-linux-arm64"
|
||||
|
||||
echo "thothctl build contract passed."
|
||||
Reference in New Issue
Block a user