#!/usr/bin/env bash set -euo pipefail repository_root=$(cd "$(dirname "$0")/.." && pwd) dockerfile="$repository_root/docker/thothctl.Dockerfile" builder_image=$(awk '$1 == "FROM" && $3 == "AS" && $4 == "build" { print $2; exit }' "$dockerfile") if [[ ! "$builder_image" =~ ^golang:1\.24@sha256:[0-9a-f]{64}$ ]]; then echo "thothctl builder must use a readable golang:1.24 tag with an immutable digest" >&2 exit 1 fi manifest=$(docker buildx imagetools inspect "$builder_image") printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/amd64' printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/arm64' temporary_output=$(mktemp -d) trap 'rm -rf "$temporary_output"' EXIT HUP INT TERM docker build --file "$dockerfile" --output "type=local,dest=$temporary_output" "$repository_root" >/dev/null test -s "$temporary_output/thothctl-windows-amd64.exe" test -s "$temporary_output/thothctl-darwin-amd64" test -s "$temporary_output/thothctl-darwin-arm64" test -s "$temporary_output/thothctl-linux-amd64" test -s "$temporary_output/thothctl-linux-arm64" echo "thothctl build contract passed."