#!/usr/bin/env bash set -euo pipefail repository_root=$(cd "$(dirname "$0")/.." && pwd) dockerfile="$repository_root/docker/tht.Dockerfile" builder_image=$(awk '$1 == "FROM" && $3 == "AS" && $4 == "build" { print $2; exit }' "$dockerfile") expected_builder='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651' if [[ "$builder_image" != "$expected_builder" ]]; then echo "tht builder must pin golang:1.26.5-bookworm by the approved multi-platform digest" >&2 exit 1 fi grep -qx 'go 1.26.0' "$repository_root/tools/tht/go.mod" grep -qx 'toolchain go1.26.5' "$repository_root/tools/tht/go.mod" grep -Eq '^[[:space:]]*github.com/sirupsen/logrus v1\.9\.1$' "$repository_root/tools/tht/go.mod" grep -Eq '^[[:space:]]*golang.org/x/sys v0\.47\.0$' "$repository_root/tools/tht/go.mod" manifest=$(docker buildx imagetools inspect "$builder_image") printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/amd64' printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/arm64' temporary_output=$(mktemp -d) trap 'rm -rf "$temporary_output"' EXIT HUP INT TERM docker build --file "$dockerfile" --output "type=local,dest=$temporary_output" "$repository_root" >/dev/null test -s "$temporary_output/tht-windows-amd64.exe" test -s "$temporary_output/tht-darwin-amd64" test -s "$temporary_output/tht-darwin-arm64" test -s "$temporary_output/tht-linux-amd64" test -s "$temporary_output/tht-linux-arm64" echo "tht build contract passed."