Files
ThothII/scripts/build-dwh-auth.sh
Codex eba6148511 test: stabilize pre-deployment gates
Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
2026-09-04 16:15:35 +02:00

92 lines
2.1 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
default_output="$repo_root/dist/dwh-auth"
output="$default_output"
usage() {
echo "usage: $0 [--output ABS_CANONICAL]" >&2
exit 2
}
while (($#)); do
case "$1" in
--output)
(($# >= 2)) || usage
output=$2
shift 2
;;
--help|-h)
usage
;;
*)
usage
;;
esac
done
case "$output" in
/*) ;;
*)
echo "build-dwh-auth: output must be an absolute canonical directory" >&2
exit 2
;;
esac
[[ "$output" != */../* && "$output" != */.. && "$output" != *'/./'* && "$output" != */. ]] || {
echo "build-dwh-auth: output must be canonical" >&2
exit 2
}
if [[ "$output" == / || "$output" == "$repo_root" || "$output" == /tmp || "$output" == /var || "$output" == /home ]]; then
echo "build-dwh-auth: refusing broad output path" >&2
exit 2
fi
parent=$(dirname "$output")
if [[ "$output" == "$default_output" && ! -e "$parent" ]]; then
mkdir -p "$parent"
fi
[[ -d "$parent" && ! -L "$parent" ]] || {
echo "build-dwh-auth: output parent must be an existing non-symlink directory" >&2
exit 2
}
leaf=$(basename "$output")
canonical_parent=$(cd "$parent" && pwd -P)
[[ "${canonical_parent%/}/$leaf" == "$output" ]] || {
echo "build-dwh-auth: output must be canonical" >&2
exit 2
}
if [[ -e "$output" || -L "$output" ]]; then
[[ -d "$output" && ! -L "$output" ]] || {
echo "build-dwh-auth: output exists and is not a directory" >&2
exit 2
}
if [[ -n "$(find "$output" -mindepth 1 -maxdepth 1 -print -quit)" ]]; then
echo "build-dwh-auth: refusing non-empty output directory" >&2
exit 2
fi
else
mkdir "$output"
fi
command -v docker >/dev/null 2>&1 || {
echo "build-dwh-auth: Docker is required for the pinned build" >&2
exit 1
}
docker build \
--file "$repo_root/docker/dwh-auth.Dockerfile" \
--output "type=local,dest=$output" \
"$repo_root"
for arch in amd64 arm64; do
artifact="$output/dwh-auth-linux-$arch"
[[ -s "$artifact" ]] || {
echo "build-dwh-auth: builder did not produce $artifact" >&2
exit 1
}
done