Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
92 lines
2.1 KiB
Bash
Executable File
92 lines
2.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
|
|
default_output="$repo_root/dist/dwh-auth"
|
|
output="$default_output"
|
|
|
|
usage() {
|
|
echo "usage: $0 [--output ABS_CANONICAL]" >&2
|
|
exit 2
|
|
}
|
|
|
|
while (($#)); do
|
|
case "$1" in
|
|
--output)
|
|
(($# >= 2)) || usage
|
|
output=$2
|
|
shift 2
|
|
;;
|
|
--help|-h)
|
|
usage
|
|
;;
|
|
*)
|
|
usage
|
|
;;
|
|
esac
|
|
done
|
|
|
|
case "$output" in
|
|
/*) ;;
|
|
*)
|
|
echo "build-dwh-auth: output must be an absolute canonical directory" >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
|
|
[[ "$output" != */../* && "$output" != */.. && "$output" != *'/./'* && "$output" != */. ]] || {
|
|
echo "build-dwh-auth: output must be canonical" >&2
|
|
exit 2
|
|
}
|
|
|
|
if [[ "$output" == / || "$output" == "$repo_root" || "$output" == /tmp || "$output" == /var || "$output" == /home ]]; then
|
|
echo "build-dwh-auth: refusing broad output path" >&2
|
|
exit 2
|
|
fi
|
|
|
|
parent=$(dirname "$output")
|
|
if [[ "$output" == "$default_output" && ! -e "$parent" ]]; then
|
|
mkdir -p "$parent"
|
|
fi
|
|
[[ -d "$parent" && ! -L "$parent" ]] || {
|
|
echo "build-dwh-auth: output parent must be an existing non-symlink directory" >&2
|
|
exit 2
|
|
}
|
|
leaf=$(basename "$output")
|
|
canonical_parent=$(cd "$parent" && pwd -P)
|
|
[[ "${canonical_parent%/}/$leaf" == "$output" ]] || {
|
|
echo "build-dwh-auth: output must be canonical" >&2
|
|
exit 2
|
|
}
|
|
|
|
if [[ -e "$output" || -L "$output" ]]; then
|
|
[[ -d "$output" && ! -L "$output" ]] || {
|
|
echo "build-dwh-auth: output exists and is not a directory" >&2
|
|
exit 2
|
|
}
|
|
if [[ -n "$(find "$output" -mindepth 1 -maxdepth 1 -print -quit)" ]]; then
|
|
echo "build-dwh-auth: refusing non-empty output directory" >&2
|
|
exit 2
|
|
fi
|
|
else
|
|
mkdir "$output"
|
|
fi
|
|
|
|
command -v docker >/dev/null 2>&1 || {
|
|
echo "build-dwh-auth: Docker is required for the pinned build" >&2
|
|
exit 1
|
|
}
|
|
|
|
docker build \
|
|
--file "$repo_root/docker/dwh-auth.Dockerfile" \
|
|
--output "type=local,dest=$output" \
|
|
"$repo_root"
|
|
|
|
for arch in amd64 arm64; do
|
|
artifact="$output/dwh-auth-linux-$arch"
|
|
[[ -s "$artifact" ]] || {
|
|
echo "build-dwh-auth: builder did not produce $artifact" >&2
|
|
exit 1
|
|
}
|
|
done
|