who_need_help/scripts/android-source-fingerprint.sh

63 lines
1.8 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
mapfile -d '' -t candidate_files < <(
git -C "$ROOT" ls-files \
--cached \
--others \
--exclude-standard \
-z \
-- android |
LC_ALL=C sort -z
)
source_files=()
for relative_path in "${candidate_files[@]}"; do
absolute_path="$ROOT/$relative_path"
# Play Console copy and artwork live beside the Android project so release
# operators can find them, but Gradle never consumes them when producing an
# APK or AAB. Keep the artifact fingerprint bound to binary build inputs,
# not to reviewer instructions or store-listing edits.
case "$relative_path" in
android/README.md|android/play-store/*|android/store-assets/*)
continue
;;
esac
# `git ls-files --cached` also reports tracked paths deleted in the working
# tree. They are not inputs to the artifact being built, so exclude them
# from the working-tree fingerprint instead of treating a valid deletion as
# a broken source tree.
if [[ ! -e "$absolute_path" && ! -L "$absolute_path" ]]; then
continue
fi
source_files+=("$relative_path")
done
if [[ "${#source_files[@]}" -eq 0 ]]; then
echo "No Android build input files were found." >&2
exit 1
fi
{
# Version the input contract so a future deliberate scope change cannot
# silently compare equal to a fingerprint produced by this implementation.
printf 'who-need-help-android-build-inputs-v2\0'
for relative_path in "${source_files[@]}"; do
absolute_path="$ROOT/$relative_path"
if [[ ! -f "$absolute_path" ]]; then
echo "Android build input is not a regular file: $relative_path" >&2
exit 1
fi
printf '%s\0' "$relative_path"
sha256sum "$absolute_path" | awk '{print $1}'
done
} | sha256sum | awk '{print $1}'