who_need_help/scripts/prepare-production-release.sh

54 lines
1.6 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
umask 077
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
if [[ -n "$(git -C "$ROOT" status --porcelain --untracked-files=no)" ]]; then
echo "Refusing to package a release from a dirty tracked checkout." >&2
exit 1
fi
commit=$(git -C "$ROOT" rev-parse --verify HEAD)
short_commit=${commit:0:12}
release_dir="$ROOT/output/releases/$commit"
bundle="$release_dir/who_need_help-$commit.bundle"
checksum="$bundle.sha256"
manifest="$release_dir/manifest.txt"
mkdir -p "$release_dir"
chmod 700 "$ROOT/output" "$ROOT/output/releases" "$release_dir"
if [[ -e "$bundle" || -e "$checksum" || -e "$manifest" ]]; then
echo "Release package already exists; verifying it instead of overwriting it."
else
git -C "$ROOT" bundle create "$bundle" HEAD
chmod 600 "$bundle"
hash=$(sha256sum "$bundle" | awk '{print $1}')
printf '%s %s\n' "$hash" "$(basename -- "$bundle")" >"$checksum"
{
printf 'commit=%s\n' "$commit"
printf 'short_commit=%s\n' "$short_commit"
printf 'created_at=%s\n' "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
printf 'bundle_sha256=%s\n' "$hash"
} >"$manifest"
chmod 600 "$checksum" "$manifest"
fi
(
cd "$release_dir"
sha256sum --check "$(basename -- "$checksum")" >/dev/null
)
git -C "$ROOT" bundle verify "$bundle" >/dev/null
bundle_head=$(git -C "$ROOT" bundle list-heads "$bundle" | awk '$2 == "HEAD" {print $1}')
if [[ "$bundle_head" != "$commit" ]]; then
echo "Release bundle HEAD does not match the current commit." >&2
exit 1
fi
printf 'Release commit: %s\n' "$commit"
printf 'Bundle: %s\n' "$bundle"
printf 'Checksum: %s\n' "$checksum"
printf 'Manifest: %s\n' "$manifest"