who_need_help/scripts/android-signing-fingerprint.sh

83 lines
2.0 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
keystore=${1:-}
password_file=${2:-}
key_alias=${3:-}
key_image="gradle:9.6.1-jdk17@sha256:7364ce528f33bb6038672bcef990d524f1ad8fbc292935819c235db886d0fae7"
if [[ -z "$keystore" || -z "$password_file" || -z "$key_alias" ]]; then
echo "Usage: $0 KEYSTORE PASSWORD_FILE KEY_ALIAS" >&2
exit 2
fi
keystore=$(realpath "$keystore")
password_file=$(realpath "$password_file")
keystore_dir=$(dirname "$keystore")
password_dir=$(dirname "$password_file")
for secret_file in "$keystore" "$password_file"; do
[[ -f "$secret_file" && ! -L "$secret_file" ]] || {
echo "Android signing input must be a regular non-symlink file: $secret_file" >&2
exit 1
}
case "$(stat -c '%a' "$secret_file")" in
400 | 600) ;;
*)
echo "Android signing input must have mode 0400 or 0600: $secret_file" >&2
exit 1
;;
esac
done
case "$key_alias" in
'' | *[!A-Za-z0-9._-]*)
echo "Android signing alias contains unsupported characters." >&2
exit 1
;;
esac
mounts=(
--mount "type=bind,src=$keystore_dir,dst=/keystore,readonly"
)
password_container_dir=/password
if [[ "$password_dir" == "$keystore_dir" ]]; then
password_container_dir=/keystore
else
mounts+=(--mount "type=bind,src=$password_dir,dst=/password,readonly")
fi
report=$(
docker run --rm \
--user "$(id -u):$(id -g)" \
"${mounts[@]}" \
--entrypoint keytool \
"$key_image" \
-list -v \
-keystore "/keystore/$(basename "$keystore")" \
-storetype PKCS12 \
-storepass:file "$password_container_dir/$(basename "$password_file")" \
-alias "$key_alias"
)
fingerprint=$(
awk -F': ' '
/^[[:space:]]*SHA256:/ {
print $2
found = 1
exit
}
END { if (!found) exit 1 }
' <<<"$report"
) || {
echo "The signing certificate SHA-256 fingerprint was not found." >&2
exit 1
}
[[ "${fingerprint//:/}" =~ ^[0-9A-Fa-f]{64}$ ]] || {
echo "The signing certificate SHA-256 fingerprint is malformed." >&2
exit 1
}
printf '%s\n' "$(tr '[:lower:]' '[:upper:]' <<<"$fingerprint")"