Sanitized root snapshot from private source commit a72903c63e1753f9e6ffbf40453c0830bdfc05c5 and tree 295641e67eef5979da76746d8ae271249568263e. Private development history and workflows are excluded by the exact allowlist. AI-assisted: OpenAI Codex helped implement, test, and audit this preview. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
19 lines
676 B
Bash
Executable File
19 lines
676 B
Bash
Executable File
#!/usr/bin/env bash
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
set -euo pipefail
|
|
root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
|
work=$(mktemp -d)
|
|
trap 'rm -rf -- "$work"' EXIT
|
|
destination=$work/public
|
|
"$root/scripts/export-public.sh" --destination "$destination" >/dev/null
|
|
test -f "$destination/PUBLIC-SNAPSHOT.json"
|
|
test -f "$destination/PUBLIC-SNAPSHOT.sha256"
|
|
(cd "$destination" && sha256sum -c PUBLIC-SNAPSHOT.sha256)
|
|
test ! -e "$destination/.git"
|
|
test ! -e "$destination/.gitea"
|
|
test ! -e "$destination/.github"
|
|
while IFS= read -r file; do
|
|
cmp "$root/$file" "$destination/$file"
|
|
done <"$root/scripts/public-snapshot.allow"
|
|
echo "public snapshot isolation verified"
|