Export the reviewed allowlisted snapshot from private source commit 8aab3db43f35e6a49aa497f45d73701b13fc9f32 and tree 992132ea4703437dc13ffdbb04a077816c02caf9. This includes routed singleton continuity, deployment evidence, strict schema-2 configuration, restricted transport, and the independently compilable public-tree guard. AI-Assisted: OpenAI Codex Signed-off-by: Cole Speelman <crspeelman@gmail.com>
26 lines
1.3 KiB
Bash
Executable File
26 lines
1.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
set -euo pipefail
|
|
root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
|
cd "$root"
|
|
./scripts/check-licenses.sh
|
|
./scripts/check-public-tree.sh
|
|
go test -count=1 ./...
|
|
go test -race -count=1 ./...
|
|
go vet ./...
|
|
for script in scripts/*.sh; do bash -n "$script"; done
|
|
work=$(mktemp -d); trap 'rm -rf -- "$work"' EXIT
|
|
GOWORK=off CGO_ENABLED=0 go build -mod=readonly -trimpath -o "$work/tend-1" ./cmd/tend
|
|
GOWORK=off CGO_ENABLED=0 go build -mod=readonly -trimpath -o "$work/tend-2" ./cmd/tend
|
|
cmp "$work/tend-1" "$work/tend-2"
|
|
"$work/tend-1" check --config "$root/examples/blue-green/tend.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/examples/singleton/tend.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/examples/server/services/example-site.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/examples/server/services/docs-site.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/release/tend.json" >/dev/null
|
|
grep -Fqx 'Defaults:tend-deploy env_keep += "SSH_ORIGINAL_COMMAND"' "$root/examples/server/tend-receive.sudoers"
|
|
grep -Fqx 'tend-deploy ALL=(root) NOPASSWD: /usr/local/bin/tend receive --policy /etc/tend/receive-policy.json' "$root/examples/server/tend-receive.sudoers"
|
|
[[ $(GOWORK=off go list -m all | wc -l) -eq 1 ]]
|
|
git diff --check
|
|
echo "Tend verification passed"
|