Files
web/scripts/check-embedded-webauthn.sh
T
gamertan a39e8f893c
verify / verify (push) Successful in 3m28s
requestlog: publish collector-readable evidence boundary
Publish the reviewed Gamertan Web Foundations v0.1.0-preview.6 snapshot with a narrow mode-0640 collector boundary, private mode-0600 default, explicit setgid ownership guidance, and native macOS-safe release verification.

Exported from reviewed private source 120d660fa432761f85316ca3dde990e2dd142f19 after trusted Gitea CI run 681 and the complete native Mac verification suite.

Material implementation assistance provided by OpenAI Codex; reviewed and verified through the maintainer workflow.

Signed-off-by: Cole Speelman <crspeelman@gmail.com>
2026-08-24 17:06:47 -04:00

53 lines
1.3 KiB
Bash
Executable File

#!/usr/bin/env bash
# SPDX-License-Identifier: AGPL-3.0-only
set -euo pipefail
root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)
cd "$root"
source_root=third_party/go-webauthn
embedded_root=internal/webauthnvendored
derived=$(mktemp -d)
trap 'rm -rf "$derived"' EXIT
packages=(
metadata
protocol
protocol/webauthncbor
protocol/webauthncose
webauthn
)
install_file() {
source=$1
destination=$2
mkdir -p "$(dirname "$destination")"
install -m 0644 "$source" "$destination"
}
install_file "$source_root/LICENSE" "$derived/LICENSE"
for package in "${packages[@]}"; do
for source in "$source_root/$package"/*.go; do
case $source in
*_test.go) continue ;;
esac
relative=${source#"$source_root"/}
install_file "$source" "$derived/$relative"
done
done
while IFS= read -r source; do
temporary="$source.tmp"
sed \
's#github.com/go-webauthn/webauthn#gamertan.com/web/internal/webauthnvendored#g' \
"$source" >"$temporary"
mv "$temporary" "$source"
done < <(find "$derived" -type f -name '*.go' | sort)
cmp -s LICENSES/BSD-3-Clause-go-webauthn.txt "$embedded_root/LICENSE"
if ! diff -ru "$derived" "$embedded_root"; then
echo 'compiled WebAuthn verifier differs from its audited mechanical derivation' >&2
exit 1
fi
test "$(find "$embedded_root" -type f | wc -l)" -eq 57