#!/bin/sh # Checks for deploy/bootstrap.sh. Run it as: sh deploy/bootstrap_test.sh # # The script it tests cannot be run here — it wants root, a package manager, k3s and the # network — so each case extracts the block it is about out of bootstrap.sh verbatim and runs # that with die/log stubbed. Extraction rather than a transcribed copy is the point: a copy # passes forever after someone edits the original. set -u BS="${1:-$(dirname "$0")/bootstrap.sh}" [ -f "$BS" ] || { echo "no such script: $BS"; exit 1; } fails=0 expect() { # label needle haystack case "$3" in *"$2"*) echo "PASS $1" ;; *) echo "FAIL $1: expected <$2> in:"; echo "$3"; fails=$((fails + 1)) ;; esac } # --- the FELIS_VELOCITY_FORK_JAR digest gate ------------------------------------------- # This jar becomes the proxy every player connects through, so the interesting cases are the # two refusals, not the happy path. gate="$(awk '/have="\$\(sha256sum <"\$FELIS_VELOCITY_FORK_JAR"/,/^ log "installing the Felis-Legacy/' "$BS")" [ -n "$gate" ] || { echo "FAIL: no fork-jar digest gate found in $BS"; exit 1; } # awk runs an unmatched end pattern to EOF, which would quietly pipe the rest of bootstrap.sh # into the `sh -c` below. The emptiness check above only catches a broken start pattern. [ "$(printf '%s\n' "$gate" | wc -l)" -lt 40 ] \ || { echo "FAIL: the extracted block is not the gate -- did its last line move?"; exit 1; } jar="$(mktemp)" trap 'rm -f "$jar"' EXIT printf 'stand-in for a fork build\n' > "$jar" want="$(sha256sum <"$jar" | cut -d' ' -f1)" run_gate() { # digest FELIS_VELOCITY_FORK_JAR="$jar" FELIS_VELOCITY_FORK_JAR_SHA256="$1" sh -c ' die() { printf "DIE: %s\n" "$*"; exit 1; } log() { printf "LOG: %s\n" "$*"; } '"$gate" } out="$(run_gate '')" expect "fork jar without a digest is refused" "DIE: FELIS_VELOCITY_FORK_JAR_SHA256 is required" "$out" expect "the refusal names the jar's real digest" "$want" "$out" out="$(run_gate 'deadbeef')" expect "a mismatched digest is refused" "checksum mismatch: got ${want}, expected deadbeef" "$out" out="$(run_gate "$want")" expect "the matching digest installs" "LOG: installing the Felis-Legacy Velocity fork" "$out" expect "the install line records the digest" "(sha256 ${want})" "$out" # The build host is usually Windows, where nothing prints the digest the way sha256sum does: # Get-FileHash returns uppercase and certutil has shipped the bytes space-separated. Feeding # the gate its own output can never catch that -- these two cases are the operator's paste. out="$(run_gate "$(printf '%s' "$want" | tr 'a-z' 'A-Z')")" expect "an uppercase digest is the same digest" "LOG: installing the Felis-Legacy Velocity fork" "$out" out="$(run_gate "$(printf '%s' "$want" | sed 's/../& /g')")" expect "a space-separated digest is the same digest" "LOG: installing the Felis-Legacy Velocity fork" "$out" # --------------------------------------------------------------------------------------- if [ "$fails" -eq 0 ]; then echo "ALL PASS" else echo "$fails FAILED" fi exit "$fails"