fix(release): stabilize remote backend hash preflight
This commit is contained in:
@@ -202,7 +202,8 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
||||
unzip -p "$backend_jar" "BOOT-INF/lib/$backend_module_jar_name" > "$local_backend_module_jar"
|
||||
local_backend_module_sha256="$(normalized_jar_content_sha256 "$local_backend_module_jar")"
|
||||
rm -f "$local_backend_module_jar"
|
||||
remote_backend_module_sha256="$(ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" bash -s -- "$remote_backend_path" "$backend_module_jar_name" <<'REMOTE'
|
||||
remote_backend_module_sha_file="$(mktemp)"
|
||||
ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" bash -s -- "$remote_backend_path" "$backend_module_jar_name" > "$remote_backend_module_sha_file" <<'REMOTE'
|
||||
set -euo pipefail
|
||||
outer="$1"
|
||||
module="$2"
|
||||
@@ -221,7 +222,9 @@ while IFS= read -r entry; do
|
||||
done < <(unzip -Z1 "$nested" | LC_ALL=C sort)
|
||||
sha256sum "$manifest" | awk '{print $1}'
|
||||
REMOTE
|
||||
)" || fail "remote backend module hash check failed: $remote_ssh:$remote_backend_path"
|
||||
remote_backend_module_sha256="$(sed -n '1p' "$remote_backend_module_sha_file")"
|
||||
rm -f "$remote_backend_module_sha_file"
|
||||
[[ -n "$remote_backend_module_sha256" ]] || fail "remote backend module hash check returned no value: $remote_ssh:$remote_backend_path"
|
||||
[[ "$remote_backend_module_sha256" =~ ^[0-9a-f]{64}$ ]] || fail "remote backend module hash is invalid: $remote_ssh:$remote_backend_path"
|
||||
echo "remote_backend_jar_sha256=$remote_backend_jar_sha256"
|
||||
echo "local_backend_jar_sha256=$local_backend_jar_sha256"
|
||||
|
||||
Reference in New Issue
Block a user