fix(release): normalize backend module evidence
This commit is contained in:
@@ -29,12 +29,28 @@ sha256_stream() {
|
||||
fi
|
||||
}
|
||||
|
||||
normalized_jar_content_sha256() {
|
||||
local jar_path="$1"
|
||||
local manifest_path
|
||||
manifest_path="$(mktemp)"
|
||||
while IFS= read -r entry; do
|
||||
case "$entry" in
|
||||
*/|META-INF/*.SF|META-INF/*.RSA|META-INF/*.DSA) continue ;;
|
||||
esac
|
||||
printf '%s %s\n' "$(unzip -p "$jar_path" "$entry" | sha256_stream)" "$entry" >> "$manifest_path"
|
||||
done < <(unzip -Z1 "$jar_path" | LC_ALL=C sort)
|
||||
sha256 "$manifest_path"
|
||||
rm -f "$manifest_path"
|
||||
}
|
||||
|
||||
frontend_index="frontend/dist/index.html"
|
||||
mobile_index="mobile-uni/dist/build/h5/index.html"
|
||||
backend_jar="backend/ruoyi-admin/target/ruoyi-admin.jar"
|
||||
require_file "$frontend_index"
|
||||
require_file "$mobile_index"
|
||||
require_file "$backend_jar"
|
||||
backend_module_jar_name="$(unzip -Z1 "$backend_jar" | sed -nE 's#BOOT-INF/lib/(ruoyi-aihr-[^/]+\.jar)#\1#p' | head -1)"
|
||||
[[ -n "$backend_module_jar_name" ]] || fail "backend jar does not contain the ruoyi-aihr module"
|
||||
|
||||
frontend_asset="$(sed -nE 's/.*src="([^"]+\.js)".*/\1/p' "$frontend_index" | head -1)"
|
||||
mobile_asset="$(sed -nE 's/.*src="([^"]+\.js)".*/\1/p' "$mobile_index" | head -1)"
|
||||
@@ -131,12 +147,41 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
||||
remote_ssh="${RELEASE_REMOTE_SSH:-YCWY}"
|
||||
remote_backend_path="${RELEASE_REMOTE_BACKEND_PATH:-/opt/wygj/app/ruoyi-admin.jar}"
|
||||
[[ "$remote_backend_path" =~ ^/[A-Za-z0-9._/-]+$ ]] || fail "remote backend path must be an absolute safe path: $remote_backend_path"
|
||||
remote_backend_sha256="$(ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" "sha256sum '$remote_backend_path'" | awk '{print $1}')" || fail "remote backend hash check failed: $remote_ssh:$remote_backend_path"
|
||||
[[ "$remote_backend_sha256" =~ ^[0-9a-f]{64}$ ]] || fail "remote backend hash is invalid: $remote_ssh:$remote_backend_path"
|
||||
local_backend_sha256="$(sha256 "$backend_jar")"
|
||||
echo "remote_backend_sha256=$remote_backend_sha256"
|
||||
[[ "$remote_backend_sha256" == "$local_backend_sha256" ]] || fail "remote backend jar does not match local build"
|
||||
echo "remote_backend_match=true"
|
||||
remote_backend_jar_sha256="$(ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" "sha256sum '$remote_backend_path'" | awk '{print $1}')" || fail "remote backend hash check failed: $remote_ssh:$remote_backend_path"
|
||||
[[ "$remote_backend_jar_sha256" =~ ^[0-9a-f]{64}$ ]] || fail "remote backend hash is invalid: $remote_ssh:$remote_backend_path"
|
||||
local_backend_jar_sha256="$(sha256 "$backend_jar")"
|
||||
local_backend_module_jar="$(mktemp)"
|
||||
unzip -p "$backend_jar" "BOOT-INF/lib/$backend_module_jar_name" > "$local_backend_module_jar"
|
||||
local_backend_module_sha256="$(normalized_jar_content_sha256 "$local_backend_module_jar")"
|
||||
rm -f "$local_backend_module_jar"
|
||||
remote_backend_module_sha256="$(ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" bash -s -- "$remote_backend_path" "$backend_module_jar_name" <<'REMOTE'
|
||||
set -euo pipefail
|
||||
outer="$1"
|
||||
module="$2"
|
||||
nested="$(mktemp)"
|
||||
manifest="$(mktemp)"
|
||||
cleanup() {
|
||||
rm -f "$nested" "$manifest"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
unzip -p "$outer" "BOOT-INF/lib/$module" > "$nested"
|
||||
while IFS= read -r entry; do
|
||||
case "$entry" in
|
||||
*/|META-INF/*.SF|META-INF/*.RSA|META-INF/*.DSA) continue ;;
|
||||
esac
|
||||
printf '%s %s\n' "$(unzip -p "$nested" "$entry" | sha256sum | awk '{print $1}')" "$entry" >> "$manifest"
|
||||
done < <(unzip -Z1 "$nested" | LC_ALL=C sort)
|
||||
sha256sum "$manifest" | awk '{print $1}'
|
||||
REMOTE
|
||||
)" || fail "remote backend module hash check failed: $remote_ssh:$remote_backend_path"
|
||||
[[ "$remote_backend_module_sha256" =~ ^[0-9a-f]{64}$ ]] || fail "remote backend module hash is invalid: $remote_ssh:$remote_backend_path"
|
||||
echo "remote_backend_jar_sha256=$remote_backend_jar_sha256"
|
||||
echo "local_backend_jar_sha256=$local_backend_jar_sha256"
|
||||
echo "backend_module=$backend_module_jar_name"
|
||||
echo "remote_backend_module_sha256=$remote_backend_module_sha256"
|
||||
echo "local_backend_module_sha256=$local_backend_module_sha256"
|
||||
[[ "$remote_backend_module_sha256" == "$local_backend_module_sha256" ]] || fail "remote AIHR module does not match local build"
|
||||
echo "remote_backend_module_match=true"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user