quantum-audit-manifest.sh (2437B)
1 #!/usr/bin/env bash 2 set -euo pipefail 3 4 cd "$(dirname "${BASH_SOURCE[0]}")/.." 5 6 usage() { 7 echo "usage: scripts/quantum-audit-manifest.sh [--output MANIFEST.json]" >&2 8 exit 2 9 } 10 11 output="" 12 if [ "$#" -gt 0 ]; then 13 [ "$#" -eq 2 ] && [ "$1" = "--output" ] || usage 14 output="$2" 15 [ -n "$output" ] || usage 16 if [ -e "$output" ]; then 17 echo "error: refusing to overwrite existing manifest: ${output}" >&2 18 exit 1 19 fi 20 fi 21 22 for command_name in cargo git jq rustc rustup; do 23 command -v "$command_name" >/dev/null 2>&1 || { 24 echo "error: missing required command: ${command_name}" >&2 25 exit 1 26 } 27 done 28 29 if [ -n "$(git status --porcelain --untracked-files=normal)" ]; then 30 echo "error: refusing to describe a dirty worktree; commit or stash every change first" >&2 31 exit 1 32 fi 33 34 sha256_file() { 35 local path="$1" 36 if command -v sha256sum >/dev/null 2>&1; then 37 sha256sum "$path" | awk '{print $1}' 38 else 39 shasum -a 256 "$path" | awk '{print $1}' 40 fi 41 } 42 43 root_lock_sha256="$(sha256_file Cargo.lock)" 44 fuzz_lock_sha256="$(sha256_file fuzz/Cargo.lock)" 45 tauri_lock_sha256="$(sha256_file src-tauri/Cargo.lock)" 46 git_commit="$(git rev-parse HEAD)" 47 rustc_version="$(rustc --version)" 48 cargo_version="$(cargo --version)" 49 nightly_version="$(rustup run nightly rustc --version)" 50 cargo_fuzz_version="$(cargo fuzz --version)" 51 captured_at="$(date -u +%Y-%m-%dT%H:%M:%SZ)" 52 53 manifest="$( 54 jq -n \ 55 --arg captured_at "$captured_at" \ 56 --arg git_commit "$git_commit" \ 57 --arg rustc "$rustc_version" \ 58 --arg cargo "$cargo_version" \ 59 --arg nightly_rustc "$nightly_version" \ 60 --arg cargo_fuzz "$cargo_fuzz_version" \ 61 --arg root_lock "$root_lock_sha256" \ 62 --arg fuzz_lock "$fuzz_lock_sha256" \ 63 --arg tauri_lock "$tauri_lock_sha256" \ 64 --slurpfile vectors tests/vectors/ml_dsa44_audit.json \ 65 '{ 66 format: 1, 67 captured_at: $captured_at, 68 git: {commit: $git_commit, tree_state: "clean"}, 69 toolchain: { 70 rustc: $rustc, 71 cargo: $cargo, 72 nightly_rustc: $nightly_rustc, 73 cargo_fuzz: $cargo_fuzz 74 }, 75 lockfiles_sha256: { 76 "Cargo.lock": $root_lock, 77 "fuzz/Cargo.lock": $fuzz_lock, 78 "src-tauri/Cargo.lock": $tauri_lock 79 }, 80 vector_sources: $vectors[0].sources 81 }' 82 )" 83 84 if [ -n "$output" ]; then 85 printf '%s\n' "$manifest" > "$output" 86 echo "wrote quantum audit manifest to ${output}" 87 else 88 printf '%s\n' "$manifest" 89 fi