Skip to content

Commit 928352f

Browse files
committed
tools: switch to PGP and SHA256 in ICU updater
Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 4791219 commit 928352f

4 files changed

Lines changed: 46 additions & 16 deletions

File tree

‎doc/contributing/maintaining/maintaining-icu.md‎

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -177,9 +177,19 @@ make clean
177177
tools/license-builder.sh
178178
```
179179

180-
* Update the URL and hash for the full ICU file in `tools/icu/current_ver.dep`.
181-
It should match the ICU URL used in the first step. When this is done, the
182-
following should build with small ICU.
180+
* Verify the PGP signature of the full ICU file:
181+
182+
```bash
183+
gpgv --keyring tools/dep_updaters/icu.kbx \
184+
icu4c-*-sources.tgz.asc icu4c-*-sources.tgz
185+
```
186+
187+
* If the release was signed with a key not present in that keyring, update it
188+
from the [ICU `KEYS` file](https://github.com/unicode-org/icu/blob/HEAD/KEYS)
189+
after confirming the new key out-of-band.
190+
* Update the URL and SHA-256 hash for the full ICU file in
191+
`tools/icu/current_ver.dep`. It should match the ICU URL used in the first
192+
step. When this is done, the following should build with small ICU.
183193

184194
```bash
185195
# clean up

‎tools/dep_updaters/icu.kbx‎

31 KB
Binary file not shown.

‎tools/dep_updaters/update-icu.sh‎

Lines changed: 32 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
#!/bin/sh
22
set -e
3-
# Shell script to update icu in the source tree to a specific version
3+
# Shell script to update icu in the source tree to a specific version.
4+
# Pass `--update-keys` to update the local copy of the key files after verifying
5+
# the upstream file history.
46

57
BASE_DIR=$(cd "$(dirname "$0")/../.." && pwd)
68
DEPS_DIR="$BASE_DIR/deps"
@@ -36,28 +38,46 @@ NEW_VERSION_TGZ="icu4c-${NEW_VERSION}-sources.tgz"
3638

3739
NEW_VERSION_TGZ_URL="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/${NEW_VERSION_TGZ}"
3840

39-
NEW_VERSION_MD5="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/icu4c-${NEW_VERSION}-sources.md5"
41+
WORKSPACE=$(mktemp -d 2> /dev/null || mktemp -d -t 'tmp')
42+
NEW_VERSION_TGZ_PATH="$WORKSPACE/$NEW_VERSION_TGZ"
4043

41-
CHECKSUM=$(curl -sL "$NEW_VERSION_MD5" | grep "$NEW_VERSION_TGZ" | grep -v "\.asc$" | awk '{print $1}')
44+
cleanup () {
45+
EXIT_CODE=$?
46+
[ -d "$WORKSPACE" ] && rm -rf "$WORKSPACE"
47+
exit $EXIT_CODE
48+
}
4249

43-
GENERATED_CHECKSUM=$( curl -sL "$NEW_VERSION_TGZ_URL" | md5sum | cut -d ' ' -f1)
50+
trap cleanup INT TERM EXIT
4451

45-
echo "Comparing checksums: deposited '$CHECKSUM' with '$GENERATED_CHECKSUM'"
52+
echo "Fetching ICU source archive"
53+
curl -sfL -o "$NEW_VERSION_TGZ_PATH" "$NEW_VERSION_TGZ_URL"
4654

47-
if [ "$CHECKSUM" != "$GENERATED_CHECKSUM" ]; then
48-
echo "Skipped because checksums do not match."
49-
exit 0
55+
KEYRING="$BASE_DIR/tools/dep_updaters/icu.kbx"
56+
if [ "$1" = "--update-keys" ]; then
57+
KEYS_FILE="$(mktemp)"
58+
echo "Fetching the upstream KEYS file"
59+
curl -sSLfo "$KEYS_FILE" https://github.com/unicode-org/icu/raw/refs/tags/release-${NEW_VERSION}/KEYS
60+
rm -f "$KEYRING"
61+
gpg --no-default-keyring --keyring "$KEYRING" --batch --import --import-options import-minimal < "$KEYS_FILE"
5062
fi
5163

52-
./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_URL"
64+
echo "Verifying PGP signature"
65+
curl -sfL -o "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_URL.asc"
66+
gpgv --keyring "$KEYRING" "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_PATH"
67+
68+
CHECKSUM=$(shasum -a 256 "$NEW_VERSION_TGZ_PATH" | cut -d ' ' -f1)
69+
echo "sha256: $CHECKSUM"
70+
71+
./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_PATH"
5372

5473
"$TOOLS_DIR/icu/shrink-icu-src.py"
5574

5675
rm -rf "$DEPS_DIR/icu"
5776

58-
perl -i -pe "s|\"url\": .*|\"url\": \"$NEW_VERSION_TGZ_URL\",|" "$TOOLS_DIR/icu/current_ver.dep"
59-
60-
perl -i -pe "s|\"md5\": .*|\"md5\": \"$CHECKSUM\"|" "$TOOLS_DIR/icu/current_ver.dep"
77+
URL="$NEW_VERSION_TGZ_URL" SHA256="$CHECKSUM" "$NODE" -e '
78+
const { URL: url, SHA256: sha256 } = process.env;
79+
console.log(JSON.stringify([{ url, sha256 }], null, 2));
80+
' > "$TOOLS_DIR/icu/current_ver.dep"
6181

6282
rm -rf out "$DEPS_DIR/icu" "$DEPS_DIR/icu4c*"
6383

‎tools/icu/current_ver.dep‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
[
22
{
33
"url": "https://github.com/unicode-org/icu/releases/download/release-78.3/icu4c-78.3-sources.tgz",
4-
"md5": "a7b736b570ef0e180c96a31715a00c78"
4+
"sha256": "3a2e7a47604ba702f345878308e6fefeca612ee895cf4a5f222e7955fabfe0c0"
55
}
66
]

0 commit comments

Comments
 (0)