|
1 | 1 | #!/bin/sh |
2 | 2 | set -e |
3 | | -# Shell script to update icu in the source tree to a specific version |
| 3 | +# Shell script to update icu in the source tree to a specific version. |
| 4 | +# Pass `--update-keys` to update the local copy of the key files after verifying |
| 5 | +# the upstream file history. |
4 | 6 |
|
5 | 7 | BASE_DIR=$(cd "$(dirname "$0")/../.." && pwd) |
6 | 8 | DEPS_DIR="$BASE_DIR/deps" |
@@ -36,28 +38,46 @@ NEW_VERSION_TGZ="icu4c-${NEW_VERSION}-sources.tgz" |
36 | 38 |
|
37 | 39 | NEW_VERSION_TGZ_URL="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/${NEW_VERSION_TGZ}" |
38 | 40 |
|
39 | | -NEW_VERSION_MD5="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/icu4c-${NEW_VERSION}-sources.md5" |
| 41 | +WORKSPACE=$(mktemp -d 2> /dev/null || mktemp -d -t 'tmp') |
| 42 | +NEW_VERSION_TGZ_PATH="$WORKSPACE/$NEW_VERSION_TGZ" |
40 | 43 |
|
41 | | -CHECKSUM=$(curl -sL "$NEW_VERSION_MD5" | grep "$NEW_VERSION_TGZ" | grep -v "\.asc$" | awk '{print $1}') |
| 44 | +cleanup () { |
| 45 | + EXIT_CODE=$? |
| 46 | + [ -d "$WORKSPACE" ] && rm -rf "$WORKSPACE" |
| 47 | + exit $EXIT_CODE |
| 48 | +} |
42 | 49 |
|
43 | | -GENERATED_CHECKSUM=$( curl -sL "$NEW_VERSION_TGZ_URL" | md5sum | cut -d ' ' -f1) |
| 50 | +trap cleanup INT TERM EXIT |
44 | 51 |
|
45 | | -echo "Comparing checksums: deposited '$CHECKSUM' with '$GENERATED_CHECKSUM'" |
| 52 | +echo "Fetching ICU source archive" |
| 53 | +curl -sfL -o "$NEW_VERSION_TGZ_PATH" "$NEW_VERSION_TGZ_URL" |
46 | 54 |
|
47 | | -if [ "$CHECKSUM" != "$GENERATED_CHECKSUM" ]; then |
48 | | - echo "Skipped because checksums do not match." |
49 | | - exit 0 |
| 55 | +KEYRING="$BASE_DIR/tools/dep_updaters/icu.kbx" |
| 56 | +if [ "$1" = "--update-keys" ]; then |
| 57 | + KEYS_FILE="$(mktemp)" |
| 58 | + echo "Fetching the upstream KEYS file" |
| 59 | + curl -sSLfo "$KEYS_FILE" https://github.com/unicode-org/icu/raw/refs/tags/release-${NEW_VERSION}/KEYS |
| 60 | + rm -f "$KEYRING" |
| 61 | + gpg --no-default-keyring --keyring "$KEYRING" --batch --import --import-options import-minimal < "$KEYS_FILE" |
50 | 62 | fi |
51 | 63 |
|
52 | | -./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_URL" |
| 64 | +echo "Verifying PGP signature" |
| 65 | +curl -sfL -o "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_URL.asc" |
| 66 | +gpgv --keyring "$KEYRING" "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_PATH" |
| 67 | + |
| 68 | +CHECKSUM=$(shasum -a 256 "$NEW_VERSION_TGZ_PATH" | cut -d ' ' -f1) |
| 69 | +echo "sha256: $CHECKSUM" |
| 70 | + |
| 71 | +./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_PATH" |
53 | 72 |
|
54 | 73 | "$TOOLS_DIR/icu/shrink-icu-src.py" |
55 | 74 |
|
56 | 75 | rm -rf "$DEPS_DIR/icu" |
57 | 76 |
|
58 | | -perl -i -pe "s|\"url\": .*|\"url\": \"$NEW_VERSION_TGZ_URL\",|" "$TOOLS_DIR/icu/current_ver.dep" |
59 | | - |
60 | | -perl -i -pe "s|\"md5\": .*|\"md5\": \"$CHECKSUM\"|" "$TOOLS_DIR/icu/current_ver.dep" |
| 77 | +URL="$NEW_VERSION_TGZ_URL" SHA256="$CHECKSUM" "$NODE" -e ' |
| 78 | + const { URL: url, SHA256: sha256 } = process.env; |
| 79 | + console.log(JSON.stringify([{ url, sha256 }], null, 2)); |
| 80 | +' > "$TOOLS_DIR/icu/current_ver.dep" |
61 | 81 |
|
62 | 82 | rm -rf out "$DEPS_DIR/icu" "$DEPS_DIR/icu4c*" |
63 | 83 |
|
|
0 commit comments