Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 13 additions & 3 deletions doc/contributing/maintaining/maintaining-icu.md
Original file line number Diff line number Diff line change
Expand Up @@ -177,9 +177,19 @@ make clean
tools/license-builder.sh
```

* Update the URL and hash for the full ICU file in `tools/icu/current_ver.dep`.
It should match the ICU URL used in the first step. When this is done, the
following should build with small ICU.
* Verify the PGP signature of the full ICU file:

```bash
gpgv --keyring tools/dep_updaters/icu.kbx \
icu4c-*-sources.tgz.asc icu4c-*-sources.tgz
```

* If the release was signed with a key not present in that keyring, update it
from the [ICU `KEYS` file](https://github.com/unicode-org/icu/blob/HEAD/KEYS)
after confirming the new key out-of-band.
* Update the URL and SHA-256 hash for the full ICU file in
`tools/icu/current_ver.dep`. It should match the ICU URL used in the first
step. When this is done, the following should build with small ICU.

```bash
# clean up
Expand Down
Binary file added tools/dep_updaters/icu.kbx
Binary file not shown.
52 changes: 37 additions & 15 deletions tools/dep_updaters/update-icu.sh
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
#!/bin/sh
set -e
# Shell script to update icu in the source tree to a specific version
# Shell script to update icu in the source tree to a specific version.
# Pass `--update-keys` to update the local copy of the key files after verifying
# the upstream file history.

BASE_DIR=$(cd "$(dirname "$0")/../.." && pwd)
DEPS_DIR="$BASE_DIR/deps"
Expand Down Expand Up @@ -36,28 +38,48 @@ NEW_VERSION_TGZ="icu4c-${NEW_VERSION}-sources.tgz"

NEW_VERSION_TGZ_URL="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/${NEW_VERSION_TGZ}"

NEW_VERSION_MD5="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/icu4c-${NEW_VERSION}-sources.md5"

CHECKSUM=$(curl -sL "$NEW_VERSION_MD5" | grep "$NEW_VERSION_TGZ" | grep -v "\.asc$" | awk '{print $1}')
WORKSPACE=$(mktemp -d 2> /dev/null || mktemp -d -t 'tmp')
NEW_VERSION_TGZ_PATH="$WORKSPACE/$NEW_VERSION_TGZ"

cleanup () {
EXIT_CODE=$?
[ -d "$WORKSPACE" ] && rm -rf "$WORKSPACE"
exit $EXIT_CODE
}

trap cleanup INT TERM EXIT

echo "Fetching ICU source archive"
curl -sfL -o "$NEW_VERSION_TGZ_PATH" "$NEW_VERSION_TGZ_URL"

KEYRING="$BASE_DIR/tools/dep_updaters/icu.kbx"
if [ "$1" = "--update-keys" ]; then
KEYS_FILE="$WORKSPACE/KEYS"
GNUPGHOME="$WORKSPACE/gnupg"
mkdir -m 700 "$GNUPGHOME"
echo "Fetching the upstream KEYS file"
curl -sSLfo "$KEYS_FILE" "https://github.com/unicode-org/icu/raw/refs/tags/release-${NEW_VERSION}/KEYS"
GNUPGHOME="$GNUPGHOME" gpg --no-default-keyring --keyring "$WORKSPACE/icu.kbx" --batch --import --import-options import-minimal < "$KEYS_FILE"
mv "$WORKSPACE/icu.kbx" "$KEYRING"
fi

GENERATED_CHECKSUM=$( curl -sL "$NEW_VERSION_TGZ_URL" | md5sum | cut -d ' ' -f1)
echo "Verifying PGP signature"
curl -sfL -o "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_URL.asc"
gpgv --keyring "$KEYRING" "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_PATH"

echo "Comparing checksums: deposited '$CHECKSUM' with '$GENERATED_CHECKSUM'"
CHECKSUM=$(shasum -a 256 "$NEW_VERSION_TGZ_PATH" | cut -d ' ' -f1)
echo "sha256: $CHECKSUM"

if [ "$CHECKSUM" != "$GENERATED_CHECKSUM" ]; then
echo "Skipped because checksums do not match."
exit 0
fi

./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_URL"
./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_PATH"

"$TOOLS_DIR/icu/shrink-icu-src.py"

rm -rf "$DEPS_DIR/icu"

perl -i -pe "s|\"url\": .*|\"url\": \"$NEW_VERSION_TGZ_URL\",|" "$TOOLS_DIR/icu/current_ver.dep"

perl -i -pe "s|\"md5\": .*|\"md5\": \"$CHECKSUM\"|" "$TOOLS_DIR/icu/current_ver.dep"
URL="$NEW_VERSION_TGZ_URL" SHA256="$CHECKSUM" "$NODE" -e '
const { URL: url, SHA256: sha256 } = process.env;
console.log(JSON.stringify([{ url, sha256 }], null, 2));
' > "$TOOLS_DIR/icu/current_ver.dep"

rm -rf out "$DEPS_DIR/icu" "$DEPS_DIR/icu4c*"

Expand Down
2 changes: 1 addition & 1 deletion tools/icu/current_ver.dep
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[
{
"url": "https://github.com/unicode-org/icu/releases/download/release-78.3/icu4c-78.3-sources.tgz",
"md5": "a7b736b570ef0e180c96a31715a00c78"
"sha256": "3a2e7a47604ba702f345878308e6fefeca612ee895cf4a5f222e7955fabfe0c0"
}
]
Loading