pcbjam/scripts/deps/build-curl-headers.sh
Gergő Törcsvári f6b0aaf122
findings X-1: pin every dependency tarball fetch to a SHA256 and enforce it
security-audit-v3 #15. download_file already had a verify branch; no caller
used it and every *_SHA256 in versions.sh was a commented placeholder, so a
tampered mirror tarball flowed straight into configure/make and the shipped
WASM.

- versions.sh: 13 pins (cross-checked against Homebrew/Buildroot/nixpkgs/
  FreeBSD/vcpkg/boost.org/curl PGP; glm .zip is TOFU), boost/curl/libgit2
  versions moved beside their pins.
- all 13 download_file call sites pass "${NAME_SHA256}".
- download_file refuses an empty or malformed pin (PCBJAM_ALLOW_UNPINNED=1
  to bootstrap a new dep); file_sha256 prefers sha256sum, falls back to shasum.
- scripts/deps/check-pins.sh: static 3-arg check + offline file:// enforcement
  test; runs in wasm-build.yml before the deps cache, on cache hits too.

Expect one cold --build-deps run: the deps-cache key hashes versions.sh.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GcsgJZ77bhZatLAVU8R84H
2026-08-28 20:34:16 +02:00

59 lines
1.6 KiB
Shell
Executable file

#!/bin/bash
# Download CURL headers for WebAssembly builds
# We only need the headers - CURL functions will be stubbed for WASM
# since networking uses browser fetch API, not native sockets
set -e
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
source "${SCRIPT_DIR}/../common/env.sh"
source "${SCRIPT_DIR}/../common/versions.sh"
source "${SCRIPT_DIR}/../common/functions.sh"
CURL_VERSION="${CURL_VERSION:-8.5.0}"
CURL_DIR="${DEPS_ROOT}/curl-${CURL_VERSION}"
CURL_STAMP="${BUILD_ROOT}/stamps/curl-headers.stamp"
# Parse arguments
CLEAN=0
for arg in "$@"; do
case $arg in
--clean)
CLEAN=1
shift
;;
esac
done
if [ $CLEAN -eq 1 ]; then
log_info "Cleaning CURL headers..."
rm -rf "${CURL_DIR}" "${CURL_STAMP}"
rm -rf "${SYSROOT}/include/curl"
fi
# Check if already installed
if check_stamp "${CURL_STAMP}"; then
log_info "CURL headers already installed, skipping..."
exit 0
fi
# Download if needed
if [ ! -d "${CURL_DIR}" ]; then
log_info "Downloading CURL ${CURL_VERSION} headers..."
mkdir -p "${DEPS_ROOT}"
cd "${DEPS_ROOT}"
# Download from curl official releases
CURL_URL="https://curl.se/download/curl-${CURL_VERSION}.tar.gz"
download_file "${CURL_URL}" "curl-${CURL_VERSION}.tar.gz" "${CURL_SHA256}"
tar -xzf "curl-${CURL_VERSION}.tar.gz"
rm "curl-${CURL_VERSION}.tar.gz"
fi
# Install headers only (no build needed - header-only for WASM stub)
log_info "Installing CURL headers to sysroot..."
mkdir -p "${SYSROOT}/include/curl"
cp "${CURL_DIR}/include/curl/"*.h "${SYSROOT}/include/curl/"
create_stamp "${CURL_STAMP}"
log_info "CURL headers installed!"