#!/usr/bin/env bash set -euo pipefail export GOTOOLCHAIN=local repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)" cd "${repo_root}" usage() { echo "usage: verify.sh infra [tofu-route|quadlets] | ipv6 | sites [OUTPUT] | luci-e2e | luci-mutation [OUTPUT] | go [PATH...] | go-race [PATH...] | go-staticcheck [PATH...] | go-vuln [PATH...] | luci-bench COUNT OUTPUT | luci-benchstat BASELINE CANDIDATE" >&2 exit 2 } repository_path() { local path path="$(realpath -m "$1")" [[ "${path}" == "${repo_root}"/* ]] || { echo "path outside repository: $1" >&2 exit 2 } printf '%s\n' "${path}" } existing_repository_file() { local path path="$(realpath "$1")" [[ -f "${path}" ]] || { echo "file not found: $1" >&2 exit 2 } [[ "${path}" == "${repo_root}"/* ]] || { echo "path outside repository: $1" >&2 exit 2 } printf '%s\n' "${path}" } untracked_repository_output() { local path relative path="$(repository_path "$1")" relative="${path#"${repo_root}"/}" git -C "${repo_root}" ls-files --error-unmatch -- "${relative}" >/dev/null 2>&1 && { echo "output is tracked: $1" >&2 exit 2 } printf '%s\n' "${path}" } benchmark_file() { local path line pattern found=false path="$(existing_repository_file "$1")" pattern='^Benchmark(BuildDashboard|BuildRun)(/[^[:space:]]+)?-[0-9]+[[:space:]]+[1-9][0-9]*[[:space:]]+([0-9]+|[0-9]*\.[0-9]+)[[:space:]]+ns/op([[:space:]].*)?$' while IFS= read -r line || [[ -n "${line}" ]]; do [[ "${line}" == Benchmark* ]] || continue [[ "${line}" =~ ${pattern} ]] || { echo "malformed Luci benchmark result in: $1" >&2 exit 2 } found=true done <"${path}" ${found} || { echo "no Luci benchmark results in: $1" >&2 exit 2 } printf '%s\n' "${path}" } target="${1:-}" [[ -n "${target}" ]] || usage shift case "${target}" in infra) [[ "$#" -le 1 ]] || usage exec "${repo_root}/scripts/local/verify-infra.sh" "$@" ;; ipv6) [[ "$#" -eq 0 ]] || usage exec "${repo_root}/scripts/local/verify-ipv6.sh" ;; sites) [[ "$#" -le 1 ]] || usage exec "${repo_root}/scripts/local/verify-sites-chrome.mjs" "${1:-/tmp/nugu-real-chrome-current}" ;; luci-e2e) [[ "$#" -eq 0 ]] || usage exec "${repo_root}/scripts/local/luci-manual-e2e.sh" ;; luci-mutation) [[ "$#" -le 1 ]] || usage output="$(untracked_repository_output "${1:-${repo_root}/services/luci/target/luci-gremlins.json}")" mkdir -p "$(dirname "${output}")" cd "${repo_root}/services/luci" exec go tool gremlins unleash . --workers 8 --exclude-files '(^|/)(target|generated|vendor)/' --threshold-efficacy 80 --threshold-mcover 100 --output "${output}" ;; go) "${repo_root}/scripts/local/go.sh" race "$@" "${repo_root}/scripts/local/go.sh" staticcheck "$@" exec "${repo_root}/scripts/local/go.sh" vuln "$@" ;; go-race) exec "${repo_root}/scripts/local/go.sh" race "$@" ;; go-staticcheck) exec "${repo_root}/scripts/local/go.sh" staticcheck "$@" ;; go-vuln) exec "${repo_root}/scripts/local/go.sh" vuln "$@" ;; luci-bench) [[ "$#" -eq 2 ]] || usage [[ "$1" =~ ^[1-9][0-9]*$ ]] || { echo "benchmark count must be a positive integer" >&2 exit 2 } output="$(untracked_repository_output "$2")" mkdir -p "$(dirname "${output}")" cd "${repo_root}/services/luci" GOMAXPROCS=1 go test ./internal/web -run '^$' -bench '^(BenchmarkBuildDashboard|BenchmarkBuildRun)$' -benchtime=3s -count="$1" | tee "${output}" grep -q '^Benchmark\(BuildDashboard\|BuildRun\)' "${output}" || { echo "no benchmark results written: ${output}" >&2 exit 1 } ;; luci-benchstat) [[ "$#" -eq 2 ]] || usage baseline="$(benchmark_file "$1")" candidate="$(benchmark_file "$2")" cd "${repo_root}/services/luci" exec go tool benchstat "${baseline}" "${candidate}" ;; *) echo "unknown verification target: ${target}" >&2 usage ;; esac