A failed release build no longer leaves a complete, loadable debug bundle in dist/ whose every wallet uses the publicly committed test recovery phrase. Each step of the release build runs through script/discard-dist-on-failure, which removes dist/ on failure, says on stderr that it did and why, and returns the step's own status. build-debug is deliberately unwrapped. script/verify-build is untouched.
110 lines
3.7 KiB
Makefile
110 lines
3.7 KiB
Makefile
.PHONY: bootstrap setup install test test-e2e test-e2e-firefox lint fmt fmt-check check check-censored docker hooks build build-debug vendor-blocklist clean dev
|
|
|
|
# Standard targets are thin shims; the implementations live in script/
|
|
# per the scripts-to-rule-them-all pattern (see the Entrypoints section
|
|
# of README.md).
|
|
|
|
bootstrap:
|
|
@script/bootstrap
|
|
|
|
setup:
|
|
@script/setup
|
|
|
|
install:
|
|
@yarn install --frozen-lockfile
|
|
|
|
test:
|
|
@script/test
|
|
|
|
# Browser end-to-end suites. Both require docker; neither is part of check.
|
|
test-e2e:
|
|
@script/test-e2e
|
|
|
|
test-e2e-firefox:
|
|
@script/test-e2e-firefox
|
|
|
|
lint:
|
|
@script/lint
|
|
|
|
fmt:
|
|
@script/fmt
|
|
|
|
fmt-check:
|
|
@script/fmt-check
|
|
|
|
check:
|
|
@script/check
|
|
|
|
# Assert that the competitor name appears nowhere but its documented
|
|
# exceptions. Part of check, and re-run against dist/ at the end of a build;
|
|
# separate target for re-running it alone.
|
|
check-censored:
|
|
@script/check-censored
|
|
|
|
docker:
|
|
@script/docker
|
|
|
|
hooks:
|
|
@script/install-precommit
|
|
|
|
# build.js writes a receipt of everything it emitted — every path, its sha256,
|
|
# and whether it is a bundle containing constants.js — and script/verify-build
|
|
# checks dist/ against that. The receipt is made here, fresh per invocation,
|
|
# outside the repo, and deleted again: a standing file inside dist/ would be
|
|
# rewritten by whoever rewrote dist/, which is what made the old check
|
|
# satisfiable by a hand-written tree.
|
|
#
|
|
# The expected mode is an explicit argument and AUTISTMASK_DEBUG is scrubbed
|
|
# from the verifier's environment. The script no longer reads it at all; env -u
|
|
# is here so that stays true of anything it calls. It is deliberately NOT
|
|
# scrubbed from the build itself: with AUTISTMASK_DEBUG=1 exported, this target
|
|
# compiles a debug bundle and then fails on it, loudly, rather than quietly
|
|
# handing back something other than the release build that was asked for.
|
|
#
|
|
# Every step of this target is wrapped in script/discard-dist-on-failure, so a
|
|
# release build that fails removes dist/ instead of leaving a complete, loadable
|
|
# debug bundle there for whoever runs the build, sees it fail, and loads
|
|
# dist/chrome/ anyway. A step that succeeds removes nothing, and build-debug is
|
|
# deliberately not wrapped.
|
|
build:
|
|
@echo "Building extension..."
|
|
@set -eu; \
|
|
receipt="$$(mktemp "$${TMPDIR:-/tmp}/autistmask-build-receipt.XXXXXX")"; \
|
|
trap 'rm -f "$$receipt"' EXIT INT TERM; \
|
|
script/discard-dist-on-failure \
|
|
env AUTISTMASK_BUILD_RECEIPT="$$receipt" yarn run build 2>&1; \
|
|
script/discard-dist-on-failure \
|
|
env -u AUTISTMASK_DEBUG script/verify-build --expect release \
|
|
--receipt "$$receipt"
|
|
@script/discard-dist-on-failure script/check-censored --require-dist
|
|
|
|
# Development-only build: enables the red DEBUG / INSECURE banner and makes
|
|
# the hardcoded test recovery phrase the output of wallet creation. Never
|
|
# distribute the artifacts this produces.
|
|
#
|
|
# No discard-dist-on-failure here, on purpose: a debug build that fails is not
|
|
# producing an artifact anyone could mistake for a release one, and its dist/ is
|
|
# the evidence of what went wrong.
|
|
build-debug:
|
|
@echo "Building extension (DEBUG)..."
|
|
@set -eu; \
|
|
receipt="$$(mktemp "$${TMPDIR:-/tmp}/autistmask-build-receipt.XXXXXX")"; \
|
|
trap 'rm -f "$$receipt"' EXIT INT TERM; \
|
|
AUTISTMASK_DEBUG=1 AUTISTMASK_BUILD_RECEIPT="$$receipt" yarn run build 2>&1; \
|
|
env -u AUTISTMASK_DEBUG script/verify-build --expect debug \
|
|
--receipt "$$receipt"
|
|
@script/check-censored --require-dist
|
|
|
|
# Refresh src/shared/phishingBlocklist.json from its hash-pinned upstream.
|
|
# Run deliberately, land the diff: the extension does no runtime fetching, so
|
|
# the shipped list is as fresh as the last vendoring run that was released.
|
|
vendor-blocklist:
|
|
@script/vendor-blocklist
|
|
|
|
clean:
|
|
@rm -rf dist/
|
|
|
|
dev:
|
|
@echo "Building in watch mode..."
|
|
@yarn run build --watch 2>&1
|