#!/bin/sh # script/bootstrap: install everything needed to build and develop this # repo. Idempotent: every install is guarded by a check, so tools that # are already there are left alone. Base tooling comes from nix, apt, # brew, or apk, detected in that order, and nothing is assumed to be # present. Go is installed at the version the Dockerfile's Go image # carries, from the official release archive, into ~/.local/go. Node is # used directly if installed; otherwise it is installed at a pinned # version via nvm (installing nvm itself first, from a hash-verified # release archive, never curl | sh). The linter is not installed here: # linting and testing run only as phases of the Dockerfile, so Docker is # what is needed for them, and that is checked for rather than # installed. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" # Must match the Go in the Dockerfile's golang image; the sha256 of each # archive is in install_go. GO_VERSION="1.26.8" # This script cannot change its caller's PATH, so script/fmt, # script/fmt-check, script/precommit and the Makefile put this directory # first on their own PATH, as is done here. GO_DIR="$HOME/.local/go" PATH="$GO_DIR/bin:$PATH" # Pinned versions, 2026-07-06 NODE_VERSION="22.17.0" NVM_VERSION="0.40.3" # sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0" YARN_VERSION="1.22.22" PKGMGR="" SUDO="" detect_pkgmgr() { [ -n "$PKGMGR" ] && return 0 if command -v nix-env >/dev/null 2>&1; then PKGMGR="nix" elif command -v apt-get >/dev/null 2>&1; then PKGMGR="apt" elif command -v brew >/dev/null 2>&1; then PKGMGR="brew" elif command -v apk >/dev/null 2>&1; then PKGMGR="apk" else echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2 exit 1 fi if [ "$PKGMGR" = "apt" ]; then export DEBIAN_FRONTEND=noninteractive if [ "$(id -u)" != "0" ]; then SUDO="sudo" fi # This runs once, before the first install: a fresh host or # runner image has no package lists yet. $SUDO apt-get update fi } # pkg_install pkg_install() { detect_pkgmgr case "$PKGMGR" in nix) nix-env -iA "nixpkgs.$1" ;; apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;; brew) brew install "$3" ;; apk) apk add --no-cache "$4" ;; esac } missing() { ! command -v "$1" >/dev/null 2>&1 } # verify_sha256 verify_sha256() { if command -v sha256sum >/dev/null 2>&1; then actual="$(sha256sum "$1" | cut -d' ' -f1)" else actual="$(shasum -a 256 "$1" | cut -d' ' -f1)" fi if [ "$actual" != "$2" ]; then echo "bootstrap: sha256 mismatch for $1" >&2 echo " expected: $2" >&2 echo " actual: $actual" >&2 exit 1 fi } # True when the go first on PATH reports exactly GO_VERSION. No go, a go # that fails, or any other output is a mismatch. go_version_matches() { out="$(go version 2>/dev/null)" || return 1 case "$out" in "go version go$GO_VERSION "*) return 0 ;; *) return 1 ;; esac } install_go() { # sha256 of the go1.26.8 archives at https://go.dev/dl/, 2026-10-04 case "$(uname -s)-$(uname -m)" in Linux-x86_64) platform="linux-amd64" sha256="d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b" ;; Linux-aarch64) platform="linux-arm64" sha256="211ffced9dcb9633a55eac6364816ec0ddd951389a740e88fa8b3337971bdda0" ;; Darwin-x86_64) platform="darwin-amd64" sha256="186be014105aa6542b767d2c6ed5cca10a0214bdff809ef1724022a8c7894150" ;; Darwin-arm64) platform="darwin-arm64" sha256="a012b25b571bd0138a03dcd25375ceba866fe5ca822f426d2c66a4de56fd3f4b" ;; *) echo "bootstrap: no Go archive pinned for $(uname -s) $(uname -m)" >&2 exit 1 ;; esac if missing curl; then pkg_install curl curl curl curl; fi tmp="$(mktemp -d)" curl -fsSL -o "$tmp/go.tar.gz" \ "https://go.dev/dl/go${GO_VERSION}.${platform}.tar.gz" verify_sha256 "$tmp/go.tar.gz" "$sha256" # An archive unpacked over an older Go leaves a broken tree. rm -rf "$GO_DIR" mkdir -p "$GO_DIR" tar -xzf "$tmp/go.tar.gz" -C "$GO_DIR" --strip-components=1 rm -rf "$tmp" } # nvm is a bash script; run a command in a bash with nvm loaded nvm_sh() { bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*" } ensure_nvm() { [ -s "$HOME/.nvm/nvm.sh" ] && return 0 # nvm prerequisites; nvm itself requires bash if missing bash; then pkg_install bash bash bash bash; fi if missing curl; then pkg_install curl curl curl curl; fi if missing git; then pkg_install git git git git; fi tmp="$(mktemp -d)" curl -fsSL -o "$tmp/nvm.tar.gz" \ "https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz" verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256" mkdir -p "$HOME/.nvm" tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1 rm -rf "$tmp" } ensure_node() { if ! missing node; then return 0; fi ensure_nvm nvm_sh "nvm install $NODE_VERSION" } ensure_yarn() { if ! missing yarn; then return 0; fi if ! missing corepack; then corepack enable corepack prepare "yarn@$YARN_VERSION" --activate elif [ -s "$HOME/.nvm/nvm.sh" ]; then nvm_sh "nvm use $NODE_VERSION >/dev/null && corepack enable && \ corepack prepare yarn@$YARN_VERSION --activate" else npm install -g "yarn@$YARN_VERSION" fi } install_js_deps() { if missing yarn && [ -s "$HOME/.nvm/nvm.sh" ]; then nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && \ yarn install --frozen-lockfile" else yarn install --frozen-lockfile fi } main() { cd "$ROOT" if missing git; then pkg_install git git git git; fi if missing make; then pkg_install gnumake make make make; fi if ! go_version_matches; then install_go hash -r if ! go_version_matches; then echo "bootstrap: $(command -v go) is not go$GO_VERSION after installing it" >&2 exit 1 fi fi go version go mod download ensure_node ensure_yarn install_js_deps if missing docker; then echo "bootstrap: docker is not installed; make lint and make test need it" >&2 fi echo "bootstrap complete" } main "$@"