#!/bin/sh # script/bootstrap: install all dependencies needed to build and develop # this repo. Idempotent: every install is guarded by a check so already # installed tools are skipped. Base tooling comes from nix, apt, brew, # or apk (detected in that order); assumes NOTHING is present (not git, # make, node, yarn, go, or python). Node is used directly if installed; # otherwise a pinned version is installed via nvm (installing nvm # itself first, from a hash-verified release archive, never curl | sh). # # Uncomment the language sections in main() that apply to this repo. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" # Pinned versions, 2026-07-06. Never "latest" or "lts"; exact versions. # The node version is in .nvmrc, where script/prettier reads it too. NODE_VERSION="$(cat "$ROOT/.nvmrc")" NVM_VERSION="0.40.3" # sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0" YARN_VERSION="1.22.22" # protoc v33.4, 2026-10-04, for script/generate. The sha256 of each # platform's release archive is in ensure_protoc. PROTOC_VERSION="33.4" PKGMGR="" SUDO="" detect_pkgmgr() { [ -n "$PKGMGR" ] && return 0 if command -v nix-env >/dev/null 2>&1; then PKGMGR="nix" elif command -v apt-get >/dev/null 2>&1; then PKGMGR="apt" elif command -v brew >/dev/null 2>&1; then PKGMGR="brew" elif command -v apk >/dev/null 2>&1; then PKGMGR="apk" else echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2 exit 1 fi if [ "$PKGMGR" = "apt" ]; then export DEBIAN_FRONTEND=noninteractive if [ "$(id -u)" != "0" ]; then SUDO="sudo" fi fi } # pkg_install pkg_install() { detect_pkgmgr case "$PKGMGR" in nix) nix-env -iA "nixpkgs.$1" ;; apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;; brew) brew install "$3" ;; apk) apk add --no-cache "$4" ;; esac } missing() { ! command -v "$1" >/dev/null 2>&1 } # verify_sha256 verify_sha256() { if command -v sha256sum >/dev/null 2>&1; then actual="$(sha256sum "$1" | cut -d' ' -f1)" else actual="$(shasum -a 256 "$1" | cut -d' ' -f1)" fi if [ "$actual" != "$2" ]; then echo "bootstrap: sha256 mismatch for $1" >&2 echo " expected: $2" >&2 echo " actual: $actual" >&2 exit 1 fi } # nvm is a bash script; run a command in a bash with nvm loaded. # --no-use: otherwise loading nvm here switches to the version .nvmrc # names, and fails silently while that version is not installed yet. nvm_sh() { bash -c ". \"\$HOME/.nvm/nvm.sh\" --no-use && $*" } ensure_nvm() { [ -s "$HOME/.nvm/nvm.sh" ] && return 0 # nvm prerequisites; nvm itself requires bash, so install it too if missing bash; then pkg_install bash bash bash bash; fi if missing curl; then pkg_install curl curl curl curl; fi if missing git; then pkg_install git git git git; fi tmp="$(mktemp -d)" curl -fsSL -o "$tmp/nvm.tar.gz" \ "https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz" verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256" mkdir -p "$HOME/.nvm" tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1 rm -rf "$tmp" } ensure_node() { if ! missing node; then return 0; fi ensure_nvm nvm_sh "nvm install $NODE_VERSION" } ensure_yarn() { if ! missing yarn; then return 0; fi if ! missing corepack; then corepack enable corepack prepare "yarn@$YARN_VERSION" --activate elif [ -s "$HOME/.nvm/nvm.sh" ]; then nvm_sh "nvm use $NODE_VERSION >/dev/null && corepack enable && \ corepack prepare yarn@$YARN_VERSION --activate" else npm install -g "yarn@$YARN_VERSION" fi } install_js_deps() { if missing yarn && [ -s "$HOME/.nvm/nvm.sh" ]; then nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && \ yarn install --frozen-lockfile" else yarn install --frozen-lockfile fi } # Unpack protoc's release archive for this platform into bin/protoc, after # checking the archive's sha256, unless bin/protoc already holds the pinned # version. ensure_protoc() { dir="$ROOT/bin/protoc" if [ "$("$dir/bin/protoc" --version 2>/dev/null)" = \ "libprotoc $PROTOC_VERSION" ]; then return 0 fi case "$(uname -s) $(uname -m)" in "Linux x86_64") platform="linux-x86_64" sha256="c0040ea9aef08fdeb2c74ca609b18d5fdbfc44ea0042fcfbfb38860d35f7dd66" ;; "Linux aarch64" | "Linux arm64") platform="linux-aarch_64" sha256="15aa988f4a6090636525ec236a8e4b3aab41eef402751bd5bb2df6afd9b7b5a5" ;; "Darwin x86_64") platform="osx-x86_64" sha256="a49bec10d039e902d3b43e49938c42526f90011467609864fa6386ac4014da58" ;; "Darwin arm64") platform="osx-aarch_64" sha256="726297dcfed58592fd35620a5a6246ae020c39e88f3fd4cb1827df7bcf3dfcf1" ;; *) echo "bootstrap: no protoc archive pinned for $(uname -s) $(uname -m)" >&2 exit 1 ;; esac if missing curl; then pkg_install curl curl curl curl; fi if missing unzip; then pkg_install unzip unzip unzip unzip; fi tmp="$(mktemp -d)" curl -fsSL -o "$tmp/protoc.zip" \ "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOC_VERSION}/protoc-${PROTOC_VERSION}-${platform}.zip" verify_sha256 "$tmp/protoc.zip" "$sha256" rm -rf "$dir" unzip -q "$tmp/protoc.zip" -d "$dir" rm -rf "$tmp" } main() { cd "$ROOT" # Base tooling (every repo) if missing git; then pkg_install git git git git; fi if missing make; then pkg_install gnumake make make make; fi # ---- JS / docs repos ---- # This is a Go repo, but node and yarn are required anyway: prettier # formats the Markdown and JSON, and script/fmt-check verifies it. # The version is pinned by package.json/yarn.lock: yarn checks every # package it fetches against its yarn.lock integrity hash, and # --frozen-lockfile fails instead of rewriting a yarn.lock that no # longer matches package.json. ensure_node ensure_yarn install_js_deps # ---- Go repos ---- if missing go; then pkg_install go golang go go; fi # No golangci-lint: script/lint runs it in Docker only. go mod download # gofumpt and protoc-gen-go: bin/tools/go.mod pins them, and # script/gofumpt and script/generate build them from there. (cd "$ROOT/bin/tools" && go mod download) ensure_protoc # ---- Python repos ---- # if missing python3; then pkg_install python3 python3 python3 python3; fi # python3 -m venv .venv # ./.venv/bin/pip install -e '.[dev]' echo "bootstrap complete" } main "$@"