#!/usr/bin/env bash # Run on Linux/WSL with a previously SHA-256-verified official Go tarball. # The caller owns download provenance. No package installation or production SSH. set -euo pipefail if [[ $# != 1 || ! -f "$1" ]]; then printf 'usage: bash scripts/verify-linux.sh /path/to/verified-go.linux-amd64.tar.gz\n' >&2 exit 2 fi task_dir=$(mktemp -d /tmp/server-deploy-test.XXXXXX) tar -xzf "$1" -C "$task_dir" export GOCACHE="$task_dir/cache" cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." "$task_dir/go/bin/go" test ./... -count=1 -v -timeout=60s "$task_dir/go/bin/go" vet ./... "$task_dir/go/bin/go" test -race ./... -count=1 -timeout=60s "$task_dir/go/bin/go" build -o "$task_dir/deployctl" ./cmd/deployctl "$task_dir/deployctl" plan < protocol/examples/plan-request.json "$task_dir/deployctl" inspect "$task_dir/deployctl" preflight if [[ "${DEPLOYCTL_ONLINE_REPOSITORY_PROBE:-0}" == 1 ]]; then DEPLOYCTL_TEST_GO="$task_dir/go/bin/go" bash scripts/probe-docker-repository.sh "$task_dir/deployctl" fi printf 'Verification artifacts retained at: %s\n' "$task_dir"