|
| 1 | +#!/usr/bin/env bash |
| 2 | +# SPDX-License-Identifier: MPL-2.0 |
| 3 | +# |
| 4 | +# Install a pinned, hash-verified Zig toolchain for CI — no third-party action. |
| 5 | +# |
| 6 | +# Why this exists: the repo's Actions policy admits only GitHub-owned and |
| 7 | +# Marketplace-verified-creator actions. mlugg/setup-zig is neither, so every |
| 8 | +# workflow that used it ended in startup_failure before running a single step |
| 9 | +# (game-server-admin#103). This script needs no action at all. |
| 10 | +# |
| 11 | +# Trust chain: the tarball is fetched from ziglang.org over HTTPS and must |
| 12 | +# match the sha256 pinned below, or the step fails. At pin time (2026-09-30) |
| 13 | +# the tarball's minisign signature was verified against the Zig Software |
| 14 | +# Foundation release key |
| 15 | +# RWSGOq2NVecA2UPNdBUZykf1CCb147pkmdtYxgb3Ti+JO/wCYvhbAb/U |
| 16 | +# (file signature and trusted-comment signature, timestamp:1760215991), and a |
| 17 | +# one-byte-altered digest was rejected as a negative control. The committed |
| 18 | +# sha256 carries that binding into CI. |
| 19 | +# |
| 20 | +# To bump: change ZIG_VERSION and ZIG_SHA256 together, taking the shasum from |
| 21 | +# https://ziglang.org/download/index.json and re-verifying the .minisig. |
| 22 | +# |
| 23 | +# Usage: bash scripts/install-zig.sh |
| 24 | +# Puts `zig` on PATH for subsequent steps via $GITHUB_PATH. |
| 25 | + |
| 26 | +set -euo pipefail |
| 27 | + |
| 28 | +ZIG_VERSION="0.15.2" |
| 29 | +ZIG_SHA256_X86_64_LINUX="02aa270f183da276e5b5920b1dac44a63f1a49e55050ebde3aecc9eb82f93239" |
| 30 | + |
| 31 | +os="$(uname -s)" |
| 32 | +arch="$(uname -m)" |
| 33 | +if [ "$os" != "Linux" ] || [ "$arch" != "x86_64" ]; then |
| 34 | + echo "::error::install-zig.sh pins only x86_64-linux; got ${os}/${arch}. Add a pinned sha256 for this platform." >&2 |
| 35 | + exit 1 |
| 36 | +fi |
| 37 | + |
| 38 | +tarball="zig-x86_64-linux-${ZIG_VERSION}.tar.xz" |
| 39 | +url="https://ziglang.org/download/${ZIG_VERSION}/${tarball}" |
| 40 | + |
| 41 | +dest_root="${RUNNER_TEMP:?RUNNER_TEMP must be set (GitHub Actions)}" |
| 42 | +work="${dest_root}/zig-download" |
| 43 | +dest="${dest_root}/zig-${ZIG_VERSION}" |
| 44 | +mkdir -p "$work" "$dest" |
| 45 | + |
| 46 | +curl --proto '=https' --tlsv1.2 -fsSL --retry 5 --retry-delay 5 \ |
| 47 | + -o "${work}/${tarball}" "$url" |
| 48 | + |
| 49 | +echo "${ZIG_SHA256_X86_64_LINUX} ${work}/${tarball}" | sha256sum -c - |
| 50 | + |
| 51 | +tar -xJf "${work}/${tarball}" -C "$dest" --strip-components=1 |
| 52 | +rm -rf "$work" |
| 53 | + |
| 54 | +got="$("${dest}/zig" version)" |
| 55 | +if [ "$got" != "$ZIG_VERSION" ]; then |
| 56 | + echo "::error::installed zig reports '${got}', expected '${ZIG_VERSION}'" >&2 |
| 57 | + exit 1 |
| 58 | +fi |
| 59 | + |
| 60 | +echo "$dest" >> "${GITHUB_PATH:?GITHUB_PATH must be set (GitHub Actions)}" |
| 61 | +echo "Installed zig ${got} at ${dest}" |
0 commit comments