forked from openwrt/docker
-
Notifications
You must be signed in to change notification settings - Fork 0
/
docker-download.sh
executable file
·49 lines (42 loc) · 1.48 KB
/
docker-download.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
#!/bin/bash
set -ex
export FILE_HOST="${FILE_HOST:-downloads.openwrt.org}"
export GNUPGHOME="${GNUPGHOME:-/keys/gpg/}"
export USIGNHOME="${USIGNHOME:-/keys/usign/}"
curl "https://$FILE_HOST/$DOWNLOAD_PATH/sha256sums" -fs -o sha256sums
curl "https://$FILE_HOST/$DOWNLOAD_PATH/sha256sums.asc" -fs -o sha256sums.asc || true
curl "https://$FILE_HOST/$DOWNLOAD_PATH/sha256sums.sig" -fs -o sha256sums.sig || true
if [ ! -f sha256sums.asc ] && [ ! -f sha256sums.sig ]; then
echo "Missing sha256sums signature files"
exit 1
fi
[ ! -f sha256sums.asc ] || gpg --with-fingerprint --verify sha256sums.asc sha256sums
if [ -f sha256sums.sig ]; then
if hash signify-openbsd 2>/dev/null; then
SIGNIFY_BIN=signify-openbsd # debian
else
SIGNIFY_BIN=signify # alpine
fi
VERIFIED=
for KEY in "$USIGNHOME"* ; do
echo "Trying $KEY..."
if "$SIGNIFY_BIN" -V -q -p "$KEY" -x sha256sums.sig -m sha256sums; then
echo "...verified"
VERIFIED=1
break
fi
done
if [ -z "$VERIFIED" ]; then
echo "Could not verify usign signature"
exit 1
fi
fi
FILE_NAME=$(grep "$DOWNLOAD_FILE" sha256sums | cut -d "*" -f 2)
wget "https://$FILE_HOST/$DOWNLOAD_PATH/$FILE_NAME" || exit 1
# shrink checksum file to single desired file and verify downloaded archive
grep "$FILE_NAME" sha256sums > sha256sums_min
sha256sum -c sha256sums_min
rm -f sha256sums{,_min,.sig,.asc}
mkdir -p ./build
tar xf "$FILE_NAME" --strip=1 -C ./build
rm -rf "$FILE_NAME"