78 lines
1.9 KiB
Bash
Executable File
78 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env zsh
|
|
|
|
set -eu
|
|
|
|
for cmd in git sops openssl; do
|
|
if ! command -v "${cmd}" >/dev/null 2>&1; then
|
|
echo "check-sops-sync: required command missing: ${cmd}" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
if [ -z "${SOPS_SYNC_HMAC_KEY:-}" ]; then
|
|
echo "check-sops-sync: SOPS_SYNC_HMAC_KEY is required" >&2
|
|
exit 1
|
|
fi
|
|
|
|
repo_root=$(git rev-parse --show-toplevel)
|
|
regex_script="${repo_root}/scripts/lib/sops-path-regexes"
|
|
lib_script="${repo_root}/scripts/lib/sops-sync-lib"
|
|
|
|
if [ ! -x "${regex_script}" ]; then
|
|
echo "check-sops-sync: missing helper ${regex_script}" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ ! -f "${lib_script}" ]; then
|
|
echo "check-sops-sync: missing helper ${lib_script}" >&2
|
|
exit 1
|
|
fi
|
|
|
|
. "${lib_script}"
|
|
|
|
regexes=("${(@f)$("${regex_script}")}")
|
|
fail=0
|
|
|
|
while IFS= read -r tracked_path; do
|
|
[ -n "${tracked_path}" ] || continue
|
|
[[ "${tracked_path}" == *.enc.* ]] || continue
|
|
|
|
if ! matches_any_rule "${tracked_path}" "${regexes[@]}"; then
|
|
continue
|
|
fi
|
|
|
|
sidecar_path=$(hmac_sidecar_for_enc "${tracked_path}")
|
|
|
|
if ! git ls-files --error-unmatch -- "${sidecar_path}" >/dev/null 2>&1; then
|
|
echo "check-sops-sync: missing sync sidecar for ${tracked_path}" >&2
|
|
fail=1
|
|
continue
|
|
fi
|
|
|
|
if ! is_sops_encrypted_file "${tracked_path}"; then
|
|
echo "check-sops-sync: file is not valid SOPS-encrypted content: ${tracked_path}" >&2
|
|
fail=1
|
|
continue
|
|
fi
|
|
|
|
sidecar_value=$(read_sidecar "${sidecar_path}" || true)
|
|
if [ -z "${sidecar_value}" ]; then
|
|
echo "check-sops-sync: sidecar is empty: ${sidecar_path}" >&2
|
|
fail=1
|
|
continue
|
|
fi
|
|
|
|
if ! computed_hmac=$(decrypt_enc_to_plain "${tracked_path}" | compute_hmac_for_stdin); then
|
|
echo "check-sops-sync: failed to decrypt ${tracked_path}" >&2
|
|
fail=1
|
|
continue
|
|
fi
|
|
|
|
if [ "${computed_hmac}" != "${sidecar_value}" ]; then
|
|
echo "check-sops-sync: decrypted plaintext HMAC does not match sidecar for ${tracked_path}" >&2
|
|
fail=1
|
|
fi
|
|
done < <(git ls-files)
|
|
|
|
exit "${fail}"
|