This commit is contained in:
Executable
+77
@@ -0,0 +1,77 @@
|
||||
#!/usr/bin/env zsh
|
||||
|
||||
set -eu
|
||||
|
||||
for cmd in git sops openssl; do
|
||||
if ! command -v "${cmd}" >/dev/null 2>&1; then
|
||||
echo "check-sops-sync: required command missing: ${cmd}" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
if [ -z "${SOPS_SYNC_HMAC_KEY:-}" ]; then
|
||||
echo "check-sops-sync: SOPS_SYNC_HMAC_KEY is required" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
repo_root=$(git rev-parse --show-toplevel)
|
||||
regex_script="${repo_root}/scripts/lib/sops-path-regexes"
|
||||
lib_script="${repo_root}/scripts/lib/sops-sync-lib"
|
||||
|
||||
if [ ! -x "${regex_script}" ]; then
|
||||
echo "check-sops-sync: missing helper ${regex_script}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ ! -f "${lib_script}" ]; then
|
||||
echo "check-sops-sync: missing helper ${lib_script}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
. "${lib_script}"
|
||||
|
||||
regexes=("${(@f)$("${regex_script}")}")
|
||||
fail=0
|
||||
|
||||
while IFS= read -r tracked_path; do
|
||||
[ -n "${tracked_path}" ] || continue
|
||||
[[ "${tracked_path}" == *.enc.* ]] || continue
|
||||
|
||||
if ! matches_any_rule "${tracked_path}" "${regexes[@]}"; then
|
||||
continue
|
||||
fi
|
||||
|
||||
sidecar_path=$(hmac_sidecar_for_enc "${tracked_path}")
|
||||
|
||||
if ! git ls-files --error-unmatch -- "${sidecar_path}" >/dev/null 2>&1; then
|
||||
echo "check-sops-sync: missing sync sidecar for ${tracked_path}" >&2
|
||||
fail=1
|
||||
continue
|
||||
fi
|
||||
|
||||
if ! is_sops_encrypted_file "${tracked_path}"; then
|
||||
echo "check-sops-sync: file is not valid SOPS-encrypted content: ${tracked_path}" >&2
|
||||
fail=1
|
||||
continue
|
||||
fi
|
||||
|
||||
sidecar_value=$(read_sidecar "${sidecar_path}" || true)
|
||||
if [ -z "${sidecar_value}" ]; then
|
||||
echo "check-sops-sync: sidecar is empty: ${sidecar_path}" >&2
|
||||
fail=1
|
||||
continue
|
||||
fi
|
||||
|
||||
if ! computed_hmac=$(decrypt_enc_to_plain "${tracked_path}" | compute_hmac_for_stdin); then
|
||||
echo "check-sops-sync: failed to decrypt ${tracked_path}" >&2
|
||||
fail=1
|
||||
continue
|
||||
fi
|
||||
|
||||
if [ "${computed_hmac}" != "${sidecar_value}" ]; then
|
||||
echo "check-sops-sync: decrypted plaintext HMAC does not match sidecar for ${tracked_path}" >&2
|
||||
fail=1
|
||||
fi
|
||||
done < <(git ls-files)
|
||||
|
||||
exit "${fail}"
|
||||
Reference in New Issue
Block a user