Repository navigation
Expand file tree
/
Copy pathMakefile
More file actions
88 lines (72 loc) · 3.35 KB
/
Copy pathMakefile
File metadata and controls
88 lines (72 loc) · 3.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
# Delilah -- build and conformance.
#
# Builds happen on the pinned build host (D020), never on `claude`.
# CGO stays off: the client must be a static binary that cross-compiles to
# macOS from Linux (D017, D034), which D013 makes a requirement rather than a
# convenience.
BIN := delilah
PKG := ./cmd/delilah
GOFLAGS := -trimpath
LDFLAGS := -s -w
export CGO_ENABLED = 0
.PHONY: all build cross mac verify test fmt vet clean
all: fmt vet test build
## test: Go tests, which run against the SAME published vectors verify.sh uses.
## If these and `make verify` ever disagree, one of them is wrong and the
## disagreement is the finding (D019).
test:
go test ./...
build:
go build $(GOFLAGS) -ldflags '$(LDFLAGS)' -o $(BIN) $(PKG)
## mac: the build Marcel actually runs. Apple Silicon, no cgo, no signing (D033).
mac:
@mkdir -p dist
GOOS=darwin GOARCH=arm64 go build $(GOFLAGS) -ldflags '$(LDFLAGS)' -o dist/$(BIN)-darwin-arm64 $(PKG)
@cd dist && sha256sum $(BIN)-darwin-arm64 > $(BIN)-darwin-arm64.sha256
@echo
@echo " dist/$(BIN)-darwin-arm64"
@echo
@echo " Fetch it with curl, NOT a browser: a browser marks the download with"
@echo " com.apple.quarantine and Gatekeeper will refuse to run it. curl does not."
@echo " Delilah ships unsigned on purpose -- a signing subscription that lapses"
@echo " would break installation years from now, which is exactly when it matters."
## cross: every platform an executor might already own (D013)
cross:
@mkdir -p dist
@for t in darwin/arm64 darwin/amd64 linux/amd64 linux/arm64 windows/amd64; do \
os=$${t%/*}; arch=$${t#*/}; ext=''; \
[ "$$os" = windows ] && ext='.exe'; \
GOOS=$$os GOARCH=$$arch go build $(GOFLAGS) -ldflags '$(LDFLAGS)' \
-o dist/$(BIN)-$$os-$$arch$$ext $(PKG) || exit 1; \
echo " built dist/$(BIN)-$$os-$$arch$$ext"; \
GOOS=$$os GOARCH=$$arch go build $(GOFLAGS) -ldflags '$(LDFLAGS)' \
-o dist/$(BIN)-fido-$$os-$$arch$$ext ./cmd/delilah-fido || exit 1; \
echo " built dist/$(BIN)-fido-$$os-$$arch$$ext"; \
done
@cd dist && sha256sum $(BIN)-* > SHA256SUMS
@echo " wrote dist/SHA256SUMS -- sign it on Marcel's Mac, never here (D042)"
## verify: the acceptance test. Stock tools, no project code (D018, D019).
## An implementation is conformant when this passes against a vault it produced.
verify:
./spec/vectors/verify.sh
fmt:
go fmt ./...
vet:
go vet ./...
clean:
rm -rf $(BIN) dist
# --- FIDO2 (D034) -------------------------------------------------------
# The plugin is a SEPARATE MODULE and needs cgo plus libfido2 headers. It is
# deliberately not part of `all`: the client must keep building, and
# cross-compiling, on a machine that has neither.
.PHONY: mock plugin fido-check
mock: ## build the software mock plugin (testing only, never shipped)
go build -o delilah-fido-mock ./cmd/delilah-fido-mock
@echo "built delilah-fido-mock -- rename or symlink to delilah-fido to use it,"
@echo "and set DELILAH_FIDO_MOCK=yes. It is not a token and enrols nothing safe."
plugin: ## build the FIDO2 plugin (pure Go since Q026; no cgo, no libfido2 headers)
go build -o delilah-fido ./cmd/delilah-fido
@echo "built delilah-fido -- needs fido2-token/fido2-cred/fido2-assert at RUN time"
fido-check: ## prove the client is still pure Go despite the token feature
CGO_ENABLED=0 go build -o /dev/null ./cmd/delilah
@echo "client builds with CGO_ENABLED=0 -- D034 holds"