UNPKG

leap-node

Version:

[![codecov](https://codecov.io/gh/leapdao/leap-node/branch/master/graph/badge.svg)](https://codecov.io/gh/leapdao/leap-node) [![Docker Repository on Quay](https://quay.io/repository/leapdao/leap-node/status "Docker Repository on Quay")](https://quay.io/re

88 lines (73 loc) 2.59 kB
#!/usr/bin/env node const { createHash } = require('crypto'); const { createWriteStream, readFileSync, renameSync } = require('fs'); const { join } = require('path'); const { get } = require('axios'); const unzip = require('unzipper').Parse; const versionPath = join(__dirname, 'version'); const tendermintVersion = readFileSync(versionPath, 'utf8').trim(); const binPath = join(__dirname, 'tendermint'); const getExpectedHash = url => { // get known hash from SHA256SUMS file const shasumPath = join(__dirname, 'SHA256SUMS'); const shasums = readFileSync(shasumPath).toString(); for (const line of shasums.split('\n')) { const [shasum, filename] = line.split(/\s+/); if (url.includes(filename)) { return shasum; } } return ''; }; // gets a URL to the binary zip, hosted on GitHub const getBinaryDownloadURL = version => { const platforms = { darwin: 'darwin', linux: 'linux', win32: 'windows', freebsd: 'freebsd', }; const arches = { x32: '386', ia32: '386', x64: 'amd64', arm: 'arm', arm64: 'arm', }; const platform = platforms[process.platform]; const arch = arches[process.arch]; return `https://github.com/leapdao/tendermint/releases/download/${version}/tendermint_${version}_${platform}_${arch}.zip`; }; const binaryDownloadUrl = getBinaryDownloadURL(tendermintVersion); console.log(`downloading ${binaryDownloadUrl}`); get(binaryDownloadUrl, { responseType: 'stream' }).then(res => { if (res.status !== 200) { throw Error(`Request failed, status: ${res.status}`); } const hasher = createHash('sha256'); const tempBinPath = join(__dirname, '_tendermint'); // unzip, write to file, and check hash const file = createWriteStream(tempBinPath, { mode: 0o755 }); res.data.pipe(unzip()).once('entry', entry => { // write to a temporary file which we rename if the hash check passes entry.pipe(file); }); // verify hash of file res.data.on('data', chunk => hasher.update(chunk)); file.on('finish', () => { const actualHash = hasher.digest().toString('hex'); const expectedHash = getExpectedHash(binaryDownloadUrl); if (actualHash !== expectedHash) { console.error( 'ERROR: hash of downloaded tendermint binary did not match. Got %s, expected %s', actualHash, expectedHash ); process.exit(1); } console.log('✅ verified hash of tendermint binary\n'); renameSync(tempBinPath, binPath); }); res.data.on('data', () => process.stdout.write('.')); res.data.on('end', () => console.log()); });