Files
Drew T 9235800fb7 tools+docs(phase-33.5): task 11 — kit part 2: the firewall pack (templates/gitignore.decomp extracted byte-for-byte from the wiki fence — gitignore_template_check now runs in tools-health; firewall.txt with purge:/glob:/required:/pending:/fixture: rules; audit_public.template.py generalised from the repo's audit with its sources in the config, refusing zero sources; firewall-fixture/ = 16 synthetic bytes + sha1, the planted negative control), no-rom.template.yml, the docs/.run READMEs, ops-setup.decomp.md, bootstrap.template.sh (skeleton), CLAUDE.decomp-overlay.md (the four fail-safes + session-start extras), pa-overlays.md (7 fenced blocks: DIGEST, the 🛑 checkpoint block, the PhaseEnd narrative axis, effort rows, cookbook entry shape + triage table, wave-playbook skeleton, settings/mcp), the LICENSE/NOTICE/README/CONTRIBUTING skeletons, .clang-format + make-format.snippet.mk; tools/MANIFEST.md (325 tool files by ladder phase from one read-only survey, coverage 325/325, as Phase-N tasks); tools/kit_lint.py (fence-aware leak grep, the PLACEHOLDERS set-diff, in-memory compile / bash -n / JSON+YAML, the gitignore diff, TODO counts, coverage; --selftest = the R39 control) wired into tools-health; decomp-architect/README.md in doc_links DEFAULT; SETUP row; PLACEHOLDERS Used-in cells reconciled; make tools-health OK on this tree (detached run, .run/P33.5/tools_health_t11.log); story-timeline regenerated by the report step; log + checkpoint (NEXT = task 12, Max)
2026-09-07 19:22:51 -06:00

65 lines
3.2 KiB
Bash

#!/usr/bin/env bash
# tools/bootstrap.sh — fresh-clone setup (installed by decomp-architect Step 5 as a SKELETON; each TODO is a phase task).
# Idempotent; never sudo. What a build needs, in order:
# 1. system packages — only CHECKED here: the missing ones are printed as one install line.
# 2. the Python venv — created from the pinned requirements file.
# 3. the submodules — the assembler shim, the differ, the decompiler, the permuter (Phase 3/4 pin them).
# 4. the vintage compiler — fetched or extracted from a tracked, checksum-verified archive (Phase 4).
# 5. the preflight — `make check-env`; its exit status is this script's (Phase 3).
# Then: stage your own dump under disks/ and run the extract + fleet-check commands from docs/ops-setup.md.
set -euo pipefail
REPO="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$REPO"
say() { printf 'bootstrap: %s\n' "$*"; }
# 1) system packages — presence only; print the install line, never run it.
# TODO(phase-3): fill the list once the toolchain is chosen (binutils for the target, a C preprocessor, clang-format, make,
# the archive tools the extractor needs, python3-venv). TODO(platform): the package names differ per target and per distro.
PKGS="git make python3-venv clang-format"
if command -v dpkg >/dev/null 2>&1; then
missing=()
for p in $PKGS; do dpkg -s "$p" >/dev/null 2>&1 || missing+=("$p"); done
if ((${#missing[@]})); then
say "MISSING packages (${#missing[@]}) — run this, then re-run bootstrap:"
printf ' sudo apt-get install -y %s\n' "${missing[*]}"
else
say "packages: all present"
fi
else
say "no dpkg on this system — install the equivalents of: $PKGS"
fi
# 2) the venv (pinned requirements; the file is created in Phase 1 with the extractor's dependencies)
if [ ! -x .venv/bin/python ]; then
say "creating .venv"
python3 -m venv .venv
fi
if [ -f requirements-python.txt ]; then
say "installing pinned Python requirements (no-op when satisfied)"
.venv/bin/pip install -q -r requirements-python.txt
else
say "requirements-python.txt not present yet — TODO(phase-1)"
fi
# 3) submodules (no-op when populated; none until Phase 3 adds the shim, the differ, the decompiler and the permuter)
if [ -f .gitmodules ]; then
say "submodules: git submodule update --init"
git submodule update --init
else
say "no submodules yet — TODO(phase-3)"
fi
# 4) the vintage compiler — TODO(phase-4): verify the tracked archive's checksum (`sha256sum --check`), extract each
# candidate into its OWN directory, and print the pinned triple from docs/ops-setup.md. Never download without a
# checksum to verify against; never vendor a compiler whose license forbids it (keep a fetch step + checksum instead).
say "vintage compiler: TODO(phase-4) — nothing to fetch until the candidate ladder exists"
# 5) the preflight (its exit status is ours) — TODO(phase-3): `make check-env` asserts the toolchain executes, the
# assembler version is the pinned one and the dump's hash matches.
if grep -q '^check-env:' Makefile 2>/dev/null; then
say "make check-env"
make --no-print-directory check-env
else
say "make check-env not present yet — TODO(phase-3); bootstrap ends here"
fi