Files
J0xh-Sec e5e6817b60 [build] verify SHA-256 of downloaded Arm toolchains (#13684)
Download the GNU Arm Embedded toolchains to a staging directory under
/var/tmp in script/bootstrap and script/check-size, verify each archive
against a pinned SHA-256 before extracting, and abort on mismatch.

Staging runs as the unprivileged user (/var/tmp is disk-backed and has no
tmpfs memory limit): in script/bootstrap sudo is limited to the final
extraction into /opt and the symlink step, and script/check-size no longer
needs sudo at all. A trap on EXIT removes the staging dir on any early exit.
In setup_arm_gcc_7 the toolchain bin directory is added to PATH before the
version probe so a previously extracted copy under /var/tmp is reused
instead of re-downloaded.
2026-10-05 18:00:30 -07:00

206 lines
8.0 KiB
Bash
Executable File

#!/bin/bash
#
# Copyright (c) 2017, The OpenThread Authors.
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions are met:
# 1. Redistributions of source code must retain the above copyright
# notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
# notice, this list of conditions and the following disclaimer in the
# documentation and/or other materials provided with the distribution.
# 3. Neither the name of the copyright holder nor the
# names of its contributors may be used to endorse or promote products
# derived from this software without specific prior written permission.
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
# POSSIBILITY OF SUCH DAMAGE.
#
# Description:
# This file installs all needed dependencies and toolchains needed for
# example compilation and programming.
#
set -euxo pipefail
repo_dir=$(cd "$(dirname "$0")/.." && pwd)
readonly repo_dir
INSTALL_FORMAT_TOOLS="${INSTALL_FORMAT_TOOLS:-1}"
LLVM_MAJOR_VERSION="19"
pip_install()
{
local python_executable="python3"
if [[ -z ${VIRTUAL_ENV:-} ]]; then
if [[ ${venv_failed:-0} -eq 1 ]]; then
return 1
fi
if [[ ! -x "${repo_dir}/.venv/bin/python3" ]]; then
echo 'Creating python3 virtual environment...'
python3 -m venv "${repo_dir}/.venv" || {
rm -rf "${repo_dir}/.venv"
venv_failed=1
return 1
}
fi
python_executable="${repo_dir}/.venv/bin/python3"
fi
echo "Installing python3 package(s): $*..."
"${python_executable}" -m pip install "$@"
}
install_packages_pretty_format()
{
echo 'Installing pretty tools useful for code contributions...'
# add clang-format and clang-tidy for pretty
# To standardize the llvm version, we don't use apt to install
sudo bash "$(dirname "$0")/install-llvm.sh"
# add yapf for pretty
pip_install yapf==0.43.0 || echo 'WARNING: could not install yapf, which is useful if you plan to contribute python code to the OpenThread project.'
# add mdv for local size report
pip_install mdv || echo 'WARNING: could not install mdv, which is required to post markdown size report for OpenThread.'
# add shfmt for shell pretty
command -v shfmt || sudo apt-get install shfmt || echo 'WARNING: could not install shfmt, which is useful if you plan to contribute shell scripts to the OpenThread project.'
sudo apt-get --no-install-recommends install -y iwyu || echo 'WARNING: iwyu, which is useful to ensure applying the IWYU rules.'
}
install_packages_apt()
{
echo 'Installing toolchain dependencies...'
# apt-get update and install dependencies
sudo apt-get update
sudo apt-get --no-install-recommends install -y g++ lsb-release cmake ninja-build shellcheck libgtest-dev libgmock-dev python3-pip python3-venv
echo 'Installing GNU Arm Embedded Toolchain...'
PLATFORM=$(lsb_release -is)
ARCH=$(arch)
if [ "$PLATFORM" = "Raspbian" ]; then
sudo apt-get --no-install-recommends install -y binutils-arm-none-eabi gcc-arm-none-eabi gdb-arm-none-eabi libnewlib-arm-none-eabi libstdc++-arm-none-eabi-newlib
elif [ "$PLATFORM" = "Ubuntu" ]; then
sudo apt-get --no-install-recommends install -y bzip2 ca-certificates wget
local toolchain_url="https://developer.arm.com/-/media/Files/downloads/gnu-rm/9-2020q2/gcc-arm-none-eabi-9-2020-q2-update-${ARCH}-linux.tar.bz2"
local toolchain_sha256
case "${ARCH}" in
x86_64) toolchain_sha256="5adc2ee03904571c2de79d5cfc0f7fe2a5c5f54f44da5b645c17ee57b217f11f" ;;
aarch64) toolchain_sha256="1f4165c25e2cff80e29870f409862487ba470afd436e245ba3c743108e17b8ac" ;;
*)
echo "Unsupported architecture for GNU Arm Embedded Toolchain: ${ARCH}" >&2
exit 1
;;
esac
local stage
stage="$(mktemp -d /var/tmp/.ot-arm-toolchain.XXXXXX)"
trap 'rm -rf "${stage:-}"' EXIT
if wget --tries 4 --no-verbose -O "${stage}/toolchain.tar.bz2" "${toolchain_url}" \
&& echo "${toolchain_sha256} ${stage}/toolchain.tar.bz2" | sha256sum -c - \
&& sudo tar xj -C /opt -f "${stage}/toolchain.tar.bz2"; then
rm -rf "${stage}"
trap - EXIT
sudo ln -s -f /opt/gcc-arm-none-eabi-9-2020-q2-update/bin/* /usr/local/bin/.
else
echo "ERROR: failed to download or verify the GNU Arm Embedded Toolchain" >&2
exit 1
fi
fi
if [ "$PLATFORM" != "Raspbian" ] && [ "${INSTALL_FORMAT_TOOLS}" = "1" ]; then
install_packages_pretty_format
fi
}
install_packages_opkg()
{
echo 'opkg not supported currently' && false
}
install_packages_rpm()
{
echo 'rpm not supported currently' && false
}
install_packages_brew()
{
echo 'Installing toolchain dependencies...'
# add build tools
brew install cmake ninja python shfmt shellcheck
echo 'Installing GNU Arm Embedded Toolchain...'
# add ARM toolchain
brew tap ArmMbed/homebrew-formulae
brew install armmbed/formulae/arm-none-eabi-gcc
# check for gcc for simulation
if ! command -v gcc; then
echo 'warning: clang/gcc needed for simulation'
echo 'warning: please install Command Line Tools from https://developer.apple.com/download/more/'
fi
if [ "$INSTALL_FORMAT_TOOLS" = "1" ]; then
echo 'Installing pretty tools useful for code contributions...'
# add clang-format for pretty
CLANG_FORMAT_VERSION="clang-format version ${LLVM_MAJOR_VERSION}"
command -v clang-format-"${LLVM_MAJOR_VERSION}" || (command -v clang-format && (clang-format --version | grep -q "${CLANG_FORMAT_VERSION}")) || {
brew install llvm@"${LLVM_MAJOR_VERSION}"
sudo ln -s "$(brew --prefix llvm@${LLVM_MAJOR_VERSION})/bin/clang-format" /usr/local/bin/clang-format-"${LLVM_MAJOR_VERSION}"
sudo ln -s "$(brew --prefix llvm@${LLVM_MAJOR_VERSION})/bin/clang-tidy" /usr/local/bin/clang-tidy-"${LLVM_MAJOR_VERSION}"
sudo ln -s "$(brew --prefix llvm@${LLVM_MAJOR_VERSION})/bin/clang-apply-replacements" /usr/local/bin/clang-apply-replacements-"${LLVM_MAJOR_VERSION}"
sudo ln -s "$(brew --prefix llvm@${LLVM_MAJOR_VERSION})/bin/run-clang-tidy" /usr/local/bin/run-clang-tidy-"${LLVM_MAJOR_VERSION}"
} || echo "WARNING: could not install llvm@${LLVM_MAJOR_VERSION}, which is useful if you plan to contribute C/C++ code to the OpenThread project."
# add yapf for pretty
pip_install yapf==0.43.0 || echo 'Failed to install python code formatter yapf. Install it manually if you need.'
fi
brew install include-what-you-use || echo 'WARNING: iwyu, which is useful to ensure applying the IWYU rules.'
}
install_packages_source()
{
echo 'source not supported currently' && false
}
install_packages()
{
PM=source
if command -v apt-get; then
PM=apt
elif command -v rpm; then
PM=rpm
elif command -v opkg; then
PM=opkg
elif command -v brew; then
PM=brew
fi
install_packages_$PM
}
main()
{
git submodule update --init --recursive || true
install_packages
echo 'bootstrap completed successfully.'
}
main