#!/bin/bash
# Release build of the bundled Squid, run inside a Cygwin login shell.
# Expects downloads/squid-7.7.tar.gz and version-resources/ beside this script's
# target root. See FRESH-BUILD-WIN2025.md for the toolchain; the bundle steps
# (DLLs, dev/shm) follow the build.
#
# --without-nettle is REQUIRED: Cygwin ships nettle 4.0, whose
# base64_decode_update treats dst_length as buffer capacity on input. Squid
# initialises it to 0 at every call site, so with nettle every base64 decode
# fails and all proxy authentication is rejected. Without nettle Squid uses its
# own bundled base64 and MD5.
set -e
ROOT=/cygdrive/c/tmp/squid-cache
SRC=$ROOT/squid-7.7
cd $ROOT
rm -rf squid-7.7
tar -xzf downloads/squid-7.7.tar.gz
# Windows VERSIONINFO resource for squid.exe (build-file change only)
cp version-resources/squid-version.rc $SRC/src/squid-version.rc
( cd $SRC && patch -p1 < ../version-resources/squid-7.7-versioninfo.patch \
           && automake --foreign src/Makefile )
rm -rf $ROOT/build/* $ROOT/install/*
mkdir -p $ROOT/build
cd $ROOT/build
CFLAGS="-O2 -DNDEBUG -march=x86-64-v2" CXXFLAGS="-O2 -DNDEBUG -march=x86-64-v2" \
"$SRC/configure" --prefix=$ROOT/install \
  --with-openssl --without-nettle --disable-strict-error-checking \
  --enable-external-acl-helpers='delayer file_userip session unix_group'
make -j$(nproc)
make install-strip
echo "ALL_DONE_OK"
