Bash script skeleton

Describe the script: its options, its arguments, the safeguards you want. The tool writes a clean, commented skeleton (strict mode, --help, short and long options, cleanup of temporary files): only the heart of the script is left to write.

The script
Options

Short name (-o), long name (--output), value name if it takes one (FILE; empty: an on/off switch), default value, description. -h, --help is always there.

    Arguments

    What comes after the options, in order: required ones first; only the last one can take several values (a list of files, for instance).

      Safeguards
      
          
      Then, to run it
      
        

      Choices made in the skeleton

      #!/usr/bin/env bash
      Finds bash wherever it is installed (/bin/bash on Linux, /opt/homebrew/bin/bash on a Mac with Homebrew).
      No getopt
      The options are read by a while and a case, and not by getopt: the one on macOS does not know long options, and getopts knows only short ones. Limit: short options cannot be grouped (-v -n, not -vn).
      bash 3.2
      Nothing newer than the bash shipped with macOS: no mapfile, no associative array, and empty arrays written so that set -u does not stop on them.
      Messages on stderr
      So that the real output of the script can go into a pipe or a file without the messages mixed in.

      Transparency

      The skeleton is written in your browser, by the scripts listed below. Nothing you type leaves this page.

      Enforced by your browser
      This page's Content Security Policy allows a single destination, the site's audience measurement (connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'), so even a bug could not send what you type anywhere. You can read the policy at the top of the page source.
      Audience measurement
      Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
      • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
        SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
      • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
      What is stored
      No cookie, and nothing in the address. What you type is never stored: it disappears when you reload or close the page. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives what you type.
      Code that runs here
      • app.js: the checks and the writing of the skeleton, written for R-no Toolbox. Not minified, no third-party library. 23.3 kB
        SHA-256 f55c36e973bf9df0f221b66d2982e2123ca183e6ff7766a4f27658f5b3056721
      • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 10.6 kB
        SHA-256 ff50efd7cd6728a765d5d8e00b2b1e5528a049e85f4720eb094c71912c4aac26
      • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
        SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
      Before you paste
      This page only writes text: it runs nothing, neither here nor on your machine. What you paste into a terminal or a configuration file runs with your rights, so read it first. The code it writes downloads nothing and calls no outside service.
      How it was checked
      Skeletons with and without each safeguard, with option values full of quotes and messages in both languages, pass ShellCheck and were run with bash 5.2: --help, missing value, unknown option, too many arguments, --, --output=…. The code avoids anything newer than bash 3.2, but was not run on bash 3.2 itself.
      Check it yourself
      Download a script and compare its fingerprint with the one above:
      curl -s https://r-no.fr/bash/script/app.js | shasum -a 256
      Limits
      A skeleton, not a finished script: the work itself is up to you. Short options cannot be grouped (-vn). The messages of the script are written in the language of this page. set -e has well-known blind spots (inside if, &&, ||, or in a command substitution): it is a net, not a guarantee.