From 7c2889c3c5216e0da5ff28b61d0291a3de44a737 Mon Sep 17 00:00:00 2001 From: Manuel de Brito Fontes Date: Thu, 1 Oct 2026 20:34:09 -0300 Subject: [PATCH] image: task, git-lfs and buildkit pinned by content in versions.yaml install-dev-tools.sh fetched all three with an empty sha256, so its check never ran, and their versions sat in env defaults nothing set. They are versions.yaml entries now, handed in by image/Dockerfile and passed through mkosi.conf's Environment=, and the script refuses to run without a sum. isal and pigz were installed twice; mkosi.conf's Packages keeps them. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/image.yml | 2 +- image/Dockerfile | 12 ++++++ image/Taskfile.yml | 2 +- image/mkosi.conf | 2 + .../local/lib/spin-base/install-dev-tools.sh | 41 +++++++------------ versions.yaml | 32 +++++++++++++++ 6 files changed, 62 insertions(+), 29 deletions(-) diff --git a/.github/workflows/image.yml b/.github/workflows/image.yml index 494e337..82f18a0 100644 --- a/.github/workflows/image.yml +++ b/.github/workflows/image.yml @@ -63,7 +63,7 @@ jobs: env: BASE: ${{ github.event.pull_request.base.sha || github.event.before }} run: | - build=$(hack/touches "$BASE" alpine e2fsprogs ubuntu mkosi -- \ + build=$(hack/touches "$BASE" alpine e2fsprogs ubuntu mkosi task git-lfs buildkit -- \ image e2fsprogs versions go.mod .github/workflows/image.yml) echo "build=${build}" | tee -a "$GITHUB_OUTPUT" diff --git a/image/Dockerfile b/image/Dockerfile index bace69b..78ff8f1 100644 --- a/image/Dockerfile +++ b/image/Dockerfile @@ -83,6 +83,18 @@ RUN --mount=type=cache,sharing=locked,id=image-mkosi-src,target=/var/cache/mkosi # Asks the binary just installed which version it is, rather than trusting the tag. test "$(mkosi --version)" = "mkosi ${MKOSI_VERSION}" +# What install-dev-tools.sh downloads into the image, by content. It runs inside mkosi's tree, +# which sees only what mkosi.conf's Environment= passes through, so each is an ENV here. +ARG TASK_VERSION +ARG TASK_SHA256 +ARG GIT_LFS_VERSION +ARG GIT_LFS_SHA256 +ARG BUILDKIT_VERSION +ARG BUILDKIT_SHA256 +ENV TASK_VERSION=${TASK_VERSION} TASK_SHA256=${TASK_SHA256} \ + GIT_LFS_VERSION=${GIT_LFS_VERSION} GIT_LFS_SHA256=${GIT_LFS_SHA256} \ + BUILDKIT_VERSION=${BUILDKIT_VERSION} BUILDKIT_SHA256=${BUILDKIT_SHA256} + COPY image/mkosi.conf image/mkosi.postinst.chroot /work/ COPY image/mkosi.extra /work/mkosi.extra COPY image/build.sh /usr/local/bin/build-base-image diff --git a/image/Taskfile.yml b/image/Taskfile.yml index 5337375..4e3f242 100644 --- a/image/Taskfile.yml +++ b/image/Taskfile.yml @@ -34,7 +34,7 @@ tasks: --platform linux/amd64 \ --cache-from {{.IMAGE_CACHE_FROM}} \ {{.IMAGE_CACHE_TO}} \ - $({{.VERSIONS}} args ubuntu mkosi) \ + $({{.VERSIONS}} args ubuntu mkosi task git-lfs buildkit) \ --tag {{.IMAGE_BUILDER_TAG}} \ --load \ . diff --git a/image/mkosi.conf b/image/mkosi.conf index 40f181a..4eb3b71 100644 --- a/image/mkosi.conf +++ b/image/mkosi.conf @@ -47,6 +47,8 @@ MinimumVersion=27.1 Incremental=yes CacheDirectory=/cache WithNetwork=yes +# From image/Dockerfile, which has them from versions.yaml: what install-dev-tools.sh downloads. +Environment=TASK_VERSION TASK_SHA256 GIT_LFS_VERSION GIT_LFS_SHA256 BUILDKIT_VERSION BUILDKIT_SHA256 [Distribution] Distribution=ubuntu diff --git a/image/mkosi.extra/usr/local/lib/spin-base/install-dev-tools.sh b/image/mkosi.extra/usr/local/lib/spin-base/install-dev-tools.sh index 548cd08..34858c6 100755 --- a/image/mkosi.extra/usr/local/lib/spin-base/install-dev-tools.sh +++ b/image/mkosi.extra/usr/local/lib/spin-base/install-dev-tools.sh @@ -3,38 +3,26 @@ set -euo pipefail echo "Installing development tools..." -# ------------------------------------------------- -# Version configuration -# ------------------------------------------------- -TASK_VERSION="${TASK_VERSION:-3.45.5}" -GIT_LFS_VERSION="${GIT_LFS_VERSION:-3.7.0}" -BUILDKIT_VERSION="${BUILDKIT_VERSION:-0.26.2}" - -# ------------------------------------------------- -# Helper functions -# ------------------------------------------------- -download_and_verify() { - local url="$1" - local output="$2" - local expected_sha256="$3" +# Versions and sha256s from versions.yaml, through image/Dockerfile and mkosi.conf's Environment=. +: "${TASK_VERSION:?}" "${TASK_SHA256:?}" +: "${GIT_LFS_VERSION:?}" "${GIT_LFS_SHA256:?}" +: "${BUILDKIT_VERSION:?}" "${BUILDKIT_SHA256:?}" +download() { + local url="$1" output="$2" sha256="$3" echo "Downloading ${url}..." curl -fsSL "${url}" -o "${output}" - - if [ -n "${expected_sha256}" ]; then - echo "Verifying checksum..." - echo "${expected_sha256} ${output}" | sha256sum -c - - fi + echo "${sha256} ${output}" | sha256sum -c - } # ------------------------------------------------- # Install Task (Taskfile runner) # ------------------------------------------------- echo "Installing Task v${TASK_VERSION}..." -download_and_verify \ +download \ "https://github.com/go-task/task/releases/download/v${TASK_VERSION}/task_linux_amd64.tar.gz" \ "/tmp/task.tar.gz" \ - "" + "${TASK_SHA256}" tar -xzf /tmp/task.tar.gz -C /tmp install -m 755 /tmp/task /usr/local/bin/task @@ -44,10 +32,10 @@ task --version # Install Git LFS # ------------------------------------------------- echo "Installing Git LFS v${GIT_LFS_VERSION}..." -download_and_verify \ +download \ "https://github.com/git-lfs/git-lfs/releases/download/v${GIT_LFS_VERSION}/git-lfs-linux-amd64-v${GIT_LFS_VERSION}.tar.gz" \ "/tmp/git-lfs.tar.gz" \ - "" + "${GIT_LFS_SHA256}" tar -xzf /tmp/git-lfs.tar.gz -C /tmp install -m 755 "/tmp/git-lfs-${GIT_LFS_VERSION}/git-lfs" /usr/local/bin/git-lfs @@ -57,10 +45,10 @@ git-lfs version # Install BuildKit # ------------------------------------------------- echo "Installing BuildKit v${BUILDKIT_VERSION}..." -download_and_verify \ +download \ "https://github.com/moby/buildkit/releases/download/v${BUILDKIT_VERSION}/buildkit-v${BUILDKIT_VERSION}.linux-amd64.tar.gz" \ "/tmp/buildkit.tar.gz" \ - "" + "${BUILDKIT_SHA256}" tar -xzf /tmp/buildkit.tar.gz -C /usr/local # Remove QEMU binaries we don't need @@ -87,8 +75,7 @@ apt-get install -y \ docker-ce-cli \ containerd.io \ docker-buildx-plugin \ - docker-compose-plugin \ - isal pigz + docker-compose-plugin # ------------------------------------------------- # Cleanup diff --git a/versions.yaml b/versions.yaml index cf9c363..b22d052 100644 --- a/versions.yaml +++ b/versions.yaml @@ -141,6 +141,38 @@ `task image:build`, then `task shell` and `task boot:bench`: a new mkosi can change the tree without failing the build. +- name: task + kind: download + source: https://github.com/go-task/task/releases/download/v{version}/task_linux_amd64.tar.gz + version: 3.45.5 + pin: e547ea2a47f5240657fdc89ea776baa90d628a1f2748242eaa7478fd92bffd40 + track: tags https://github.com/go-task/task.git + note: >- + image/Dockerfile hands it to install-dev-tools.sh, which puts it in the base image's + /usr/local/bin for whoever works inside a guest. The pin can be checked against + task_checksums.txt beside the tarball. After the bump: `task image:build`. + +- name: git-lfs + kind: download + source: https://github.com/git-lfs/git-lfs/releases/download/v{version}/git-lfs-linux-amd64-v{version}.tar.gz + version: 3.7.0 + pin: e7ebba491af8a54e560be3a00666fa97e4cf2bbbb223178a0934b8ef74cf9bed + track: tags https://github.com/git-lfs/git-lfs.git + note: >- + image/Dockerfile hands it to install-dev-tools.sh, as task. The pin can be checked against + sha256sums.asc beside the tarball. After the bump: `task image:build`. + +- name: buildkit + kind: download + source: https://github.com/moby/buildkit/releases/download/v{version}/buildkit-v{version}.linux-amd64.tar.gz + version: 0.26.2 + pin: 1ef7c888f808e7f3f49d9aeeca11f661afe5c0880a4b114cc31c56dee86acd35 + track: tags https://github.com/moby/buildkit.git + note: >- + image/Dockerfile hands it to install-dev-tools.sh, as task: buildctl and buildkitd. The + release publishes no checksums, only a provenance attestation beside the tarball. After the + bump: `task image:build`. + - name: qboot kind: git source: https://github.com/bonzini/qboot.git