build(plugins): 插件构建统一钉到 gradle 9.8 镜像与带 sha256 的 wrapper,paper-api/Limbo 对齐锁文件并启用依赖校验

This commit is contained in:
Lemon-miaow committed 2026-09-25 23:45:33 +08:00
1 parent 2d1592bf01
commit d9453a6488
32 files changed
+2729 -97

No files matched your search

+6 -2
View File
@@ -372,6 +372,9 @@ SYSTEM_SERVER_IMAGES="${STATE_DIR}/system-server-images"
PG_FIREWALL_RULES="${STATE_DIR}/postgres-firewall.nft"
PG_FIREWALL_SERVICE="/etc/systemd/system/felis-postgres-firewall.service"
JRE_DIR="/opt/felis/jre"
# The gradle image the lobby and limbo Dockerfiles build their plugins in, digest
# included; build_velocity_plugin runs the same one.
PLUGIN_BUILD_IMAGE="gradle:9.8.0-jdk25@sha256:2b2fc1b1dfc3604a2acc916839f36eb5ee48fd7f232427fc5faca224c73bcb01"
K3S_BIN_DIR="${K3S_BIN_DIR:-/usr/local/bin}"
K3S_BIN="${K3S_BIN_DIR}/k3s"
# k3s's containerd mirror config, written by configure_registry_mirror. A variable
@@ -2126,7 +2129,8 @@ atomic_install_file() {
# build_velocity_plugin compiles plugins/velocity in the same gradle image the two
# Dockerfiles use, and drops the jar where Velocity will look for it. Docker is the
# toolchain here on purpose: the host needs no JDK and no gradle, only a JRE.
# toolchain here on purpose: the host needs no JDK and no gradle, only a JRE. Gradle
# checks every dependency against plugins/velocity/gradle/verification-metadata.xml.
build_velocity_plugin() {
log "building felis-velocity.jar (gradle in a container; the host gets no JDK)"
prepare_velocity_layout
@@ -2134,7 +2138,7 @@ build_velocity_plugin() {
docker run --rm \
-v "${GAME_STACK_DIR}:/src:z" \
-w /src/plugins/velocity \
gradle:8.14-jdk21 gradle --no-daemon clean build \
"$PLUGIN_BUILD_IMAGE" gradle --no-daemon clean build \
|| die "felis-velocity plugin build failed"
local -a jars=( "${GAME_STACK_DIR}"/plugins/velocity/build/libs/felis-velocity-*.jar )
[ "${#jars[@]}" -eq 1 ] && [ -f "${jars[0]}" ] \
+14 -10
View File
@@ -29,22 +29,26 @@
# overridable via FELIS_HEALTH_PORT) and returns 200 only after the first tick.
# ---- build the felis-limbo plugin jar ----
# gradle:*-jdk21 — an official Gradle image on JDK 21. JDK 21 is required because
# current LOOHP/Limbo releases ship Java 21 API classes (class-file major 65); a
# JDK 17 fails to read them with "wrong version 65.0, should be 61.0". The image
# also provides the `gradle` binary (this tree vendors no Gradle wrapper).
# build.gradle still targets release 17 bytecode so the plugin loads on Java 17+.
FROM gradle:8.14-jdk21@sha256:5c4c0c4284de4a19951e82ac78f86dbcda2e136644bbfe159beba7ea3420cc80 AS plugin
# The same pinned Gradle image as the lobby build (see deploy/lobby/Dockerfile). Its JDK
# must be >= 21 because current LOOHP/Limbo releases ship Java 21 API classes
# (class-file major 65); a JDK 17 fails to read them with "wrong version 65.0, should be
# 61.0". build.gradle still targets release 17 bytecode so the plugin loads on Java 17+.
FROM gradle:9.8.0-jdk25@sha256:2b2fc1b1dfc3604a2acc916839f36eb5ee48fd7f232427fc5faca224c73bcb01 AS plugin
WORKDIR /src
# Copy what the limbo module needs: its own tree plus the shared link core it
# srcDir-includes (../shared/src/main/java → /src/plugins/shared/src/main/java), so
# the account-link client + config loader compile straight into the jar.
COPY plugins/limbo/ ./plugins/limbo/
COPY plugins/shared/ ./plugins/shared/
ARG LIMBO_VERSION=+
RUN cd plugins/limbo \
&& (test -x ./gradlew && ./gradlew --no-daemon -PlimboVersion="$LIMBO_VERSION" build \
|| gradle --no-daemon -PlimboVersion="$LIMBO_VERSION" build) \
# The Limbo API release to compile against: deploy/game-stack.lock's LIMBO_VERSION, which
# bootstrap passes. Required — the API is checked against the checksum
# plugins/limbo/gradle/verification-metadata.xml holds for that release.
ARG LIMBO_VERSION
RUN if [ -z "${LIMBO_VERSION:-}" ]; then \
echo "LIMBO_VERSION is required (deploy/game-stack.lock)" >&2; exit 1; \
fi \
&& cd plugins/limbo \
&& gradle --no-daemon -PlimboVersion="$LIMBO_VERSION" build \
&& cp build/libs/*.jar /felis-limbo.jar
# ---- assemble the runtime ----
+9 -6
View File
@@ -25,16 +25,19 @@
# Secret) and refuses to start without it: a lobby that cannot verify the proxy's signed
# handshake would trust an offline, forgeable UUID.
# ---- build the felis-paper plugin jar (Paper API is Java 21) ----
# gradle:8.14-jdk21 — an official Gradle image on JDK 21 (this tree vendors no Gradle
# wrapper, and a bare JDK image ships no `gradle`). JDK 21 matches the Paper API.
FROM gradle:8.14-jdk21@sha256:5c4c0c4284de4a19951e82ac78f86dbcda2e136644bbfe159beba7ea3420cc80 AS plugin
# ---- build the felis-paper plugin jar (Paper API is Java 25) ----
# The official Gradle image on JDK 25, the Gradle version plugins/*/gradle/wrapper pins.
# The limbo Dockerfile and bootstrap's velocity build use this same image, digest and all
# (bootstrap_asset_test.go holds the three together). The image's own `gradle` runs the
# build rather than the module's wrapper, which would download the same distribution
# again on every image build. The build checks every dependency against
# plugins/paper/gradle/verification-metadata.xml and fails on a mismatch.
FROM gradle:9.8.0-jdk25@sha256:2b2fc1b1dfc3604a2acc916839f36eb5ee48fd7f232427fc5faca224c73bcb01 AS plugin
WORKDIR /src
COPY plugins/paper/ ./plugins/paper/
COPY plugins/shared/ ./plugins/shared/
RUN cd plugins/paper \
&& (test -x ./gradlew && ./gradlew --no-daemon build \
|| gradle --no-daemon build) \
&& gradle --no-daemon build \
&& cp build/libs/*.jar /felis-paper.jar
# ---- assemble the runtime ----
+5 -2
View File
@@ -10,7 +10,10 @@
# and hashed here; Paper and Velocity come from Fill's content-addressed URLs.
#
# Review the diff before committing: MC_VERSION moves the login gate's protocol, and the
# lobby, plain-Paper image and every client follow it.
# lobby, plain-Paper image and every client follow it. The plugins compile against these
# same builds (paper-api, the Limbo API, velocity-api) with their checksums pinned in
# plugins/*/gradle/verification-metadata.xml, so a moved build also moves those; go test .
# names what is left to bring along.
set -Eeuo pipefail
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
@@ -70,4 +73,4 @@ if [ "$check" = 1 ]; then
die "upstream has newer builds than game-stack.lock"
fi
cp "$tmp" "$LOCK"
ok "game-stack.lock updated; run go test . and the bootstrap tests, then commit"
ok "game-stack.lock updated; move plugins/paper's paper-api pin to the new Paper build and regenerate the plugins' gradle/verification-metadata.xml (plugins/README.md \"Dependency verification\"), run go test . and the bootstrap tests, then commit"