build(plugins): 插件构建统一钉到 gradle 9.8 镜像与带 sha256 的 wrapper,paper-api/Limbo 对齐锁文件并启用依赖校验
This commit is contained in:
32 files changed
+2729
-97
No files matched your search
+6
-2
@@ -372,6 +372,9 @@ SYSTEM_SERVER_IMAGES="${STATE_DIR}/system-server-images"
|
||||
PG_FIREWALL_RULES="${STATE_DIR}/postgres-firewall.nft"
|
||||
PG_FIREWALL_SERVICE="/etc/systemd/system/felis-postgres-firewall.service"
|
||||
JRE_DIR="/opt/felis/jre"
|
||||
# The gradle image the lobby and limbo Dockerfiles build their plugins in, digest
|
||||
# included; build_velocity_plugin runs the same one.
|
||||
PLUGIN_BUILD_IMAGE="gradle:9.8.0-jdk25@sha256:2b2fc1b1dfc3604a2acc916839f36eb5ee48fd7f232427fc5faca224c73bcb01"
|
||||
K3S_BIN_DIR="${K3S_BIN_DIR:-/usr/local/bin}"
|
||||
K3S_BIN="${K3S_BIN_DIR}/k3s"
|
||||
# k3s's containerd mirror config, written by configure_registry_mirror. A variable
|
||||
@@ -2126,7 +2129,8 @@ atomic_install_file() {
|
||||
|
||||
# build_velocity_plugin compiles plugins/velocity in the same gradle image the two
|
||||
# Dockerfiles use, and drops the jar where Velocity will look for it. Docker is the
|
||||
# toolchain here on purpose: the host needs no JDK and no gradle, only a JRE.
|
||||
# toolchain here on purpose: the host needs no JDK and no gradle, only a JRE. Gradle
|
||||
# checks every dependency against plugins/velocity/gradle/verification-metadata.xml.
|
||||
build_velocity_plugin() {
|
||||
log "building felis-velocity.jar (gradle in a container; the host gets no JDK)"
|
||||
prepare_velocity_layout
|
||||
@@ -2134,7 +2138,7 @@ build_velocity_plugin() {
|
||||
docker run --rm \
|
||||
-v "${GAME_STACK_DIR}:/src:z" \
|
||||
-w /src/plugins/velocity \
|
||||
gradle:8.14-jdk21 gradle --no-daemon clean build \
|
||||
"$PLUGIN_BUILD_IMAGE" gradle --no-daemon clean build \
|
||||
|| die "felis-velocity plugin build failed"
|
||||
local -a jars=( "${GAME_STACK_DIR}"/plugins/velocity/build/libs/felis-velocity-*.jar )
|
||||
[ "${#jars[@]}" -eq 1 ] && [ -f "${jars[0]}" ] \
|
||||
|
||||
+14
-10
@@ -29,22 +29,26 @@
|
||||
# overridable via FELIS_HEALTH_PORT) and returns 200 only after the first tick.
|
||||
|
||||
# ---- build the felis-limbo plugin jar ----
|
||||
# gradle:*-jdk21 — an official Gradle image on JDK 21. JDK 21 is required because
|
||||
# current LOOHP/Limbo releases ship Java 21 API classes (class-file major 65); a
|
||||
# JDK 17 fails to read them with "wrong version 65.0, should be 61.0". The image
|
||||
# also provides the `gradle` binary (this tree vendors no Gradle wrapper).
|
||||
# build.gradle still targets release 17 bytecode so the plugin loads on Java 17+.
|
||||
FROM gradle:8.14-jdk21@sha256:5c4c0c4284de4a19951e82ac78f86dbcda2e136644bbfe159beba7ea3420cc80 AS plugin
|
||||
# The same pinned Gradle image as the lobby build (see deploy/lobby/Dockerfile). Its JDK
|
||||
# must be >= 21 because current LOOHP/Limbo releases ship Java 21 API classes
|
||||
# (class-file major 65); a JDK 17 fails to read them with "wrong version 65.0, should be
|
||||
# 61.0". build.gradle still targets release 17 bytecode so the plugin loads on Java 17+.
|
||||
FROM gradle:9.8.0-jdk25@sha256:2b2fc1b1dfc3604a2acc916839f36eb5ee48fd7f232427fc5faca224c73bcb01 AS plugin
|
||||
WORKDIR /src
|
||||
# Copy what the limbo module needs: its own tree plus the shared link core it
|
||||
# srcDir-includes (../shared/src/main/java → /src/plugins/shared/src/main/java), so
|
||||
# the account-link client + config loader compile straight into the jar.
|
||||
COPY plugins/limbo/ ./plugins/limbo/
|
||||
COPY plugins/shared/ ./plugins/shared/
|
||||
ARG LIMBO_VERSION=+
|
||||
RUN cd plugins/limbo \
|
||||
&& (test -x ./gradlew && ./gradlew --no-daemon -PlimboVersion="$LIMBO_VERSION" build \
|
||||
|| gradle --no-daemon -PlimboVersion="$LIMBO_VERSION" build) \
|
||||
# The Limbo API release to compile against: deploy/game-stack.lock's LIMBO_VERSION, which
|
||||
# bootstrap passes. Required — the API is checked against the checksum
|
||||
# plugins/limbo/gradle/verification-metadata.xml holds for that release.
|
||||
ARG LIMBO_VERSION
|
||||
RUN if [ -z "${LIMBO_VERSION:-}" ]; then \
|
||||
echo "LIMBO_VERSION is required (deploy/game-stack.lock)" >&2; exit 1; \
|
||||
fi \
|
||||
&& cd plugins/limbo \
|
||||
&& gradle --no-daemon -PlimboVersion="$LIMBO_VERSION" build \
|
||||
&& cp build/libs/*.jar /felis-limbo.jar
|
||||
|
||||
# ---- assemble the runtime ----
|
||||
|
||||
@@ -25,16 +25,19 @@
|
||||
# Secret) and refuses to start without it: a lobby that cannot verify the proxy's signed
|
||||
# handshake would trust an offline, forgeable UUID.
|
||||
|
||||
# ---- build the felis-paper plugin jar (Paper API is Java 21) ----
|
||||
# gradle:8.14-jdk21 — an official Gradle image on JDK 21 (this tree vendors no Gradle
|
||||
# wrapper, and a bare JDK image ships no `gradle`). JDK 21 matches the Paper API.
|
||||
FROM gradle:8.14-jdk21@sha256:5c4c0c4284de4a19951e82ac78f86dbcda2e136644bbfe159beba7ea3420cc80 AS plugin
|
||||
# ---- build the felis-paper plugin jar (Paper API is Java 25) ----
|
||||
# The official Gradle image on JDK 25, the Gradle version plugins/*/gradle/wrapper pins.
|
||||
# The limbo Dockerfile and bootstrap's velocity build use this same image, digest and all
|
||||
# (bootstrap_asset_test.go holds the three together). The image's own `gradle` runs the
|
||||
# build rather than the module's wrapper, which would download the same distribution
|
||||
# again on every image build. The build checks every dependency against
|
||||
# plugins/paper/gradle/verification-metadata.xml and fails on a mismatch.
|
||||
FROM gradle:9.8.0-jdk25@sha256:2b2fc1b1dfc3604a2acc916839f36eb5ee48fd7f232427fc5faca224c73bcb01 AS plugin
|
||||
WORKDIR /src
|
||||
COPY plugins/paper/ ./plugins/paper/
|
||||
COPY plugins/shared/ ./plugins/shared/
|
||||
RUN cd plugins/paper \
|
||||
&& (test -x ./gradlew && ./gradlew --no-daemon build \
|
||||
|| gradle --no-daemon build) \
|
||||
&& gradle --no-daemon build \
|
||||
&& cp build/libs/*.jar /felis-paper.jar
|
||||
|
||||
# ---- assemble the runtime ----
|
||||
|
||||
@@ -10,7 +10,10 @@
|
||||
# and hashed here; Paper and Velocity come from Fill's content-addressed URLs.
|
||||
#
|
||||
# Review the diff before committing: MC_VERSION moves the login gate's protocol, and the
|
||||
# lobby, plain-Paper image and every client follow it.
|
||||
# lobby, plain-Paper image and every client follow it. The plugins compile against these
|
||||
# same builds (paper-api, the Limbo API, velocity-api) with their checksums pinned in
|
||||
# plugins/*/gradle/verification-metadata.xml, so a moved build also moves those; go test .
|
||||
# names what is left to bring along.
|
||||
set -Eeuo pipefail
|
||||
|
||||
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
@@ -70,4 +73,4 @@ if [ "$check" = 1 ]; then
|
||||
die "upstream has newer builds than game-stack.lock"
|
||||
fi
|
||||
cp "$tmp" "$LOCK"
|
||||
ok "game-stack.lock updated; run go test . and the bootstrap tests, then commit"
|
||||
ok "game-stack.lock updated; move plugins/paper's paper-api pin to the new Paper build and regenerate the plugins' gradle/verification-metadata.xml (plugins/README.md \"Dependency verification\"), run go test . and the bootstrap tests, then commit"
|
||||
Reference in new issue
Block a user