fix(bootstrap): wrap the downloaded binary in the same base CI ships
build_image_from_binary built on distroless/base-debian12 while the repo
Dockerfile's final stage uses distroless/static-debian12, so the image an
install runs did not match the image CI publishes.
Every binary that can reach HOST_BIN traces back to the Dockerfile's
CGO_ENABLED=0 build -- the downloaded CI asset, the binary the TUI is already
running, and the one build_image_from_source docker-cp's out of the image it
just built. None link glibc, so base-debian12 bought nothing and only widened
the runtime surface.
This mattered little while build_image_from_binary was the rare fallback.
659c8e5 made the release channel download a binary and wrap it here, which
makes this the image most installs actually run.
This commit is contained in:
1 file changed
+8
-1
+8
-1
@@ -1005,8 +1005,15 @@ build_image_from_binary() {
|
||||
tmp="$(mktemp -d)"
|
||||
remember_temp "$tmp"
|
||||
cp "$HOST_BIN" "${tmp}/felis"
|
||||
# static-debian12, matching the repo Dockerfile's final stage. Every binary that can reach
|
||||
# HOST_BIN traces back to that Dockerfile's CGO_ENABLED=0 build: the downloaded CI asset,
|
||||
# the binary the TUI is already running, and the one build_image_from_source docker-cp's
|
||||
# out of the image it just built. None of them link glibc, so the larger base-debian12
|
||||
# bought nothing and only widened the runtime surface. It mattered little while this was
|
||||
# the rare fallback; now that the release channel downloads a binary and wraps it here,
|
||||
# this is the image most installs actually run, and it should be the one CI publishes.
|
||||
cat > "${tmp}/Dockerfile" <<'EOF'
|
||||
FROM gcr.io/distroless/base-debian12:nonroot
|
||||
FROM gcr.io/distroless/static-debian12:nonroot
|
||||
ENV PATH=/usr/local/bin:/usr/bin:/bin
|
||||
COPY felis /usr/local/bin/felis
|
||||
USER 65532:65532
|
||||
|
||||
Reference in new issue
Block a user