mirror of
https://github.com/mvschwarz/openrig.git
synced 2026-10-02 08:35:15 +08:00
Break #4 in the Q2 series (Dockerfile unchanged since fold 54; revealed by fixing break #3 — the self-contained tarball now lets npm reach better-sqlite3's native install). better-sqlite3's install is `prebuild-install || node-gyp rebuild`; the image had neither a prebuilt path nor a toolchain, so layer 3 died ('prebuild-install: not found' → 'Could not find any Python installation', exit 1). FIX (a), per the sealed Q2 packaging ruling (better-sqlite3 builds FRESH ON TARGET, never prebuilt/nested → no wrong-arch binary): layer 1 installs python3 make g++. Testbed-image scope only (no multi-stage gold-plating). RIDER (PM, ratified) — close the CLASS 'green gate over a broken install' (assert-the-EFFECT-not-the-command): the build verb now LOADS the daemon inside the freshly-built container (rig daemon start → opens the DB → better-sqlite3 must have bound), reusing the proven L3-daemon-in-container sequence. A host clean-dir install can't catch this (host has the toolchain); only a container load does. Rides the pre-pin build verb (not a per-fold docker build); the A/B pin package requires it green. PROOF STATUS — HONEST: docker is absent in the VM seat BY RULING (build is host-side; build-testbed-image.sh itself guards `command -v docker` → exit 3). VM-authorable structural fences GREEN 12/12 (build-testbed-image.test.mjs: toolchain present + effect-proof load step present) + bash -n clean. The behavioral RED→GREEN (docker build fails at layer 3 on this branch's parent → builds + daemon loads with this fix) MUST run HOST-SIDE — handing off. NOT claiming a verified image build. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
65 lines
3.5 KiB
Docker
65 lines
3.5 KiB
Docker
# 51-04 testbed image (openrig-testbed) — see IMPL-PLAN §1. Built HOST-side by
|
|
# scripts/build-testbed-image.sh, which resolves + records the base digest, pins node, stages the
|
|
# stub assets, and COPYs the local openrig pack tarball. Byte-reproducible BY CONTRACT: the base is
|
|
# digest-pinned (the verb refuses a tag-floating reference), node is pinned, and openrig comes from
|
|
# the tree — never the npm registry (0.5.1 is unreleased). Layers are ordered stable -> volatile.
|
|
|
|
# --- base: a digest-pinned LTS-slim Linux, supplied by the build verb (docker/testbed/base-image,
|
|
# which REFUSES a non-@sha256 reference). No floating tag is baked into this file. ---
|
|
ARG BASE_IMAGE
|
|
FROM ${BASE_IMAGE}
|
|
|
|
# --- layer 1: userland + tmux + git + PTY/process essentials + the native-build toolchain (most stable) ---
|
|
# python3/make/g++ are REQUIRED, not optional: the sealed Q2 packaging ruling builds better-sqlite3
|
|
# FRESH ON TARGET (never a prebuilt/nested binary — that would risk a wrong-arch native module). Its
|
|
# install is `prebuild-install || node-gyp rebuild`; with a self-contained tarball npm reaches that
|
|
# step, prebuild-install is absent, and node-gyp needs python3+make+g++ to compile from source. Without
|
|
# them layer 3 dies ('prebuild-install: not found' → 'Could not find any Python installation'). This is
|
|
# testbed-image scope only (no multi-stage gold-plating — the image is a throwaway test target).
|
|
RUN set -eux; \
|
|
apt-get update; \
|
|
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
|
ca-certificates curl xz-utils git tmux tini procps \
|
|
python3 make g++; \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
# --- layer 2: pinned node (an in-range engines version — see scripts/check-engines) ---
|
|
ARG NODE_VERSION=22.22.1
|
|
ARG TARGETARCH
|
|
RUN set -eux; \
|
|
case "${TARGETARCH}" in \
|
|
amd64) NODE_ARCH=x64 ;; \
|
|
arm64) NODE_ARCH=arm64 ;; \
|
|
"") echo "TARGETARCH is empty — the legacy (non-BuildKit) builder does not populate it. Pass --build-arg TARGETARCH explicitly (build-testbed-image.sh does) or enable BuildKit. REFUSING to default to amd64, which would install wrong-arch Node." >&2; exit 1 ;; \
|
|
*) echo "unsupported TARGETARCH=${TARGETARCH}" >&2; exit 1 ;; \
|
|
esac; \
|
|
curl -fsSLo /tmp/node.tar.xz \
|
|
"https://nodejs.org/dist/v${NODE_VERSION}/node-v${NODE_VERSION}-linux-${NODE_ARCH}.tar.xz"; \
|
|
tar -xJf /tmp/node.tar.xz -C /usr/local --strip-components=1 --no-same-owner; \
|
|
rm -f /tmp/node.tar.xz; \
|
|
node --version; npm --version
|
|
|
|
# --- layer 3: the OpenRig package from the LOCAL pack tarball, never the npm registry ---
|
|
ARG OPENRIG_TARBALL
|
|
COPY ${OPENRIG_TARBALL} /tmp/openrig.tgz
|
|
RUN set -eux; \
|
|
npm install -g /tmp/openrig.tgz; \
|
|
rm -f /tmp/openrig.tgz; \
|
|
rig --version
|
|
|
|
# --- layer 4: stub runtime assets (zero-token by construction; staged by the build verb into the
|
|
# build context as ./stub-assets/, hashed into the manifest via deriveStubAssetsHash) ---
|
|
COPY stub-assets/ /opt/openrig-testbed/stub-assets/
|
|
|
|
# --- layer 5: a non-root openrig user + a tini entrypoint into tmux-server-friendly init ---
|
|
RUN set -eux; \
|
|
useradd --create-home --shell /bin/bash openrig; \
|
|
mkdir -p /opt/openrig-testbed; \
|
|
chown -R openrig:openrig /opt/openrig-testbed
|
|
COPY entrypoint.sh /opt/openrig-testbed/entrypoint.sh
|
|
RUN chmod 0755 /opt/openrig-testbed/entrypoint.sh
|
|
USER openrig
|
|
WORKDIR /home/openrig
|
|
ENTRYPOINT ["/usr/bin/tini", "--", "/opt/openrig-testbed/entrypoint.sh"]
|
|
CMD ["sleep", "infinity"]
|