From e68e68169020d98b877543f583373b1144442ee7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 10 Oct 2026 08:04:01 +0000 Subject: [PATCH 1/2] build(deps): bump ubuntu from `678c655` to `f144425` in /server Bumps ubuntu from `678c655` to `f144425`. --- updated-dependencies: - dependency-name: ubuntu dependency-version: '26.04' dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- server/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server/Dockerfile b/server/Dockerfile index 1322626e6..f6dc92179 100644 --- a/server/Dockerfile +++ b/server/Dockerfile @@ -58,7 +58,7 @@ RUN mkdir -p /tmp/worldmaker /tmp/atrinik-assets /tmp/worldmaker/data/tmp \ --resourcespath=/src/server/resources \ && test -d /tmp/atrinik-assets/client-maps -FROM ubuntu:26.04@sha256:678c6550cc43645e08669028bc177f50be4e7c5b8cca677067b1914d4afc7a03 +FROM ubuntu:26.04@sha256:f144425ff09be612d6d9ad965196e9cdc23dae1f42110a8a11a3e9a8198759f7 ENV DEBIAN_FRONTEND=noninteractive ATRINIK_HTTP_URL=off # The minimal base lacks the default OpenSSL trust links. Select this public From b21ff1e36197d48cf82461fcfdbf4d1c675fb68a Mon Sep 17 00:00:00 2001 From: Zoey Rose <3865595+zoeyrose@users.noreply.github.com> Date: Sat, 10 Oct 2026 13:47:02 -0500 Subject: [PATCH 2/2] fix(server): allow automatic runtime base image updates --- docs/CARES_PROVIDER.md | 9 +++++++-- server/docker/runtime-provider.lock.json | 1 - tools/tests/test_server_runtime_provider.py | 6 ++++-- 3 files changed, 11 insertions(+), 5 deletions(-) diff --git a/docs/CARES_PROVIDER.md b/docs/CARES_PROVIDER.md index c9ae60c14..8b217d064 100644 --- a/docs/CARES_PROVIDER.md +++ b/docs/CARES_PROVIDER.md @@ -18,8 +18,13 @@ symlinks and verifies the staged result. Headers, pkg-config metadata, compiler binaries and the rest of the build prefix are excluded. Both full curl and c-ares licenses remain in `/usr/local/share/licenses/`. -The destination uses the producer's immutable Ubuntu 26.04 base and signed -`20260810T000000Z` snapshot. A public distro CA bundle is copied from the compiler +The destination uses the digest-pinned Ubuntu base in +[`server/Dockerfile`](../server/Dockerfile) and the signed `20260810T000000Z` +snapshot. Dockerfile is the sole owner of the runtime base image pin, so +Dependabot can update it without synchronizing a duplicate lock field. The +provider lock continues to verify the copied libraries and installed package +closure; a new base must still pass the actual assembly checks below. +A public distro CA bundle is copied from the compiler stage before HTTPS package acquisition, then the locked `ca-certificates` package owns runtime system trust. HTTPS peer verification and APT Release signature and package hash verification remain enabled. Historical Release expiry is disabled diff --git a/server/docker/runtime-provider.lock.json b/server/docker/runtime-provider.lock.json index cf346b5da..18abd3a55 100644 --- a/server/docker/runtime-provider.lock.json +++ b/server/docker/runtime-provider.lock.json @@ -3,7 +3,6 @@ "build_image": "ghcr.io/atrinik/classic-build:1.16.0@sha256:e1c366dbf83ef987765ff913bbb193868314a139ae1e00cc134b22a3159464f2", "platform_digest": "sha256:66a637c76f07d32ff933886a96bc5bd720fc695cf20a4acb9c1710983fdb7478", "producer_source": "4be36a1f1eebb667aad77c227f7855a4a656d150", - "runtime_base": "ubuntu:26.04@sha256:678c6550cc43645e08669028bc177f50be4e7c5b8cca677067b1914d4afc7a03", "snapshot": "20260810T000000Z", "openssl_version": "3.5.5", "evidence_sha256": { diff --git a/tools/tests/test_server_runtime_provider.py b/tools/tests/test_server_runtime_provider.py index 09b6ace30..81930db29 100644 --- a/tools/tests/test_server_runtime_provider.py +++ b/tools/tests/test_server_runtime_provider.py @@ -298,10 +298,12 @@ def test_docker_apt_install_failure_propagates(self): self.assertEqual(result.returncode, 123) # xargs propagates child failure. self.assertEqual(len(calls), 2) - def test_docker_uses_locked_images_and_checks_without_tls_bypass(self): + def test_docker_uses_pinned_images_and_checks_without_tls_bypass(self): docker = (ROOT / "server/Dockerfile").read_text() self.assertIn("FROM " + LOCK["build_image"] + " AS build", docker) - self.assertIn("FROM " + LOCK["runtime_base"], docker) + # Dependabot owns the runtime image pin in Dockerfile. Validate an + # immutable Ubuntu reference without duplicating its current digest. + self.assertRegex(docker, r"(?m)^FROM ubuntu:[^\s@]+@sha256:[0-9a-f]{64}$") self.assertIn("https://snapshot.ubuntu.com/ubuntu/" + LOCK["snapshot"] + "/", docker) self.assertIn("RUN --network=none python3 tools/dependencies.py", docker) self.assertIn("COPY --from=build /opt/runtime-provider/ /usr/local/", docker)