Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions docs/CARES_PROVIDER.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,13 @@ symlinks and verifies the staged result. Headers, pkg-config metadata, compiler
binaries and the rest of the build prefix are excluded. Both full curl and c-ares
licenses remain in `/usr/local/share/licenses/`.

The destination uses the producer's immutable Ubuntu 26.04 base and signed
`20260810T000000Z` snapshot. A public distro CA bundle is copied from the compiler
The destination uses the digest-pinned Ubuntu base in
[`server/Dockerfile`](../server/Dockerfile) and the signed `20260810T000000Z`
snapshot. Dockerfile is the sole owner of the runtime base image pin, so
Dependabot can update it without synchronizing a duplicate lock field. The
provider lock continues to verify the copied libraries and installed package
closure; a new base must still pass the actual assembly checks below.
A public distro CA bundle is copied from the compiler
stage before HTTPS package acquisition, then the locked `ca-certificates` package
owns runtime system trust. HTTPS peer verification and APT Release signature and
package hash verification remain enabled. Historical Release expiry is disabled
Expand Down
2 changes: 1 addition & 1 deletion server/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ RUN mkdir -p /tmp/worldmaker /tmp/atrinik-assets /tmp/worldmaker/data/tmp \
--resourcespath=/src/server/resources \
&& test -d /tmp/atrinik-assets/client-maps

FROM ubuntu:26.04@sha256:678c6550cc43645e08669028bc177f50be4e7c5b8cca677067b1914d4afc7a03
FROM ubuntu:26.04@sha256:f144425ff09be612d6d9ad965196e9cdc23dae1f42110a8a11a3e9a8198759f7

ENV DEBIAN_FRONTEND=noninteractive ATRINIK_HTTP_URL=off
# The minimal base lacks the default OpenSSL trust links. Select this public
Expand Down
1 change: 0 additions & 1 deletion server/docker/runtime-provider.lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@
"build_image": "ghcr.io/atrinik/classic-build:1.16.0@sha256:e1c366dbf83ef987765ff913bbb193868314a139ae1e00cc134b22a3159464f2",
"platform_digest": "sha256:66a637c76f07d32ff933886a96bc5bd720fc695cf20a4acb9c1710983fdb7478",
"producer_source": "4be36a1f1eebb667aad77c227f7855a4a656d150",
"runtime_base": "ubuntu:26.04@sha256:678c6550cc43645e08669028bc177f50be4e7c5b8cca677067b1914d4afc7a03",
"snapshot": "20260810T000000Z",
"openssl_version": "3.5.5",
"evidence_sha256": {
Expand Down
6 changes: 4 additions & 2 deletions tools/tests/test_server_runtime_provider.py
Original file line number Diff line number Diff line change
Expand Up @@ -298,10 +298,12 @@ def test_docker_apt_install_failure_propagates(self):
self.assertEqual(result.returncode, 123) # xargs propagates child failure.
self.assertEqual(len(calls), 2)

def test_docker_uses_locked_images_and_checks_without_tls_bypass(self):
def test_docker_uses_pinned_images_and_checks_without_tls_bypass(self):
docker = (ROOT / "server/Dockerfile").read_text()
self.assertIn("FROM " + LOCK["build_image"] + " AS build", docker)
self.assertIn("FROM " + LOCK["runtime_base"], docker)
# Dependabot owns the runtime image pin in Dockerfile. Validate an
# immutable Ubuntu reference without duplicating its current digest.
self.assertRegex(docker, r"(?m)^FROM ubuntu:[^\s@]+@sha256:[0-9a-f]{64}$")
self.assertIn("https://snapshot.ubuntu.com/ubuntu/" + LOCK["snapshot"] + "/", docker)
self.assertIn("RUN --network=none python3 tools/dependencies.py", docker)
self.assertIn("COPY --from=build /opt/runtime-provider/ /usr/local/", docker)
Expand Down