Skip to content

Commit 9695502

Browse files
authored
Merge pull request #2271 from larsewi/ci-source-date-epoch
ENT-14061: Reproducible masterfiles builds with container scripts
2 parents 0e89392 + 63d54eb commit 9695502

3 files changed

Lines changed: 26 additions & 4 deletions

File tree

‎build-in-container-inner.sh‎

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -88,6 +88,23 @@ install_mission_portal_deps() (
8888
find "$BASEDIR/mission-portal" "$BASEDIR/nova/api/http" -type d -name .git -path '*/vendor/*' -exec rm -rf {} +
8989
)
9090

91+
# Build the masterfiles tarballs, mirroring build-scripts/bootstrap-tarballs.
92+
# Produces both the source tarball ("make dist") and the package tarball
93+
# ("make tar-package", files laid out as installed under prefix) and drops
94+
# them in /output alongside the platform packages.
95+
build_masterfiles_tarballs() (
96+
set -e
97+
98+
cd "$BASEDIR/masterfiles"
99+
rm -f cfengine-masterfiles*.tar.gz
100+
# Configure so the dist targets work, matching bootstrap-tarballs (no args).
101+
./configure
102+
make dist # source tarball: cfengine-masterfiles-<version>.tar.gz
103+
make tar-package # package tarball: cfengine-masterfiles-<version>.pkg.tar.gz
104+
mv cfengine-masterfiles*.tar.gz /output/
105+
make distclean
106+
)
107+
91108
# === Step runner with failure reporting ===
92109
# Disable set -e so we can capture exit codes and report which step failed.
93110
set +e
@@ -107,12 +124,15 @@ run_step() {
107124
# === Build steps ===
108125
run_step "01-autogen" "$BASEDIR/buildscripts/build-scripts/autogen"
109126
run_step "02-install-dependencies" "$BASEDIR/buildscripts/build-scripts/install-dependencies"
110-
if [ "$EXPLICIT_ROLE" = "hub" ]; then
127+
# Mission Portal is an Enterprise/nova-only component; its sources are only
128+
# synced when PROJECT=nova. Skip this step for community hubs.
129+
if [ "$PROJECT" = "nova" ] && [ "$EXPLICIT_ROLE" = "hub" ]; then
111130
run_step "03-mission-portal-deps" install_mission_portal_deps
112131
fi
113132
run_step "04-configure" "$BASEDIR/buildscripts/build-scripts/configure"
114133
run_step "05-compile" "$BASEDIR/buildscripts/build-scripts/compile"
115134
run_step "06-package" "$BASEDIR/buildscripts/build-scripts/package"
135+
run_step "07-masterfiles-tarballs" build_masterfiles_tarballs
116136

117137
# === Copy output packages ===
118138
# Packages are created under $BASEDIR/<project>/ by dpkg-buildpackage / rpmbuild.

‎build-in-container.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -474,7 +474,7 @@ def main():
474474
packages = (
475475
list(output_dir.glob("*.deb"))
476476
+ list(output_dir.glob("*.rpm"))
477-
+ list(output_dir.glob("*.pkg.tar.gz"))
477+
+ list(output_dir.glob("*.tar.gz"))
478478
)
479479
if packages:
480480
log.info("Output packages:")

‎container/Dockerfile.debian‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,11 @@ RUN apt-get update && apt-get install -y ${NCURSES_PKGS} \
1717
&& rm -rf /var/lib/apt/lists/*
1818

1919
# Hub build tools: Node.js 20 LTS (system nodejs is too old for modern npm
20-
# packages that use the node: protocol), PHP, and Composer
20+
# packages that use the node: protocol), PHP, and Composer.
21+
# php-zip lets Composer extract --prefer-dist zip archives natively instead
22+
# of falling back to git clones (which leave non-reproducible .git dirs).
2123
RUN curl -fsSL https://deb.nodesource.com/setup_20.x | bash - \
22-
&& apt-get install -y nodejs php-cli \
24+
&& apt-get install -y nodejs php-cli php-zip \
2325
&& rm -rf /var/lib/apt/lists/*
2426
RUN npm install -g less
2527
RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/bin --filename=composer.phar

0 commit comments

Comments
 (0)