Dockerfile.base: LABEL se.jordbo.pi-devbox.mempalace-version, inherited by both variants
Closes the blind spot check 9 (cb6d9e5) named: no label recorded the palace pin, so a MEMPALACE_VERSION bump — the one component whose skew against the shared central palace is fleet-wide — could ship without a CHANGELOG line. In Dockerfile.base, not Dockerfile.variant, deliberately: the value sits next to the ARG that defines it (a copy in the variant is one more pin able to drift); labels are inherited by every image built FROM the base, so no build-arg to plumb through the variant's four call sites; and inheritance means the label states the pin of the base the image ACTUALLY built on, which is the question when base-decide cache-hits an older base. Both mechanisms measured on the published v1.9.2 config blob rather than assumed: maintainer + image.source (set only in Dockerfile.base) are present on the variant image, and pi-version=0.85.1 is an ARG expanded inside a LABEL. Intent, like every se.jordbo.pi-devbox.* label; the manifest's mempalace_version (read from the installed binary) stays the ground truth, and smoke-test.sh now asserts label == installed core — the one way they diverge is a base built with INSTALL_MEMPALACE=false or an off-pin install, both invisible to a label-only check. check-doc-drift check 9 gains the component (literal, against ARG MEMPALACE_VERSION in Dockerfile.base); the label-key rule generalises to "names ending in -version are the label itself". Until a release carries the label it reports a counted SKIP, not OK — measured: "v1.9.2 carries no se.jordbo.pi-devbox.mempalace-version label", summary says 1 SKIPPED. Costs nothing extra: this Unreleased already forces a base rebuild (50153e6rootfs/ skill floor). check-base-hash unchanged (no new *_REF).
This commit is contained in:
@@ -111,7 +111,9 @@ re-brand of opencode-devbox's `pi-only` variant.
|
|||||||
`git ls-remote`s each floating `*_REF`. A red check 9 means an upstream
|
`git ls-remote`s each floating `*_REF`. A red check 9 means an upstream
|
||||||
(pi-toolkit, pi-extensions, mempalace-toolkit, pi-fork,
|
(pi-toolkit, pi-extensions, mempalace-toolkit, pi-fork,
|
||||||
pi-observational-memory, pi-studio) moved and no entry names the new SHA;
|
pi-observational-memory, pi-studio) moved and no entry names the new SHA;
|
||||||
the failure prints the compare URL. Name the 7-char SHA where you describe
|
the failure prints the compare URL; a `PI_VERSION` or `MEMPALACE_VERSION`
|
||||||
|
bump is caught the same way via the `pi-version` / `mempalace-version`
|
||||||
|
labels. Name the 7-char SHA (or version) where you describe
|
||||||
the change — that is what the old "Dependency audit" tables recorded by
|
the change — that is what the old "Dependency audit" tables recorded by
|
||||||
hand, now required.
|
hand, now required.
|
||||||
|
|
||||||
|
|||||||
@@ -75,6 +75,22 @@ would fire on nothing wrong), and a "documented tag exists on Hub" check
|
|||||||
(check 8 already SKIPs a missing tag by name, and a hard fail would
|
(check 8 already SKIPs a missing tag by name, and a hard fail would
|
||||||
misreport the window between tagging and publish).
|
misreport the window between tagging and publish).
|
||||||
|
|
||||||
|
**Blind spot closed while it was free: `se.jordbo.pi-devbox.mempalace-version`.**
|
||||||
|
No label recorded the palace pin, so check 9 could not see a `MEMPALACE_VERSION`
|
||||||
|
bump — checks 1–3 keep README's pin table consistent, but nothing required a
|
||||||
|
CHANGELOG line for the one component whose skew against the shared central
|
||||||
|
palace is fleet-wide. The label is set in `Dockerfile.base` next to the `ARG`
|
||||||
|
that defines it and **inherited** by both variants: no second copy of the pin to
|
||||||
|
drift, no build-arg to plumb through four variant call sites, and it states the
|
||||||
|
pin of the base the image *actually* built on — the question that matters when
|
||||||
|
`base-decide` cache-hits an older base. Intent, like every label here; the
|
||||||
|
manifest's `mempalace_version` stays the ground truth, and `smoke-test.sh` now
|
||||||
|
asserts label == installed binary (the one way they diverge is a base built with
|
||||||
|
`INSTALL_MEMPALACE=false`, or an install that resolved off-pin). Until a release
|
||||||
|
carries the label, check 9 reports that component as a counted SKIP, not OK;
|
||||||
|
costs nothing extra because this Unreleased already forces a base rebuild
|
||||||
|
(`rootfs/` skill floor).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
**The rule "use `pi-task`, not `fork`, for a brief that carries a prohibition" was
|
**The rule "use `pi-task`, not `fork`, for a brief that carries a prohibition" was
|
||||||
|
|||||||
@@ -552,6 +552,20 @@ ARG INSTALL_MEMPALACE=true
|
|||||||
# so they stay dark until synlig is redeployed — a client bump alone cannot
|
# so they stay dark until synlig is redeployed — a client bump alone cannot
|
||||||
# light them up.
|
# light them up.
|
||||||
ARG MEMPALACE_VERSION=3.9.0
|
ARG MEMPALACE_VERSION=3.9.0
|
||||||
|
# Recorded as a label HERE, not in Dockerfile.variant, for three reasons: the
|
||||||
|
# value lives next to the ARG that defines it (a second copy in the variant
|
||||||
|
# would be one more pin able to drift, which is the class check-doc-drift.sh
|
||||||
|
# exists to catch); labels are inherited by every image built FROM this one, so
|
||||||
|
# both variants carry it with no build-arg to plumb through four call sites;
|
||||||
|
# and inheritance means the label states the pin of the base the variant
|
||||||
|
# ACTUALLY built on — which is the question when base-decide cache-hits an
|
||||||
|
# older base. Like every se.jordbo.pi-devbox.* label this records INTENT; the
|
||||||
|
# ground truth is /etc/pi-devbox/build-manifest.json's mempalace_version, read
|
||||||
|
# from the installed binary, and scripts/smoke-test.sh asserts the two agree.
|
||||||
|
# check-doc-drift.sh check 9 reads this off the last published image so that a
|
||||||
|
# pin bump must be named in the CHANGELOG — until this label ships, that
|
||||||
|
# component reports SKIP (label absent on the published release), not OK.
|
||||||
|
LABEL se.jordbo.pi-devbox.mempalace-version="${MEMPALACE_VERSION}"
|
||||||
ENV UV_TOOL_DIR=/opt/uv-tools
|
ENV UV_TOOL_DIR=/opt/uv-tools
|
||||||
ENV UV_TOOL_BIN_DIR=/usr/local/bin
|
ENV UV_TOOL_BIN_DIR=/usr/local/bin
|
||||||
RUN if [ "${INSTALL_MEMPALACE}" = "true" ]; then \
|
RUN if [ "${INSTALL_MEMPALACE}" = "true" ]; then \
|
||||||
|
|||||||
@@ -901,8 +901,10 @@ docker inspect --format '{{json .Config.Labels}}' joakimp/pi-devbox:latest | jq
|
|||||||
```
|
```
|
||||||
|
|
||||||
`org.opencontainers.image.{version,revision,created}` plus
|
`org.opencontainers.image.{version,revision,created}` plus
|
||||||
`se.jordbo.pi-devbox.*-ref` record the intended pi version and companion
|
`se.jordbo.pi-devbox.*-ref` and `se.jordbo.pi-devbox.*-version` record the
|
||||||
refs. The on-disk `/etc/pi-devbox/build-manifest.json` records **ground
|
intended pi and mempalace versions and companion refs (`mempalace-version` is
|
||||||
|
set in `Dockerfile.base` and inherited, so it names the pin of the base the
|
||||||
|
image actually built on). The on-disk `/etc/pi-devbox/build-manifest.json` records **ground
|
||||||
truth** — the actual checked-out commit of each `/opt` clone, the live
|
truth** — the actual checked-out commit of each `/opt` clone, the live
|
||||||
`pi --version`, and (from v1.8.6) the live `mempalace --version` of the
|
`pi --version`, and (from v1.8.6) the live `mempalace --version` of the
|
||||||
installed palace core — so a tag is reconstructable after CI logs rotate:
|
installed palace core — so a tag is reconstructable after CI logs rotate:
|
||||||
|
|||||||
@@ -414,7 +414,9 @@ fi
|
|||||||
# a tag or branch is `git ls-remote`d (peeled `^{}` first -- an annotated
|
# a tag or branch is `git ls-remote`d (peeled `^{}` first -- an annotated
|
||||||
# tag's un-dereferenced SHA is the tag object, a false alarm this repo has
|
# tag's un-dereferenced SHA is the tag object, a false alarm this repo has
|
||||||
# already fallen for once), pi-studio is the highest semver tag, and
|
# already fallen for once), pi-studio is the highest semver tag, and
|
||||||
# `PI_VERSION` is compared as a literal against the `pi-version` label.
|
# `PI_VERSION` / `MEMPALACE_VERSION` are compared as literals against the
|
||||||
|
# `pi-version` / `mempalace-version` labels (the latter set in Dockerfile.base
|
||||||
|
# and inherited; absent on releases before it shipped, which reports SKIP).
|
||||||
#
|
#
|
||||||
# The rule: baked == would-bake is OK with no mention required. If they
|
# The rule: baked == would-bake is OK with no mention required. If they
|
||||||
# differ, the text ABOVE the last published version's `## ` heading -- i.e.
|
# differ, the text ABOVE the last published version's `## ` heading -- i.e.
|
||||||
@@ -472,7 +474,8 @@ pi-atelier|ref|$ATELIER_REPO|$ATELIER_ACTUAL
|
|||||||
mempalace-toolkit|ref|$MPTK_REPO|$MPTK_REF
|
mempalace-toolkit|ref|$MPTK_REPO|$MPTK_REF
|
||||||
pi-studio|studio|$STUDIO_REPO|
|
pi-studio|studio|$STUDIO_REPO|
|
||||||
skillset-snapshot|literal||$SKILLSET_SNAPSHOT
|
skillset-snapshot|literal||$SKILLSET_SNAPSHOT
|
||||||
pi-version|literal||$PI_ACTUAL"
|
pi-version|literal||$PI_ACTUAL
|
||||||
|
mempalace-version|literal||$MEMPALACE_ACTUAL"
|
||||||
REF_RC=0
|
REF_RC=0
|
||||||
# Same discipline as check 8: no `|| true` on the python, or a printed DRIFT
|
# Same discipline as check 8: no `|| true` on the python, or a printed DRIFT
|
||||||
# exits 0. Per-component SKIP lines are counted afterwards by grep, so a run
|
# exits 0. Per-component SKIP lines are counted afterwards by grep, so a run
|
||||||
@@ -600,7 +603,9 @@ for line in os.environ["COMPONENTS"].splitlines():
|
|||||||
if not line.strip():
|
if not line.strip():
|
||||||
continue
|
continue
|
||||||
name, kind, url, ref = line.split("|", 3)
|
name, kind, url, ref = line.split("|", 3)
|
||||||
key = LABEL + name if name == "pi-version" else LABEL + name + "-ref"
|
# <name>-ref labels hold SHAs; names that already end in -version are the
|
||||||
|
# label (pi-version, mempalace-version) -- a version string, compared literally.
|
||||||
|
key = LABEL + name if name.endswith("-version") else LABEL + name + "-ref"
|
||||||
try:
|
try:
|
||||||
if kind == "studio":
|
if kind == "studio":
|
||||||
if studio_labels is None:
|
if studio_labels is None:
|
||||||
|
|||||||
@@ -597,6 +597,19 @@ if [ -n "$LBL" ] && [ "$LBL" != "<no value>" ]; then
|
|||||||
else
|
else
|
||||||
printf " ❌ OCI label se.jordbo.pi-devbox.pi-extensions-ref missing or empty\n"; FAIL=$((FAIL+1))
|
printf " ❌ OCI label se.jordbo.pi-devbox.pi-extensions-ref missing or empty\n"; FAIL=$((FAIL+1))
|
||||||
fi
|
fi
|
||||||
|
# mempalace-version is set in Dockerfile.base and INHERITED by the variant, so
|
||||||
|
# it states the pin of the base this image actually built on. It must equal the
|
||||||
|
# installed binary: the one way they diverge is a base built with
|
||||||
|
# INSTALL_MEMPALACE=false (label says 3.x, nothing installed) or an install that
|
||||||
|
# resolved to something other than the pin — both invisible to a label-only
|
||||||
|
# check. Same ground-truth rule as the manifest assertion above.
|
||||||
|
MP_LBL=$(docker inspect --format '{{ index .Config.Labels "se.jordbo.pi-devbox.mempalace-version" }}' "$IMAGE" 2>/dev/null || true)
|
||||||
|
MP_BIN=$(docker run --rm --entrypoint= "$IMAGE" sh -c 'mempalace --version 2>/dev/null | head -n1 | tr -d "\r"' 2>/dev/null || true); MP_BIN=${MP_BIN##* }
|
||||||
|
if [ -n "$MP_LBL" ] && [ "$MP_LBL" != "<no value>" ] && [ "$MP_LBL" = "$MP_BIN" ]; then
|
||||||
|
printf " ✅ OCI label se.jordbo.pi-devbox.mempalace-version=%s equals the installed core\n" "$MP_LBL"; PASS=$((PASS+1))
|
||||||
|
else
|
||||||
|
printf " ❌ OCI label se.jordbo.pi-devbox.mempalace-version=[%s] vs installed mempalace=[%s]\n" "$MP_LBL" "$MP_BIN"; FAIL=$((FAIL+1))
|
||||||
|
fi
|
||||||
|
|
||||||
# ── Runtime deployment (needs entrypoint to run) ──────────────────────
|
# ── Runtime deployment (needs entrypoint to run) ──────────────────────
|
||||||
echo ""
|
echo ""
|
||||||
|
|||||||
Reference in New Issue
Block a user