From b9057fdc8c45674033d5784634885008f13781cb Mon Sep 17 00:00:00 2001 From: Joakim Persson Date: Sat, 19 Sep 2026 17:27:34 +0200 Subject: [PATCH] Dockerfile.base: LABEL se.jordbo.pi-devbox.mempalace-version, inherited by both variants MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Closes the blind spot check 9 (cb6d9e5) named: no label recorded the palace pin, so a MEMPALACE_VERSION bump — the one component whose skew against the shared central palace is fleet-wide — could ship without a CHANGELOG line. In Dockerfile.base, not Dockerfile.variant, deliberately: the value sits next to the ARG that defines it (a copy in the variant is one more pin able to drift); labels are inherited by every image built FROM the base, so no build-arg to plumb through the variant's four call sites; and inheritance means the label states the pin of the base the image ACTUALLY built on, which is the question when base-decide cache-hits an older base. Both mechanisms measured on the published v1.9.2 config blob rather than assumed: maintainer + image.source (set only in Dockerfile.base) are present on the variant image, and pi-version=0.85.1 is an ARG expanded inside a LABEL. Intent, like every se.jordbo.pi-devbox.* label; the manifest's mempalace_version (read from the installed binary) stays the ground truth, and smoke-test.sh now asserts label == installed core — the one way they diverge is a base built with INSTALL_MEMPALACE=false or an off-pin install, both invisible to a label-only check. check-doc-drift check 9 gains the component (literal, against ARG MEMPALACE_VERSION in Dockerfile.base); the label-key rule generalises to "names ending in -version are the label itself". Until a release carries the label it reports a counted SKIP, not OK — measured: "v1.9.2 carries no se.jordbo.pi-devbox.mempalace-version label", summary says 1 SKIPPED. Costs nothing extra: this Unreleased already forces a base rebuild (50153e6 rootfs/ skill floor). check-base-hash unchanged (no new *_REF). --- AGENTS.md | 4 +++- CHANGELOG.md | 16 ++++++++++++++++ Dockerfile.base | 14 ++++++++++++++ README.md | 6 ++++-- scripts/check-doc-drift.sh | 11 ++++++++--- scripts/smoke-test.sh | 13 +++++++++++++ 6 files changed, 58 insertions(+), 6 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index ace5689..860271e 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -111,7 +111,9 @@ re-brand of opencode-devbox's `pi-only` variant. `git ls-remote`s each floating `*_REF`. A red check 9 means an upstream (pi-toolkit, pi-extensions, mempalace-toolkit, pi-fork, pi-observational-memory, pi-studio) moved and no entry names the new SHA; - the failure prints the compare URL. Name the 7-char SHA where you describe + the failure prints the compare URL; a `PI_VERSION` or `MEMPALACE_VERSION` + bump is caught the same way via the `pi-version` / `mempalace-version` + labels. Name the 7-char SHA (or version) where you describe the change — that is what the old "Dependency audit" tables recorded by hand, now required. diff --git a/CHANGELOG.md b/CHANGELOG.md index 60efffa..53eea36 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -75,6 +75,22 @@ would fire on nothing wrong), and a "documented tag exists on Hub" check (check 8 already SKIPs a missing tag by name, and a hard fail would misreport the window between tagging and publish). +**Blind spot closed while it was free: `se.jordbo.pi-devbox.mempalace-version`.** +No label recorded the palace pin, so check 9 could not see a `MEMPALACE_VERSION` +bump — checks 1–3 keep README's pin table consistent, but nothing required a +CHANGELOG line for the one component whose skew against the shared central +palace is fleet-wide. The label is set in `Dockerfile.base` next to the `ARG` +that defines it and **inherited** by both variants: no second copy of the pin to +drift, no build-arg to plumb through four variant call sites, and it states the +pin of the base the image *actually* built on — the question that matters when +`base-decide` cache-hits an older base. Intent, like every label here; the +manifest's `mempalace_version` stays the ground truth, and `smoke-test.sh` now +asserts label == installed binary (the one way they diverge is a base built with +`INSTALL_MEMPALACE=false`, or an install that resolved off-pin). Until a release +carries the label, check 9 reports that component as a counted SKIP, not OK; +costs nothing extra because this Unreleased already forces a base rebuild +(`rootfs/` skill floor). + --- **The rule "use `pi-task`, not `fork`, for a brief that carries a prohibition" was diff --git a/Dockerfile.base b/Dockerfile.base index e732c9a..706d08a 100644 --- a/Dockerfile.base +++ b/Dockerfile.base @@ -552,6 +552,20 @@ ARG INSTALL_MEMPALACE=true # so they stay dark until synlig is redeployed — a client bump alone cannot # light them up. ARG MEMPALACE_VERSION=3.9.0 +# Recorded as a label HERE, not in Dockerfile.variant, for three reasons: the +# value lives next to the ARG that defines it (a second copy in the variant +# would be one more pin able to drift, which is the class check-doc-drift.sh +# exists to catch); labels are inherited by every image built FROM this one, so +# both variants carry it with no build-arg to plumb through four call sites; +# and inheritance means the label states the pin of the base the variant +# ACTUALLY built on — which is the question when base-decide cache-hits an +# older base. Like every se.jordbo.pi-devbox.* label this records INTENT; the +# ground truth is /etc/pi-devbox/build-manifest.json's mempalace_version, read +# from the installed binary, and scripts/smoke-test.sh asserts the two agree. +# check-doc-drift.sh check 9 reads this off the last published image so that a +# pin bump must be named in the CHANGELOG — until this label ships, that +# component reports SKIP (label absent on the published release), not OK. +LABEL se.jordbo.pi-devbox.mempalace-version="${MEMPALACE_VERSION}" ENV UV_TOOL_DIR=/opt/uv-tools ENV UV_TOOL_BIN_DIR=/usr/local/bin RUN if [ "${INSTALL_MEMPALACE}" = "true" ]; then \ diff --git a/README.md b/README.md index 417843a..ba2b3bd 100644 --- a/README.md +++ b/README.md @@ -901,8 +901,10 @@ docker inspect --format '{{json .Config.Labels}}' joakimp/pi-devbox:latest | jq ``` `org.opencontainers.image.{version,revision,created}` plus -`se.jordbo.pi-devbox.*-ref` record the intended pi version and companion -refs. The on-disk `/etc/pi-devbox/build-manifest.json` records **ground +`se.jordbo.pi-devbox.*-ref` and `se.jordbo.pi-devbox.*-version` record the +intended pi and mempalace versions and companion refs (`mempalace-version` is +set in `Dockerfile.base` and inherited, so it names the pin of the base the +image actually built on). The on-disk `/etc/pi-devbox/build-manifest.json` records **ground truth** — the actual checked-out commit of each `/opt` clone, the live `pi --version`, and (from v1.8.6) the live `mempalace --version` of the installed palace core — so a tag is reconstructable after CI logs rotate: diff --git a/scripts/check-doc-drift.sh b/scripts/check-doc-drift.sh index 5d9abbf..bf8588c 100755 --- a/scripts/check-doc-drift.sh +++ b/scripts/check-doc-drift.sh @@ -414,7 +414,9 @@ fi # a tag or branch is `git ls-remote`d (peeled `^{}` first -- an annotated # tag's un-dereferenced SHA is the tag object, a false alarm this repo has # already fallen for once), pi-studio is the highest semver tag, and -# `PI_VERSION` is compared as a literal against the `pi-version` label. +# `PI_VERSION` / `MEMPALACE_VERSION` are compared as literals against the +# `pi-version` / `mempalace-version` labels (the latter set in Dockerfile.base +# and inherited; absent on releases before it shipped, which reports SKIP). # # The rule: baked == would-bake is OK with no mention required. If they # differ, the text ABOVE the last published version's `## ` heading -- i.e. @@ -472,7 +474,8 @@ pi-atelier|ref|$ATELIER_REPO|$ATELIER_ACTUAL mempalace-toolkit|ref|$MPTK_REPO|$MPTK_REF pi-studio|studio|$STUDIO_REPO| skillset-snapshot|literal||$SKILLSET_SNAPSHOT -pi-version|literal||$PI_ACTUAL" +pi-version|literal||$PI_ACTUAL +mempalace-version|literal||$MEMPALACE_ACTUAL" REF_RC=0 # Same discipline as check 8: no `|| true` on the python, or a printed DRIFT # exits 0. Per-component SKIP lines are counted afterwards by grep, so a run @@ -600,7 +603,9 @@ for line in os.environ["COMPONENTS"].splitlines(): if not line.strip(): continue name, kind, url, ref = line.split("|", 3) - key = LABEL + name if name == "pi-version" else LABEL + name + "-ref" + # -ref labels hold SHAs; names that already end in -version are the + # label (pi-version, mempalace-version) -- a version string, compared literally. + key = LABEL + name if name.endswith("-version") else LABEL + name + "-ref" try: if kind == "studio": if studio_labels is None: diff --git a/scripts/smoke-test.sh b/scripts/smoke-test.sh index 7a4a967..12d272e 100755 --- a/scripts/smoke-test.sh +++ b/scripts/smoke-test.sh @@ -597,6 +597,19 @@ if [ -n "$LBL" ] && [ "$LBL" != "" ]; then else printf " ❌ OCI label se.jordbo.pi-devbox.pi-extensions-ref missing or empty\n"; FAIL=$((FAIL+1)) fi +# mempalace-version is set in Dockerfile.base and INHERITED by the variant, so +# it states the pin of the base this image actually built on. It must equal the +# installed binary: the one way they diverge is a base built with +# INSTALL_MEMPALACE=false (label says 3.x, nothing installed) or an install that +# resolved to something other than the pin — both invisible to a label-only +# check. Same ground-truth rule as the manifest assertion above. +MP_LBL=$(docker inspect --format '{{ index .Config.Labels "se.jordbo.pi-devbox.mempalace-version" }}' "$IMAGE" 2>/dev/null || true) +MP_BIN=$(docker run --rm --entrypoint= "$IMAGE" sh -c 'mempalace --version 2>/dev/null | head -n1 | tr -d "\r"' 2>/dev/null || true); MP_BIN=${MP_BIN##* } +if [ -n "$MP_LBL" ] && [ "$MP_LBL" != "" ] && [ "$MP_LBL" = "$MP_BIN" ]; then + printf " ✅ OCI label se.jordbo.pi-devbox.mempalace-version=%s equals the installed core\n" "$MP_LBL"; PASS=$((PASS+1)) +else + printf " ❌ OCI label se.jordbo.pi-devbox.mempalace-version=[%s] vs installed mempalace=[%s]\n" "$MP_LBL" "$MP_BIN"; FAIL=$((FAIL+1)) +fi # ── Runtime deployment (needs entrypoint to run) ────────────────────── echo ""