Dockerfile.base: LABEL se.jordbo.pi-devbox.mempalace-version, inherited by both variants
Closes the blind spot check 9 (cb6d9e5) named: no label recorded the palace pin, so a MEMPALACE_VERSION bump — the one component whose skew against the shared central palace is fleet-wide — could ship without a CHANGELOG line. In Dockerfile.base, not Dockerfile.variant, deliberately: the value sits next to the ARG that defines it (a copy in the variant is one more pin able to drift); labels are inherited by every image built FROM the base, so no build-arg to plumb through the variant's four call sites; and inheritance means the label states the pin of the base the image ACTUALLY built on, which is the question when base-decide cache-hits an older base. Both mechanisms measured on the published v1.9.2 config blob rather than assumed: maintainer + image.source (set only in Dockerfile.base) are present on the variant image, and pi-version=0.85.1 is an ARG expanded inside a LABEL. Intent, like every se.jordbo.pi-devbox.* label; the manifest's mempalace_version (read from the installed binary) stays the ground truth, and smoke-test.sh now asserts label == installed core — the one way they diverge is a base built with INSTALL_MEMPALACE=false or an off-pin install, both invisible to a label-only check. check-doc-drift check 9 gains the component (literal, against ARG MEMPALACE_VERSION in Dockerfile.base); the label-key rule generalises to "names ending in -version are the label itself". Until a release carries the label it reports a counted SKIP, not OK — measured: "v1.9.2 carries no se.jordbo.pi-devbox.mempalace-version label", summary says 1 SKIPPED. Costs nothing extra: this Unreleased already forces a base rebuild (50153e6rootfs/ skill floor). check-base-hash unchanged (no new *_REF).
This commit is contained in:
@@ -111,7 +111,9 @@ re-brand of opencode-devbox's `pi-only` variant.
|
||||
`git ls-remote`s each floating `*_REF`. A red check 9 means an upstream
|
||||
(pi-toolkit, pi-extensions, mempalace-toolkit, pi-fork,
|
||||
pi-observational-memory, pi-studio) moved and no entry names the new SHA;
|
||||
the failure prints the compare URL. Name the 7-char SHA where you describe
|
||||
the failure prints the compare URL; a `PI_VERSION` or `MEMPALACE_VERSION`
|
||||
bump is caught the same way via the `pi-version` / `mempalace-version`
|
||||
labels. Name the 7-char SHA (or version) where you describe
|
||||
the change — that is what the old "Dependency audit" tables recorded by
|
||||
hand, now required.
|
||||
|
||||
|
||||
@@ -75,6 +75,22 @@ would fire on nothing wrong), and a "documented tag exists on Hub" check
|
||||
(check 8 already SKIPs a missing tag by name, and a hard fail would
|
||||
misreport the window between tagging and publish).
|
||||
|
||||
**Blind spot closed while it was free: `se.jordbo.pi-devbox.mempalace-version`.**
|
||||
No label recorded the palace pin, so check 9 could not see a `MEMPALACE_VERSION`
|
||||
bump — checks 1–3 keep README's pin table consistent, but nothing required a
|
||||
CHANGELOG line for the one component whose skew against the shared central
|
||||
palace is fleet-wide. The label is set in `Dockerfile.base` next to the `ARG`
|
||||
that defines it and **inherited** by both variants: no second copy of the pin to
|
||||
drift, no build-arg to plumb through four variant call sites, and it states the
|
||||
pin of the base the image *actually* built on — the question that matters when
|
||||
`base-decide` cache-hits an older base. Intent, like every label here; the
|
||||
manifest's `mempalace_version` stays the ground truth, and `smoke-test.sh` now
|
||||
asserts label == installed binary (the one way they diverge is a base built with
|
||||
`INSTALL_MEMPALACE=false`, or an install that resolved off-pin). Until a release
|
||||
carries the label, check 9 reports that component as a counted SKIP, not OK;
|
||||
costs nothing extra because this Unreleased already forces a base rebuild
|
||||
(`rootfs/` skill floor).
|
||||
|
||||
---
|
||||
|
||||
**The rule "use `pi-task`, not `fork`, for a brief that carries a prohibition" was
|
||||
|
||||
@@ -552,6 +552,20 @@ ARG INSTALL_MEMPALACE=true
|
||||
# so they stay dark until synlig is redeployed — a client bump alone cannot
|
||||
# light them up.
|
||||
ARG MEMPALACE_VERSION=3.9.0
|
||||
# Recorded as a label HERE, not in Dockerfile.variant, for three reasons: the
|
||||
# value lives next to the ARG that defines it (a second copy in the variant
|
||||
# would be one more pin able to drift, which is the class check-doc-drift.sh
|
||||
# exists to catch); labels are inherited by every image built FROM this one, so
|
||||
# both variants carry it with no build-arg to plumb through four call sites;
|
||||
# and inheritance means the label states the pin of the base the variant
|
||||
# ACTUALLY built on — which is the question when base-decide cache-hits an
|
||||
# older base. Like every se.jordbo.pi-devbox.* label this records INTENT; the
|
||||
# ground truth is /etc/pi-devbox/build-manifest.json's mempalace_version, read
|
||||
# from the installed binary, and scripts/smoke-test.sh asserts the two agree.
|
||||
# check-doc-drift.sh check 9 reads this off the last published image so that a
|
||||
# pin bump must be named in the CHANGELOG — until this label ships, that
|
||||
# component reports SKIP (label absent on the published release), not OK.
|
||||
LABEL se.jordbo.pi-devbox.mempalace-version="${MEMPALACE_VERSION}"
|
||||
ENV UV_TOOL_DIR=/opt/uv-tools
|
||||
ENV UV_TOOL_BIN_DIR=/usr/local/bin
|
||||
RUN if [ "${INSTALL_MEMPALACE}" = "true" ]; then \
|
||||
|
||||
@@ -901,8 +901,10 @@ docker inspect --format '{{json .Config.Labels}}' joakimp/pi-devbox:latest | jq
|
||||
```
|
||||
|
||||
`org.opencontainers.image.{version,revision,created}` plus
|
||||
`se.jordbo.pi-devbox.*-ref` record the intended pi version and companion
|
||||
refs. The on-disk `/etc/pi-devbox/build-manifest.json` records **ground
|
||||
`se.jordbo.pi-devbox.*-ref` and `se.jordbo.pi-devbox.*-version` record the
|
||||
intended pi and mempalace versions and companion refs (`mempalace-version` is
|
||||
set in `Dockerfile.base` and inherited, so it names the pin of the base the
|
||||
image actually built on). The on-disk `/etc/pi-devbox/build-manifest.json` records **ground
|
||||
truth** — the actual checked-out commit of each `/opt` clone, the live
|
||||
`pi --version`, and (from v1.8.6) the live `mempalace --version` of the
|
||||
installed palace core — so a tag is reconstructable after CI logs rotate:
|
||||
|
||||
@@ -414,7 +414,9 @@ fi
|
||||
# a tag or branch is `git ls-remote`d (peeled `^{}` first -- an annotated
|
||||
# tag's un-dereferenced SHA is the tag object, a false alarm this repo has
|
||||
# already fallen for once), pi-studio is the highest semver tag, and
|
||||
# `PI_VERSION` is compared as a literal against the `pi-version` label.
|
||||
# `PI_VERSION` / `MEMPALACE_VERSION` are compared as literals against the
|
||||
# `pi-version` / `mempalace-version` labels (the latter set in Dockerfile.base
|
||||
# and inherited; absent on releases before it shipped, which reports SKIP).
|
||||
#
|
||||
# The rule: baked == would-bake is OK with no mention required. If they
|
||||
# differ, the text ABOVE the last published version's `## ` heading -- i.e.
|
||||
@@ -472,7 +474,8 @@ pi-atelier|ref|$ATELIER_REPO|$ATELIER_ACTUAL
|
||||
mempalace-toolkit|ref|$MPTK_REPO|$MPTK_REF
|
||||
pi-studio|studio|$STUDIO_REPO|
|
||||
skillset-snapshot|literal||$SKILLSET_SNAPSHOT
|
||||
pi-version|literal||$PI_ACTUAL"
|
||||
pi-version|literal||$PI_ACTUAL
|
||||
mempalace-version|literal||$MEMPALACE_ACTUAL"
|
||||
REF_RC=0
|
||||
# Same discipline as check 8: no `|| true` on the python, or a printed DRIFT
|
||||
# exits 0. Per-component SKIP lines are counted afterwards by grep, so a run
|
||||
@@ -600,7 +603,9 @@ for line in os.environ["COMPONENTS"].splitlines():
|
||||
if not line.strip():
|
||||
continue
|
||||
name, kind, url, ref = line.split("|", 3)
|
||||
key = LABEL + name if name == "pi-version" else LABEL + name + "-ref"
|
||||
# <name>-ref labels hold SHAs; names that already end in -version are the
|
||||
# label (pi-version, mempalace-version) -- a version string, compared literally.
|
||||
key = LABEL + name if name.endswith("-version") else LABEL + name + "-ref"
|
||||
try:
|
||||
if kind == "studio":
|
||||
if studio_labels is None:
|
||||
|
||||
@@ -597,6 +597,19 @@ if [ -n "$LBL" ] && [ "$LBL" != "<no value>" ]; then
|
||||
else
|
||||
printf " ❌ OCI label se.jordbo.pi-devbox.pi-extensions-ref missing or empty\n"; FAIL=$((FAIL+1))
|
||||
fi
|
||||
# mempalace-version is set in Dockerfile.base and INHERITED by the variant, so
|
||||
# it states the pin of the base this image actually built on. It must equal the
|
||||
# installed binary: the one way they diverge is a base built with
|
||||
# INSTALL_MEMPALACE=false (label says 3.x, nothing installed) or an install that
|
||||
# resolved to something other than the pin — both invisible to a label-only
|
||||
# check. Same ground-truth rule as the manifest assertion above.
|
||||
MP_LBL=$(docker inspect --format '{{ index .Config.Labels "se.jordbo.pi-devbox.mempalace-version" }}' "$IMAGE" 2>/dev/null || true)
|
||||
MP_BIN=$(docker run --rm --entrypoint= "$IMAGE" sh -c 'mempalace --version 2>/dev/null | head -n1 | tr -d "\r"' 2>/dev/null || true); MP_BIN=${MP_BIN##* }
|
||||
if [ -n "$MP_LBL" ] && [ "$MP_LBL" != "<no value>" ] && [ "$MP_LBL" = "$MP_BIN" ]; then
|
||||
printf " ✅ OCI label se.jordbo.pi-devbox.mempalace-version=%s equals the installed core\n" "$MP_LBL"; PASS=$((PASS+1))
|
||||
else
|
||||
printf " ❌ OCI label se.jordbo.pi-devbox.mempalace-version=[%s] vs installed mempalace=[%s]\n" "$MP_LBL" "$MP_BIN"; FAIL=$((FAIL+1))
|
||||
fi
|
||||
|
||||
# ── Runtime deployment (needs entrypoint to run) ──────────────────────
|
||||
echo ""
|
||||
|
||||
Reference in New Issue
Block a user