# Every third-party version arena pins, in one place. Sourced by the build # scripts and passed into the Dockerfile as build args, so bumping a dependency # is a one-line change here rather than a grep across the tree. # # . ./versions.env # # Bumping MEGAMEK_VERSION: also refresh MEGAMEK_RELEASE_DIR / MEGAMEK_SRC_DIR # (upstream's tarballs do not use the same string), then re-run # scripts/build-patched-jar.sh - a patch that no longer applies is the signal # that upstream moved under us. # --- Java ------------------------------------------------------------------- # MegaMek needs Java 21. Temurin is GPLv2 + Classpath Exception; see LICENSING.md. # x86_64 only for now - the checksum is architecture-specific. JDK_VERSION="21.0.12+8" JDK_URL_TAG="jdk-21.0.12%2B8" JDK_ARCHIVE="OpenJDK21U-jdk_x64_linux_hotspot_21.0.12_8.tar.gz" JDK_SHA256="e4446ff06a276155697597cc0f1b15da004ff083f4964a35271ecee567177370" JDK_DIR="jdk-21.0.12+8" # Modules the jlink runtime keeps: 60MB against 346MB for the full JDK, which is # most of the image. # # jdk.net is not optional. Suramadu's Jetty connector configures socket # options through jdk.net.ExtendedSocketOptions on every accept(), so without it # the server binds the port, then throws NoClassDefFoundError on each incoming # connection - a listening socket that refuses every client. # # jdk.accessibility is here because the client is Swing and it costs nothing # measurable. # # jdk.management supplies com.sun.management.OperatingSystemMXBean, which # Suramadu's CpuMonitor loads in a static initialiser. Without it that # initialiser throws, monitoring disables itself, and every stats line reports # cpuUtilization -1 - which is exactly the number you want when asking whether # a match is CPU-bound on a 2-vCPU task. # # Deliberately absent, despite being statically referenced: java.compiler, # java.rmi, jdk.compiler, jdk.javadoc. They come from build-time tooling and # optional code paths in bundled libraries, and cost 14MB. Add one only if # something actually fails without it. # # To find what a new dependency needs, see tests/module-scan.py. JRE_MODULES="java.base,java.datatransfer,java.xml,java.prefs,java.desktop,java.logging,java.management,java.security.sasl,java.naming,java.scripting,java.transaction.xa,java.sql,jdk.unsupported,jdk.crypto.ec,jdk.zipfs,java.instrument,jdk.net,jdk.accessibility,jdk.management" # --- MegaMek ---------------------------------------------------------------- # GPL-3.0 code, CC BY-NC-SA 4.0 data. Both the release tarball (jar + data) and # the source tarball are needed: the patchset applies against source. MEGAMEK_VERSION="0.51.0" MEGAMEK_RELEASE_DIR="MegaMek-0.51.00" # upstream's tarball has a trailing 0 MEGAMEK_SRC_DIR="megamek-0.51.0" # Upstream publishes no digest for either tarball, so these come from a # double fetch that agreed with itself (2026-08-09) and are enforced the way # JDK_SHA256 is. The release asset's bytes are fixed at publish. The source # tarball is generated from the tag on demand - GitHub has committed to # keeping that generation stable, but if it ever changes the build fails # naming this line, and the fix is a fetch you trust and a new digest here. # Bumping MEGAMEK_VERSION: refresh both from such a fetch. MEGAMEK_RELEASE_SHA256="5d673cdaca0ead0e58d6e74db5b2d1e06bc25ccb5caaf332dad71624f6487b85" MEGAMEK_SRC_SHA256="58847cf8413f67194036296d7b33493233cf5316c0ab5f89aaa8451e69c88ee3" # --- Suramadu --------------------------------------------------------------- # The AGPL-3.0 fork by manticore-projects of Webswing v20.2.5, the last release # under that licence. Renamed from "Webswing Lite" to Suramadu in 26.4.6; see # LICENSING.md. The distribution renamed with it - the archive, the war, the # config files and the frontend bundles are all suramadu-* from 26.4.6 on. SURAMADU_VERSION="26.4.7" SURAMADU_WAR="suramadu-server-26.4.7.war" # Same story as MegaMek's: no published digest, so this is from the same # verified double fetch, of a release asset whose bytes are fixed at publish. SURAMADU_SHA256="4fbf166d633493669e1545b6427fa87c40c826a63a18b559e5487d9a95c2cd79" # --- async-profiler --------------------------------------------------------- # Apache-2.0. Staged in the image but never loaded unless ARENA_PROFILE is set; # see container/entrypoint.sh. x86_64 only, like the JDK - the checksum is # architecture-specific. # # The digest is the one GitHub publishes for the release asset: # gh api repos/async-profiler/async-profiler/releases/tags/v4.5 \ # --jq '.assets[] | select(.name=="async-profiler-4.5-linux-x64.tar.gz") | .digest' # # scripts/build.sh does not pass these as build args yet, so the Dockerfile # carries the same four values as ARG defaults. tests/shell/test-profiling.sh # fails if the two drift. ASYNC_PROFILER_VERSION="4.5" ASYNC_PROFILER_ARCHIVE="async-profiler-4.5-linux-x64.tar.gz" ASYNC_PROFILER_SHA256="89546fbb9ee0fc5496c7edd4099b0709489bc78b0d8057ccbb4b801f6b032b62" ASYNC_PROFILER_DIR="async-profiler-4.5-linux-x64" # --- Image ------------------------------------------------------------------ IMAGE_NAME="${IMAGE_NAME:-lance-blue/arena}" # The tag is unique per build: dependency versions plus the branch and commit, # so a stale image can never be mistaken for the current one and the registry # can refuse tag reuse. Outside a work tree the ref reads "unknown"; a dirty # tree is marked, and push.sh refuses both. if [ -z "${BUILD_REF:-}" ]; then _repo="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" BUILD_REF="$(git -C "$_repo" rev-parse --short=12 HEAD 2>/dev/null || echo unknown)" if [ "$BUILD_REF" != unknown ]; then # Branch before commit. Characters docker rejects in a tag (slashes in # particular) become dashes; a detached HEAD contributes no branch. _branch="$(git -C "$_repo" rev-parse --abbrev-ref HEAD 2>/dev/null || echo HEAD)" if [ "$_branch" != HEAD ]; then BUILD_REF="$(printf '%s' "$_branch" | tr -c 'A-Za-z0-9_.-' '-')-$BUILD_REF" fi if [ -n "$(git -C "$_repo" status --porcelain 2>/dev/null)" ]; then BUILD_REF="$BUILD_REF-dirty" fi unset _branch fi unset _repo fi IMAGE_TAG="${IMAGE_TAG:-mm${MEGAMEK_VERSION}-sur${SURAMADU_VERSION}-${BUILD_REF}}"