Something went wrong. Try again.
linux observer
Something went wrong. Try again.
8.2 kB · 171 lines
at main
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172# SPDX-License-Identifier: AGPL-3.0-only# Copyright (c) 2026 sol pbcARG UBUNTU_TOOL_BASEARG FEDORA_TOOL_BASEFROM ${UBUNTU_TOOL_BASE} AS baselineARG DEBIAN_FRONTEND=noninteractiveARG RUST_VERSION=1.97.1ARG UBUNTU_TOOL_BASERUN case "$UBUNTU_TOOL_BASE" in \ sha256:*) suffix="${UBUNTU_TOOL_BASE#sha256:}" ;; \ *@sha256:*) suffix="${UBUNTU_TOOL_BASE##*@sha256:}" ;; \ *) exit 1 ;; \ esac \ && test "${#suffix}" -eq 64 \ && case "$suffix" in *[!0-9a-f]*) exit 1 ;; *) ;; esacENV PATH="/root/.cargo/bin:${PATH}"ENV CARGO_NET_OFFLINE=trueWORKDIR /src# The full repository is required: build.rs rasterizes contrib/icons and# deliberately panics if those canonical source files cannot be read.COPY . .RUN rustc --version --verbose > /tmp/rustc-verbose \ && grep -Fx "release: ${RUST_VERSION}" /tmp/rustc-verbose \ && grep -Fx "host: x86_64-unknown-linux-gnu" /tmp/rustc-verbose \ && grep -Eq "^rustc ${RUST_VERSION} \([0-9a-f]+ [0-9]{4}-[0-9]{2}-[0-9]{2}\)$" /tmp/rustc-verbose \ || { echo "error: Rust compiler mismatch: expected ${RUST_VERSION} x86_64-unknown-linux-gnu verbose banner, actual different" >&2; \ echo "repair: rustup toolchain install ${RUST_VERSION} --profile minimal" >&2; exit 1; }# Cargo currently serializes package name immediately before version. Keep the# non-empty guard below so any JSON ordering change fails the build.RUN cargo build --locked --release -p solstone-linux -p rust-release-manifest \ && VERSION=$(cargo metadata --locked --format-version 1 --no-deps \ | sed -n 's/.*"name":"solstone-linux","version":"\([^"]*\)".*/\1/p') \ && { test -n "$VERSION" \ || { echo "error: package version mismatch: expected a nonempty solstone-linux version, actual empty" >&2; \ echo "repair: cargo metadata --locked --format-version 1 --no-deps" >&2; exit 1; }; } \ && ROOT="solstone-linux-${VERSION}-linux-x86_64" \ && install -D -m 0755 target/release/solstone-linux "/release-tree/${ROOT}/bin/solstone-linux" \ && install -D -m 0644 LICENSE "/release-tree/${ROOT}/LICENSE" \ && install -D -m 0644 packaging/INSTALL-NOTES "/release-tree/${ROOT}/INSTALL-NOTES" \ && install -D -m 0644 RUST_DEPENDENCY_NOTICES.txt "/release-tree/${ROOT}/RUST_DEPENDENCY_NOTICES.txt" \ && mkdir -p "/release-tree/${ROOT}/share/icons" /release \ && cp -R contrib/icons/hicolor "/release-tree/${ROOT}/share/icons/hicolor" \ && tar -C /release-tree -czf "/release/${ROOT}.tar.gz" "$ROOT" \ && printf '%s\n' "$VERSION" > /release/VERSIONFROM scratch AS proof-runner-exportCOPY --from=baseline /src/target/release/rust-release-manifest /proof-runnerFROM baseline AS deb-buildARG CARGO_DEB_VERSION=3.7.0ARG INVOCATION_IDARG SOURCE_COMMITARG SOURCE_ARCHIVE_SHA256ARG CARGO_LOCK_SHA256ARG RELEASE_VERSIONARG UBUNTU_TOOL_BASERUN actual="$(cargo deb --version)" \ && { test "${actual}" = "cargo-deb ${CARGO_DEB_VERSION}" \ || { echo "error: cargo-deb mismatch: expected 'cargo-deb ${CARGO_DEB_VERSION}', actual '${actual:-unavailable}'" >&2; \ echo "repair: provision the local Ubuntu tool image with cargo-deb ${CARGO_DEB_VERSION}" >&2; exit 1; }; } \ && cargo deb --locked --no-build -p solstone-linux \ && VERSION=$(cat /release/VERSION) \ && test "$VERSION" = "$RELEASE_VERSION" \ && DEB="/src/target/debian/solstone-linux_${VERSION}-1_amd64.deb" \ && { test -f "$DEB" \ || { echo "error: Debian artifact mismatch: expected ${DEB}, actual missing" >&2; \ echo "repair: cargo deb --locked --no-build -p solstone-linux" >&2; exit 1; }; } \ && DEB_ROOT=$(mktemp -d) \ && dpkg-deb --raw-extract "$DEB" "$DEB_ROOT" \ && cd "$DEB_ROOT" \ && find . -path ./DEBIAN -prune -o -type f -printf '%P\0' \ | LC_ALL=C sort -z \ | xargs -0 -r md5sum -- > DEBIAN/md5sums \ && md5_count="$(wc -l < DEBIAN/md5sums)" \ && { test "${md5_count}" -eq 20 \ || { echo "error: Debian md5 inventory mismatch: expected 20 payloads, actual ${md5_count:-unavailable}" >&2; \ echo "repair: align the sealing bound with package assets and generated copyright" >&2; exit 1; }; } \ && chmod 0644 DEBIAN/md5sums \ && dpkg-deb --root-owner-group -Zxz -z9 --build "$DEB_ROOT" "${DEB}.sealed" >/dev/null \ && mv "${DEB}.sealed" "$DEB" \ && cd /src \ && DEB_OUT="/release/solstone-linux_${VERSION}-1_amd64.deb" \ && TAR_OUT="/release/solstone-linux-${VERSION}-linux-x86_64.tar.gz" \ && cp "$DEB" "$DEB_OUT" \ && target/release/rust-release-manifest lane-handoff \ --lane deb \ --invocation-id "$INVOCATION_ID" \ --source-commit "$SOURCE_COMMIT" \ --source-archive-sha256 "$SOURCE_ARCHIVE_SHA256" \ --cargo-lock-sha256 "$CARGO_LOCK_SHA256" \ --version "$VERSION" \ --target x86_64-unknown-linux-gnu \ --profile release \ --image-digest "$UBUNTU_TOOL_BASE" \ --baseline-executable target/release/solstone-linux \ --artifact "$TAR_OUT" \ --artifact "$DEB_OUT" \ --output /release/.lane-evidence-handoff.json \ && rm /release/VERSIONFROM scratch AS debCOPY --from=deb-build /release/ /FROM ${FEDORA_TOOL_BASE} AS rpm-buildARG RUST_VERSION=1.97.1ARG CARGO_GENERATE_RPM_VERSION=0.21.0ARG FEDORA_TOOL_BASERUN case "$FEDORA_TOOL_BASE" in \ sha256:*) suffix="${FEDORA_TOOL_BASE#sha256:}" ;; \ *@sha256:*) suffix="${FEDORA_TOOL_BASE##*@sha256:}" ;; \ *) exit 1 ;; \ esac \ && test "${#suffix}" -eq 64 \ && case "$suffix" in *[!0-9a-f]*) exit 1 ;; *) ;; esacENV PATH="/root/.cargo/bin:${PATH}"ENV CARGO_NET_OFFLINE=trueWORKDIR /srcCOPY --from=baseline /src /srcCOPY --from=baseline /release /releaseRUN rustc --version --verbose > /tmp/rustc-verbose \ && grep -Fx "release: ${RUST_VERSION}" /tmp/rustc-verbose \ && grep -Fx "host: x86_64-unknown-linux-gnu" /tmp/rustc-verbose \ && grep -Eq "^rustc ${RUST_VERSION} \([0-9a-f]+ [0-9]{4}-[0-9]{2}-[0-9]{2}\)$" /tmp/rustc-verbose \ || { echo "error: Rust compiler mismatch: expected ${RUST_VERSION} x86_64-unknown-linux-gnu verbose banner, actual different" >&2; \ echo "repair: rustup toolchain install ${RUST_VERSION} --profile minimal" >&2; exit 1; }ARG INVOCATION_IDARG SOURCE_COMMITARG SOURCE_ARCHIVE_SHA256ARG CARGO_LOCK_SHA256ARG RELEASE_VERSIONRUN actual="$(CARGO_NET_OFFLINE=true cargo-generate-rpm --version)" \ && { test "${actual}" = "cargo-generate-rpm ${CARGO_GENERATE_RPM_VERSION}" \ || { echo "error: cargo-generate-rpm mismatch: expected 'cargo-generate-rpm ${CARGO_GENERATE_RPM_VERSION}', actual '${actual:-unavailable}'" >&2; \ echo "repair: provision the local Fedora tool image with cargo-generate-rpm ${CARGO_GENERATE_RPM_VERSION}" >&2; exit 1; }; } \ && CARGO_NET_OFFLINE=true cargo-generate-rpm -p crates/solstone-linux \ && VERSION=$(cat /release/VERSION) \ && test "$VERSION" = "$RELEASE_VERSION" \ && RPM="target/generate-rpm/solstone-linux-${VERSION}-1.x86_64.rpm" \ && { test -f "$RPM" \ || { echo "error: RPM artifact mismatch: expected ${RPM}, actual missing" >&2; \ echo "repair: CARGO_NET_OFFLINE=true cargo-generate-rpm -p crates/solstone-linux" >&2; exit 1; }; } \ && RPM_OUT="/release/solstone-linux-${VERSION}-1.x86_64.rpm" \ && TAR_OUT="/release/solstone-linux-${VERSION}-linux-x86_64.tar.gz" \ && cp "$RPM" "$RPM_OUT" \ && target/release/rust-release-manifest lane-handoff \ --lane rpm \ --invocation-id "$INVOCATION_ID" \ --source-commit "$SOURCE_COMMIT" \ --source-archive-sha256 "$SOURCE_ARCHIVE_SHA256" \ --cargo-lock-sha256 "$CARGO_LOCK_SHA256" \ --version "$VERSION" \ --target x86_64-unknown-linux-gnu \ --profile release \ --image-digest "$FEDORA_TOOL_BASE" \ --baseline-executable target/release/solstone-linux \ --artifact "$TAR_OUT" \ --artifact "$RPM_OUT" \ --output /release/.lane-evidence-handoff.json \ && rm /release/VERSIONFROM scratch AS rpmCOPY --from=rpm-build /release/ /