From ad938e7f79d16d8cd106fde0c63fe3353561adbc Mon Sep 17 00:00:00 2001 From: timonwong Date: Mon, 21 Sep 2026 11:59:22 +0000 Subject: [PATCH] build(wasm): pin the base image digest and verify the fgl tarball debian:13-slim was a mutable tag and the pre-seeded fgl tarball was fetched without any integrity check, so either could change the Artifact without a diff in this repository. Pin the base image by digest and let Dependabot's docker ecosystem keep it current. Check the fgl tarball against its Hackage sha256, cross- checked with commercialhaskell/all-cabal-hashes. --- .github/dependabot.yml | 5 +++++ AGENTS.md | 4 ++-- buildtools/wasm/Dockerfile | 2 +- buildtools/wasm/build.sh | 5 ++++- 4 files changed, 12 insertions(+), 4 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f4e6df6..dfc8577 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,11 @@ updates: patterns: ["*"] update-types: [minor, patch] + - package-ecosystem: docker + directory: /buildtools/wasm + schedule: + interval: weekly + - package-ecosystem: npm directory: / schedule: diff --git a/AGENTS.md b/AGENTS.md index af0a4e5..a41098f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -52,8 +52,8 @@ Bumping `buildtools/wasm/ghc-wasm-meta.txt` means revisiting, in the same PR: - `WASM_CFLAGS` in the Dockerfile against ghc-wasm-meta's current defaults (keep `-mtail-call`). - `index-state` in `buildtools/wasm/cabal.project`. -- The pre-seeded `fgl` tarball version in the Dockerfile: it must equal what the solver picks at - that `index-state`. The pre-seed exists because Hackage's CDN returns 403 to cabal's download. +- The pre-seeded `fgl` tarball version and sha256 in `build.sh`: the version must equal what the + solver picks at that `index-state`. The pre-seed exists because Hackage's CDN returns 403 to cabal's download. The Dockerfile is validated by review and by `ci.yml`, which builds the artifact on every run (Docker layer cache via `type=gha`). diff --git a/buildtools/wasm/Dockerfile b/buildtools/wasm/Dockerfile index 64ff3f8..c140336 100644 --- a/buildtools/wasm/Dockerfile +++ b/buildtools/wasm/Dockerfile @@ -1,4 +1,4 @@ -FROM debian:13-slim AS toolchain +FROM debian:13-slim@sha256:a99cfc517144bc59b1978475ec53b46ecabec7e43635402ee5b77cc54cd1b20a AS toolchain SHELL ["/bin/bash", "-o", "pipefail", "-c"] # GHC-built tools abort on non-ASCII output in the POSIX locale. ENV LANG=C.UTF-8 diff --git a/buildtools/wasm/build.sh b/buildtools/wasm/build.sh index 83adc25..ef5878c 100755 --- a/buildtools/wasm/build.sh +++ b/buildtools/wasm/build.sh @@ -14,12 +14,15 @@ ghc_wasm="${GHC_WASM_PREFIX:-/root/.ghc-wasm}" mkdir -p "$out" # Hackage's CDN answers cabal's own download of this tarball with 403; pre-seed the cache. -# The version must equal what the solver picks at cabal.project's index-state. +# The version must equal what the solver picks at cabal.project's index-state; the hash pins +# the content cabal would otherwise have verified itself. fgl_version=5.8.3.1 +fgl_sha256=02f71384d3f286f8473a58c55ed3ca040f4d142ca4badf5c024ab077bc40362f fgl_dir="$ghc_wasm/.cabal/packages/hackage.haskell.org/fgl/$fgl_version" mkdir -p "$fgl_dir" curl -fL --retry 5 -o "$fgl_dir/fgl-$fgl_version.tar.gz" \ "https://hackage.haskell.org/package/fgl-$fgl_version/fgl-$fgl_version.tar.gz" +echo "$fgl_sha256 $fgl_dir/fgl-$fgl_version.tar.gz" | sha256sum -c - wasm32-wasi-cabal update wasm32-wasi-cabal build exe:shellcheck