Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@ updates:
patterns: ["*"]
update-types: [minor, patch]

- package-ecosystem: docker
directory: /buildtools/wasm
schedule:
interval: weekly

- package-ecosystem: npm
directory: /
schedule:
Expand Down
4 changes: 2 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,8 +52,8 @@ Bumping `buildtools/wasm/ghc-wasm-meta.txt` means revisiting, in the same PR:

- `WASM_CFLAGS` in the Dockerfile against ghc-wasm-meta's current defaults (keep `-mtail-call`).
- `index-state` in `buildtools/wasm/cabal.project`.
- The pre-seeded `fgl` tarball version in the Dockerfile: it must equal what the solver picks at
that `index-state`. The pre-seed exists because Hackage's CDN returns 403 to cabal's download.
- The pre-seeded `fgl` tarball version and sha256 in `build.sh`: the version must equal what the
solver picks at that `index-state`. The pre-seed exists because Hackage's CDN returns 403 to cabal's download.

The Dockerfile is validated by review and by `ci.yml`, which builds the artifact on every run
(Docker layer cache via `type=gha`).
Expand Down
2 changes: 1 addition & 1 deletion buildtools/wasm/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM debian:13-slim AS toolchain
FROM debian:13-slim@sha256:a99cfc517144bc59b1978475ec53b46ecabec7e43635402ee5b77cc54cd1b20a AS toolchain
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
# GHC-built tools abort on non-ASCII output in the POSIX locale.
ENV LANG=C.UTF-8
Expand Down
5 changes: 4 additions & 1 deletion buildtools/wasm/build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,15 @@ ghc_wasm="${GHC_WASM_PREFIX:-/root/.ghc-wasm}"
mkdir -p "$out"

# Hackage's CDN answers cabal's own download of this tarball with 403; pre-seed the cache.
# The version must equal what the solver picks at cabal.project's index-state.
# The version must equal what the solver picks at cabal.project's index-state; the hash pins
# the content cabal would otherwise have verified itself.
fgl_version=5.8.3.1
fgl_sha256=02f71384d3f286f8473a58c55ed3ca040f4d142ca4badf5c024ab077bc40362f
fgl_dir="$ghc_wasm/.cabal/packages/hackage.haskell.org/fgl/$fgl_version"
mkdir -p "$fgl_dir"
curl -fL --retry 5 -o "$fgl_dir/fgl-$fgl_version.tar.gz" \
"https://hackage.haskell.org/package/fgl-$fgl_version/fgl-$fgl_version.tar.gz"
echo "$fgl_sha256 $fgl_dir/fgl-$fgl_version.tar.gz" | sha256sum -c -

wasm32-wasi-cabal update
wasm32-wasi-cabal build exe:shellcheck
Expand Down
Loading