Check that the build version reaches the binary - #93
Merged
Merged
Conversation
- Read the linker flags back out of each binary the Makefile builds. - Refuse an image build that takes a VERSION arg without declaring it. - Run the built container and the released binary to confirm the version.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
The version probe in the
testjob runsmakeon the host. The image builds are where aVERSIONbuild arg was dropped, and nothing looked there. Three checks close that, each catching a different failure.The Makefile reads the linker flags back.
all,static, andlambdanow rungo version -magainst what they just built and fail whenVERSIONis not in it. The lambda binary callslambda.Startinmain, so it cannot be asked for its version; the recorded build settings answer instead.pr.ymlrefuses an image build that takesVERSIONwithout declaring it. This is the exact invariant that was violated.Dockerfile.lambdaandDockerfile.binarieswere handed the arg and never declaredARG VERSION, so Docker discarded it.pr.ymlandrelease.ymlask the artifact. The container build now loads and runsdims version. The release workflow unzips the standalone binary and does the same. Both runners are native for their architecture, so the artifact answers for itself.VERSIONalso falls back tounknownrather than an empty string whengit rev-parsefails, so a build from a source tarball still stamps something.Verify
The Makefile guard, in the builder image:
The declaration guard:
The artifact check, against the real failure. Removing
ARG VERSIONfromDockerfileand building with--build-arg VERSION=pr-999:With the declaration in place the same build reports
pr-999.make VERSION=version-probestill satisfies the existing probe, andgo test -race -count=1 ./...passes on the builder image.make lambdareaches its zip step, which the plain builder image cannot run becausezipis installed byDockerfile.lambdarather than the base image. The guard runs before that and passes.