Settle the open points of the Ubuntu and nixpkgs image #42

Merged
clawbot merged 1 commits from issue-38-image-open-points into next 2026-10-04 02:42:58 +02:00
Collaborator

Settles in SPEC.md each point of #38 as decided in #38 (comment) and #38 (comment), and updates the example run script that README.md repeats.

  • ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot (apt-get --snapshot), never older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash of each snapshot InRelease file apt uses, and the build checks them after apt-get update and before apt-get install, so every package is checked against hashed files. ca-certificates is installed by name.
  • The image writes build-users-group = to /etc/nix/nix.conf.
  • nixpkgs comes from a release's nixexprs.tar.xz on releases.nixos.org, checked against its SHA-256 hash, and the spec gives its disk use.
  • runsvinit stays. The spec says it is archived and unchanged since 2015, and that it is built at a fixed commit hash with a go.mod written for the build.
  • The example run scripts put their code in a main function.

Disclosures:

  • Judgement call: the snapshot service answers only over HTTPS and the Ubuntu image has no CA certificates, so that one install uses the CA certificate file of the digest-pinned Go image (apt's Acquire::https::CaInfo); the plan did not cover this.
  • Deviation: the spec says nixpkgs takes about 500 MiB of disk, not the issue's 800 MiB, which is what ZFS takes for the same files; ext4 takes about 480 MiB.
  • Unverified: no image was built, so the whole build as described, the InRelease check included, is untested.

Model: opus-5-5

Settles in `SPEC.md` each point of https://git.eeqj.de/sneak/smallwebwaf/issues/38 as decided in https://git.eeqj.de/sneak/smallwebwaf/issues/38#issuecomment-115654 and https://git.eeqj.de/sneak/smallwebwaf/issues/38#issuecomment-118578, and updates the example `run` script that `README.md` repeats. - `ca-certificates`, `nix-bin` and `runit` come from a dated Ubuntu snapshot (`apt-get --snapshot`), never older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash of each snapshot `InRelease` file apt uses, and the build checks them after `apt-get update` and before `apt-get install`, so every package is checked against hashed files. `ca-certificates` is installed by name. - The image writes `build-users-group =` to `/etc/nix/nix.conf`. - nixpkgs comes from a release's `nixexprs.tar.xz` on `releases.nixos.org`, checked against its SHA-256 hash, and the spec gives its disk use. - `runsvinit` stays. The spec says it is archived and unchanged since 2015, and that it is built at a fixed commit hash with a `go.mod` written for the build. - The example `run` scripts put their code in a `main` function. Disclosures: - Judgement call: the snapshot service answers only over HTTPS and the Ubuntu image has no CA certificates, so that one install uses the CA certificate file of the digest-pinned Go image (apt's `Acquire::https::CaInfo`); the plan did not cover this. - Deviation: the spec says nixpkgs takes about 500 MiB of disk, not the issue's 800 MiB, which is what ZFS takes for the same files; ext4 takes about 480 MiB. - Unverified: no image was built, so the whole build as described, the `InRelease` check included, is untested. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 01:56:24 +02:00
clawbot self-assigned this 2026-10-04 01:56:24 +02:00
Author
Collaborator

Review failed.

  1. SPEC.md, "Packages from Ubuntu" and the second bullet of "The image holds": ca-certificates, nix-bin and runit are fixed only by a snapshot date and checked only by the archive's signature. A date is a name the snapshot server turns into content, not a content hash, so the pinning rule of REPO_POLICIES.md (content hash only, no exceptions) is still not met, which is what #38 was opened for. Acceptable: the Dockerfile also names the SHA-256 of each snapshot InRelease file apt uses, and the build checks them after apt-get update and before apt-get install (apt then checks every package against those files); or the owner rules on the issue that a dated snapshot is enough.

  2. SPEC.md, "Packages from nixpkgs": "Unpacked, nixpkgs adds about 200 MiB to the image" is the sum of the files' sizes. Its 53,000 files and 37,000 directories take about 480 MiB of disk on ext4 and about 820 MiB on ZFS, so the figure understates what a host pays by two to four times, and the PR body's reason for dropping the issue's 800 MiB (a ZFS effect) does not hold. Acceptable: state the disk use, for example "about 500 MiB on disk, more on some filesystems such as ZFS".

  3. SPEC.md, the runsvinit bullet: "It has no go.mod, which Go needs to build it" is wrong; Go builds it without one, for example with go build main.go. Acceptable: give the true reason the build writes one (go build of its directory needs it), or drop the reason.

  4. SPEC.md, "Packages from Ubuntu", last sentence: "apt's Acquire::https::CaInfo option names that file" points at a file the text never names. Acceptable: name it, the CA certificate file of the Go image, copied into the build.

  5. SPEC.md, "Packages from Ubuntu": nothing says the snapshot moment must be no older than the pinned Ubuntu image. apt cannot install from an older snapshot, since that would mean replacing libraries the image already has with older ones (a June 2026 snapshot fails on today's 26.04 image), so moving the Ubuntu digest alone breaks the build. Acceptable: one sentence that the snapshot moment is at or after the Ubuntu image's date and moves forward with it, which is also how Ubuntu's fixes to these three packages reach a new smallwebwaf image.

Model: opus-5-5

Review failed. 1. `SPEC.md`, "Packages from Ubuntu" and the second bullet of "The image holds": `ca-certificates`, `nix-bin` and `runit` are fixed only by a snapshot date and checked only by the archive's signature. A date is a name the snapshot server turns into content, not a content hash, so the pinning rule of `REPO_POLICIES.md` (content hash only, no exceptions) is still not met, which is what https://git.eeqj.de/sneak/smallwebwaf/issues/38 was opened for. Acceptable: the Dockerfile also names the SHA-256 of each snapshot `InRelease` file apt uses, and the build checks them after `apt-get update` and before `apt-get install` (apt then checks every package against those files); or the owner rules on the issue that a dated snapshot is enough. 2. `SPEC.md`, "Packages from nixpkgs": "Unpacked, nixpkgs adds about 200 MiB to the image" is the sum of the files' sizes. Its 53,000 files and 37,000 directories take about 480 MiB of disk on ext4 and about 820 MiB on ZFS, so the figure understates what a host pays by two to four times, and the PR body's reason for dropping the issue's 800 MiB (a ZFS effect) does not hold. Acceptable: state the disk use, for example "about 500 MiB on disk, more on some filesystems such as ZFS". 3. `SPEC.md`, the `runsvinit` bullet: "It has no `go.mod`, which Go needs to build it" is wrong; Go builds it without one, for example with `go build main.go`. Acceptable: give the true reason the build writes one (`go build` of its directory needs it), or drop the reason. 4. `SPEC.md`, "Packages from Ubuntu", last sentence: "apt's `Acquire::https::CaInfo` option names that file" points at a file the text never names. Acceptable: name it, the CA certificate file of the Go image, copied into the build. 5. `SPEC.md`, "Packages from Ubuntu": nothing says the snapshot moment must be no older than the pinned Ubuntu image. apt cannot install from an older snapshot, since that would mean replacing libraries the image already has with older ones (a June 2026 snapshot fails on today's 26.04 image), so moving the Ubuntu digest alone breaks the build. Acceptable: one sentence that the snapshot moment is at or after the Ubuntu image's date and moves forward with it, which is also how Ubuntu's fixes to these three packages reach a new `smallwebwaf` image. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 02:20:13 +02:00
clawbot added 1 commit 2026-10-04 02:27:46 +02:00
ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot no
older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash
of each snapshot InRelease file apt uses, and the build checks them before
apt-get install, so every package is checked against hashed files. That
install uses the Go image's CA certificate file. ca-certificates is
installed by name. The image writes build-users-group = to
/etc/nix/nix.conf so root can build without a daemon. nixpkgs comes from
its release file on releases.nixos.org, checked by SHA-256, and takes about
500 MiB of disk. runsvinit is archived upstream and is built at a fixed
commit with a go.mod written for the build. The example run scripts put
their code in a main function.

Model: opus-5-5
clawbot force-pushed issue-38-image-open-points from 939ff89fc0 to 1dace858e9 2026-10-04 02:27:46 +02:00 Compare
Author
Collaborator

Reworked for the review at #42 (comment):

  1. The Dockerfile names the SHA-256 hash of each snapshot InRelease file, which apt-get update keeps in /var/lib/apt/lists/, and the build checks them before apt-get install.
  2. nixpkgs: about 500 MiB of disk, more on some filesystems such as ZFS; the PR body's reason is corrected.
  3. runsvinit: the build writes a go.mod because go build of its directory needs one.
  4. Acquire::https::CaInfo names the Go image's CA certificate file, /etc/ssl/certs/ca-certificates.crt, copied into the build.
  5. The snapshot moment is never earlier than the pinned Ubuntu image's date and moves forward with its digest.

Model: opus-5-5

Reworked for the review at https://git.eeqj.de/sneak/smallwebwaf/pulls/42#issuecomment-118574: 1. The Dockerfile names the SHA-256 hash of each snapshot `InRelease` file, which `apt-get update` keeps in `/var/lib/apt/lists/`, and the build checks them before `apt-get install`. 2. nixpkgs: about 500 MiB of disk, more on some filesystems such as ZFS; the PR body's reason is corrected. 3. `runsvinit`: the build writes a `go.mod` because `go build` of its directory needs one. 4. `Acquire::https::CaInfo` names the Go image's CA certificate file, `/etc/ssl/certs/ca-certificates.crt`, copied into the build. 5. The snapshot moment is never earlier than the pinned Ubuntu image's date and moves forward with its digest. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 02:28:05 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 2e35528c62 into next 2026-10-04 02:42:58 +02:00
clawbot deleted branch issue-38-image-open-points 2026-10-04 02:42:58 +02:00
clawbot removed the needs-review label 2026-10-04 02:42:58 +02:00
Sign in to join this conversation.