Files
archy/image-recipe/_archived
archipelagoandClaude Opus 5 d9b3a7d5e0 fix(10-03): quote the Dockerfile heredoc so comments cannot execute
`cat > "$WORK_DIR/Dockerfile.rootfs" <<DOCKERFILE` was unquoted, so the build
shell performed command substitution on the Dockerfile body. Any backtick in a
Dockerfile COMMENT was executed on the build host and its output spliced into
the generated file. Six comments did this. One of them ran
`systemctl start archipelago-fips.service` against the build machine on every
ISO build; the others were harmless only by accident of being command-not-found.

Fixes the class, not the six instances. The delimiter is now quoted, so the
body is emitted verbatim and a future backticked comment is inert. Verified the
boundary by line range first: the other backticked comments in this file
(:264, :809, :1188, :1289, :1506, :1605, :3597, :3651) are ordinary shell
comments outside any unquoted heredoc and were never at risk — they are
untouched.

The body needs exactly four build-time values and they are all package names
(LINUX_IMAGE_PKG, GRUB_EFI_PKG, GRUB_EFI_SIGNED_PKG, GRUB_PC_PKG), on four
consecutive lines. So quoting was practical: the heredoc is split into
DOCKERFILE_HEAD and DOCKERFILE_TAIL, both quoted, with a single explicit printf
interpolating those four names between them. Escapes that existed only because
the heredoc was unquoted are undone in the same pass: six trailing `\\` become
`\` (Docker line continuations) and four `\$` become `$` (RUN arguments reach
the shell verbatim — Docker does not substitute variables in RUN).

Verified by rendering the generated Dockerfile before and after with the same
inputs and diffing them normalised (continuations joined, whitespace
collapsed). Both are 190 normalised lines and the ONLY differences are the six
comments regaining their text — every instruction is byte-identical. Before:
"# the archipelago backend calls" / after: "# the archipelago backend calls
`systemctl start archipelago-fips.service`".

Test: case 7 asserts every heredoc writing Dockerfile.rootfs has a quoted
delimiter, and when one is not, reports which body lines would execute. The
assertion is on the delimiter, not on backticks — with quoting a backticked
comment is legal and six of them are back in the body on purpose, so flagging
backticks would flag a non-bug and fail on the very comments this restored.

This bug is invisible to `bash -n`; an instance of it introduced earlier in
this plan hung a syntactically-clean build for two minutes before being caught.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-02 09:48:19 -04:00
..

Archived ISO build recipes

These scripts built the Archipelago auto-installer ISO (bundled and unbundled variants). As of v1.7.43-alpha, ISOs are no longer part of the release deliverable. Releases ship as tarballs consumed by scripts/self-update.sh on existing nodes.

Archived here rather than deleted so they can be resurrected if ISO distribution is reintroduced.

Contents

  • build-auto-installer-iso.sh — orchestrator, bundles container images into squashfs
  • build-unbundled-iso.sh — thin wrapper that sets BUNDLE_IMAGES=0 and delegates
  • test-iso-qemu.sh — smoke-tests a built ISO under QEMU
  • scripts/convert-iso-to-disk.sh — converts an ISO to a raw disk image
  • BUILD-ISO-STATUS.md, ISO-BUILD-CHECKLIST.md — contributor guides
  • branding/isohdpfx.bin — isolinux MBR hybrid image
  • .gitea-workflows/build-iso-dev.yml — CI workflow that ran the build+smoke-test

To resurrect

  1. git mv image-recipe/_archived/* image-recipe/ (adjust paths back)
  2. Restore .gitea/workflows/build-iso-dev.yml
  3. Re-add release-process references (see scripts/create-release.sh, docs/BETA-RELEASE-CHECKLIST.md, docs/hotfix-process.md, README.md).

Why archived

The release flow is simpler and faster as tarball-only:

  • releases/vX.Y.Z-alpha/archipelago (backend binary)
  • releases/vX.Y.Z-alpha/archipelago-frontend-X.Y.Z-alpha.tar.gz (frontend + AIUI + filebrowser UI assets)
  • releases/manifest.json (pointers + changelog)

Nodes pull these via scripts/self-update.sh from either Gitea mirror. Filebrowser and AIUI remain bundled inside the frontend tarball and deployed atomically by self-update.sh.