Conversation
…irebirdSQL#47) The FB3 installer sets the generated SYSDBA password with 'gsec', which links against libtommath.so.0 and libncurses.so.5. Both were provisioned in RUN steps after install.sh, so gsec failed to load and the installer silently carried on. Images shipped an untouched security3.fdb (no Srp user, no PLG$SRP) with a SYSDBA.password that was never set, and every Srp login failed with "Install incomplete". Move the libtommath symlink and the libncurses5/libtinfo5 provisioning into the main RUN step, ahead of install.sh. Add tests covering the stock container's SYSDBA.password credentials. Record as D-019.
archive.ubuntu.com superseded 6.3-2ubuntu0.2 and the old .deb now returns 404, breaking the Firebird 3 Noble build.
… start (issue FirebirdSQL#48) When FIREBIRD_ROOT_PASSWORD is not set, the SYSDBA password was the one generated by the Firebird installer at image build time: the same for every container of an image, and readable by anyone who can pull it. The entrypoint now generates a random password, sets it (Srp, plus Legacy_UserManager with FIREBIRD_USE_LEGACY_AUTH=true) and rewrites /opt/firebird/SYSDBA.password. Only the file's path is logged, not the password. It does so only while the security database still matches the checksum recorded at build time, so restarts keep the password and a bind-mounted security database (issue FirebirdSQL#5) is never touched. See DECISIONS.md D-021.
…initialization step set_sysdba now changes the security database even without FIREBIRD_ROOT_PASSWORD, so a missing FIREBIRD_PASSWORD was only detected after SYSDBA had been changed. Fail first, without changing anything (restores FIREBIRD_USER_fails_without_password).
fdcastel
marked this pull request as ready for review
September 26, 2026 21:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #48.
Problem
When
FIREBIRD_ROOT_PASSWORDis not set, the SYSDBA password is the one the Firebird installer generated at image build time. It is baked into an image layer, so every container of an image shares it, and anyone who can pull the image can read it from/opt/firebird/SYSDBA.password. A container started with port 3050 published and withoutFIREBIRD_ROOT_PASSWORDhas SYSDBA protected by a publicly known password. FB4 and FB5 images are affected today. FB3 images will be too once #49 makes the installer's password actually work.Fix
src/Dockerfile.template: after./install.sh, record the SHA-256 checksum of the security database as shipped in the image (/opt/firebird/.security.fdb.sha256).src/entrypoint.sh, whenFIREBIRD_ROOT_PASSWORDis not set and the security database still matches that checksum:CREATE OR ALTER USER SYSDBA ... USING PLUGIN Srp(andLegacy_UserManagerwhenFIREBIRD_USE_LEGACY_AUTH=true, like the existingFIREBIRD_ROOT_PASSWORDpath);/opt/firebird/SYSDBA.passwordin the installer's format (mode 0440).FIREBIRD_ROOT_PASSWORDand without generating/opt/firebird/SYSDBA.password#5 use case) doesn't match either, so its SYSDBA password is never overwritten. A plain marker file would have reset it on every container recreation.FIREBIRD_ROOT_PASSWORDis set is unchanged.FIREBIRD_USER/FIREBIRD_PASSWORDare now validated before any initialization step. A missingFIREBIRD_PASSWORDfails the container before SYSDBA is changed (keepsFIREBIRD_USER_fails_without_passwordpassing).src/image.tests.ps1, new tests:SYSDBA_password_is_generated_on_container_first_start:docker restart.FIREBIRD_USE_LEGACY_AUTH_generated_sysdba_password_works_with_legacy_auth: server restricted toAuthServer = Legacy_Auth.SYSDBA_password_is_kept_for_bind_mounted_security_database: a security database with a known SYSDBA password, bind-mounted into a new container, keeps that password.FIREBIRD_ROOT_PASSWORDsection no longer calls the installer's password "one-off", and describes the new behaviour.DECISIONS.md: D-021. (D-020 is taken by Support running as a non-root user (firebird or any UID with GID 0) #51.)generated/: updated.Test plan
firebirdsql/firebird:5.0.4, with the new entrypoint and checksum file mounted in:Legacy_Auth-only login works;FIREBIRD_USERwithout a password fails with empty stdout.FIREBIRD_USER_fails_without_passwordand Support running as a non-root user (firebird or any UID with GID 0) #51's non-root tests that exercise theSYSDBA.passwordrewrite as UID 84 and 12345:0.workflow_dispatchwithdistro-filter=trixieat9199898: 36272737506 — success. amd64: all 19 releases (3.0.9 → 3.0.14, 4.0.0 → 4.0.7, 5.0.0 → 5.0.4). arm64: 5.0.0 → 5.0.4. 30/30 tests green on each image.Bullseye is excluded from CI validation because of the unrelated
bullseye-security404 (#50).