From 20ff40594de866599b0c016b1442b2feba30d4c2 Mon Sep 17 00:00:00 2001 From: "F.D.Castel" Date: Wed, 23 Sep 2026 15:00:22 +0000 Subject: [PATCH 1/4] fix(fb3): provision FB3 libraries before running the installer (issue #47) The FB3 installer sets the generated SYSDBA password with 'gsec', which links against libtommath.so.0 and libncurses.so.5. Both were provisioned in RUN steps after install.sh, so gsec failed to load and the installer silently carried on. Images shipped an untouched security3.fdb (no Srp user, no PLG$SRP) with a SYSDBA.password that was never set, and every Srp login failed with "Install incomplete". Move the libtommath symlink and the libncurses5/libtinfo5 provisioning into the main RUN step, ahead of install.sh. Add tests covering the stock container's SYSDBA.password credentials. Record as D-019. --- DECISIONS.md | 6 ++ generated/3.0.10/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/3.0.10/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/3.0.10/jammy/Dockerfile | 82 ++++++++++++---------------- generated/3.0.10/noble/Dockerfile | 82 ++++++++++++---------------- generated/3.0.10/trixie/Dockerfile | 82 ++++++++++++---------------- generated/3.0.11/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/3.0.11/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/3.0.11/jammy/Dockerfile | 82 ++++++++++++---------------- generated/3.0.11/noble/Dockerfile | 82 ++++++++++++---------------- generated/3.0.11/trixie/Dockerfile | 82 ++++++++++++---------------- generated/3.0.12/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/3.0.12/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/3.0.12/jammy/Dockerfile | 82 ++++++++++++---------------- generated/3.0.12/noble/Dockerfile | 82 ++++++++++++---------------- generated/3.0.12/trixie/Dockerfile | 82 ++++++++++++---------------- generated/3.0.13/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/3.0.13/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/3.0.13/jammy/Dockerfile | 82 ++++++++++++---------------- generated/3.0.13/noble/Dockerfile | 82 ++++++++++++---------------- generated/3.0.13/trixie/Dockerfile | 82 ++++++++++++---------------- generated/3.0.14/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/3.0.14/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/3.0.14/jammy/Dockerfile | 82 ++++++++++++---------------- generated/3.0.14/noble/Dockerfile | 82 ++++++++++++---------------- generated/3.0.14/trixie/Dockerfile | 82 ++++++++++++---------------- generated/3.0.9/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/3.0.9/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/3.0.9/jammy/Dockerfile | 82 ++++++++++++---------------- generated/3.0.9/noble/Dockerfile | 82 ++++++++++++---------------- generated/3.0.9/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.0/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.0/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.0/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.0/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.0/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.1/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.1/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.1/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.1/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.1/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.2/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.2/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.2/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.2/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.2/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.3/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.3/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.3/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.3/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.3/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.4/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.4/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.4/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.4/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.4/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.5/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.5/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.5/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.5/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.5/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.6/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.6/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.6/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.6/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.6/trixie/Dockerfile | 82 ++++++++++++---------------- generated/4.0.7/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/4.0.7/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/4.0.7/jammy/Dockerfile | 82 ++++++++++++---------------- generated/4.0.7/noble/Dockerfile | 82 ++++++++++++---------------- generated/4.0.7/trixie/Dockerfile | 82 ++++++++++++---------------- generated/5.0.0/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/5.0.0/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/5.0.0/jammy/Dockerfile | 82 ++++++++++++---------------- generated/5.0.0/noble/Dockerfile | 82 ++++++++++++---------------- generated/5.0.0/trixie/Dockerfile | 82 ++++++++++++---------------- generated/5.0.1/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/5.0.1/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/5.0.1/jammy/Dockerfile | 82 ++++++++++++---------------- generated/5.0.1/noble/Dockerfile | 82 ++++++++++++---------------- generated/5.0.1/trixie/Dockerfile | 82 ++++++++++++---------------- generated/5.0.2/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/5.0.2/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/5.0.2/jammy/Dockerfile | 82 ++++++++++++---------------- generated/5.0.2/noble/Dockerfile | 82 ++++++++++++---------------- generated/5.0.2/trixie/Dockerfile | 82 ++++++++++++---------------- generated/5.0.3/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/5.0.3/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/5.0.3/jammy/Dockerfile | 82 ++++++++++++---------------- generated/5.0.3/noble/Dockerfile | 82 ++++++++++++---------------- generated/5.0.3/trixie/Dockerfile | 82 ++++++++++++---------------- generated/5.0.4/bookworm/Dockerfile | 82 ++++++++++++---------------- generated/5.0.4/bullseye/Dockerfile | 82 ++++++++++++---------------- generated/5.0.4/jammy/Dockerfile | 82 ++++++++++++---------------- generated/5.0.4/noble/Dockerfile | 82 ++++++++++++---------------- generated/5.0.4/trixie/Dockerfile | 82 ++++++++++++---------------- src/Dockerfile.template | 82 ++++++++++++---------------- src/image.tests.ps1 | 31 +++++++++++ 98 files changed, 3301 insertions(+), 4608 deletions(-) diff --git a/DECISIONS.md b/DECISIONS.md index f05efb6..e8a9194 100644 --- a/DECISIONS.md +++ b/DECISIONS.md @@ -121,3 +121,9 @@ Also adds `tzdata` to Noble's distro `extraPackages` (matching Jammy). FB3 relie **Decision:** The `update-repo` job in `publish-fork.yaml` only commits and pushes regenerated `generated/` and `README.md` when running on the fork's default branch (`github.event.repository.default_branch`). Dispatches on PR or feature branches still run `Invoke-Build Prepare` and `Invoke-Build Update-Readme` (so a template-substitution regression still fails the workflow) but skip the `git commit` / `git push`. Amends D-014 for the publish-fork case; `publish.yaml` (the official-repo publish) is unchanged. **Rationale:** `publish-fork.yaml` passes `-Registry 'ghcr.io/'` to `Update-Readme`, which substitutes the fork's registry into the README table header. The previous unguarded auto-commit pushed that fork-specific README back to whatever branch was dispatched, including branches with open upstream PRs — directly polluting the PR diff with content that must not land upstream, and breaking GitHub's linear rebase when the upstream master had its own concurrent `README.md` changes (observed during PR #43, which required a force-pushed clean rebase to unblock). Branch-gating preserves D-014's "generated/ tracked in git" invariant on the fork's default branch while keeping PR/feature branches diff-clean against upstream. Confines the `-Registry` rewrite to the only place the fork wants it (its own showcased README on `master`). + +## D-019: FB3 library provisioning runs before the Firebird installer + +**Decision:** The FB3-only `libtommath.so.0` symlink and the `libncurses5`/`libtinfo5` provisioning (D-017) run inside the main `RUN` step, after the prerequisite `apt-get install` and before `./install.sh -silent`. They are no longer separate `RUN` steps after the install. Amends the placement described in D-017; the provisioning logic itself is unchanged. + +**Rationale:** The FB3 installer sets the generated SYSDBA password with `gsec -add sysdba -pw `, and then writes that password to `/opt/firebird/SYSDBA.password`. FB3's `gsec` (and `libfbclient`, `libSrp.so`) link against `libtommath.so.0` and `libncurses.so.5`/`libtinfo.so.5`. With the libraries provisioned only after the install, `gsec` failed with `error while loading shared libraries: libtommath.so.0`; the installer's `runSilent` wrapper printed the error and carried on. The image therefore shipped the tarball's pristine `security3.fdb` — no Srp user, no `PLG$SRP` table — alongside a `SYSDBA.password` file holding a password that was never set. Any Srp login then failed with the misleading `Install incomplete, please read the Compatibility chapter in the release notes for this version`. The defect stayed hidden because `FIREBIRD_ROOT_PASSWORD` (used in every documented example) and `FIREBIRD_USER` both go through the Srp user manager at container start, which creates the missing structures. The test suite now covers the stock, no-environment container. FB4+ is unaffected: its binaries' dependencies are satisfied by the prerequisite packages. See [issue #47](https://github.com/FirebirdSQL/firebird-docker/issues/47). diff --git a/generated/3.0.10/bookworm/Dockerfile b/generated/3.0.10/bookworm/Dockerfile index 33a9de5..5df1048 100644 --- a/generated/3.0.10/bookworm/Dockerfile +++ b/generated/3.0.10/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.10/bullseye/Dockerfile b/generated/3.0.10/bullseye/Dockerfile index 923d45e..df267bf 100644 --- a/generated/3.0.10/bullseye/Dockerfile +++ b/generated/3.0.10/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.10/jammy/Dockerfile b/generated/3.0.10/jammy/Dockerfile index 3a3bb1d..e269427 100644 --- a/generated/3.0.10/jammy/Dockerfile +++ b/generated/3.0.10/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.10/noble/Dockerfile b/generated/3.0.10/noble/Dockerfile index 6a38647..de260fe 100644 --- a/generated/3.0.10/noble/Dockerfile +++ b/generated/3.0.10/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.10/trixie/Dockerfile b/generated/3.0.10/trixie/Dockerfile index 9c0b884..e7af19f 100644 --- a/generated/3.0.10/trixie/Dockerfile +++ b/generated/3.0.10/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.11/bookworm/Dockerfile b/generated/3.0.11/bookworm/Dockerfile index 652383c..adaefe1 100644 --- a/generated/3.0.11/bookworm/Dockerfile +++ b/generated/3.0.11/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.11/bullseye/Dockerfile b/generated/3.0.11/bullseye/Dockerfile index 0f4a13c..f2bb148 100644 --- a/generated/3.0.11/bullseye/Dockerfile +++ b/generated/3.0.11/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.11/jammy/Dockerfile b/generated/3.0.11/jammy/Dockerfile index 2dd64b2..26bbf47 100644 --- a/generated/3.0.11/jammy/Dockerfile +++ b/generated/3.0.11/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.11/noble/Dockerfile b/generated/3.0.11/noble/Dockerfile index 3c2e520..5a538f7 100644 --- a/generated/3.0.11/noble/Dockerfile +++ b/generated/3.0.11/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.11/trixie/Dockerfile b/generated/3.0.11/trixie/Dockerfile index c5ed8c1..3d5bd41 100644 --- a/generated/3.0.11/trixie/Dockerfile +++ b/generated/3.0.11/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.12/bookworm/Dockerfile b/generated/3.0.12/bookworm/Dockerfile index 7861cfc..cc97d5b 100644 --- a/generated/3.0.12/bookworm/Dockerfile +++ b/generated/3.0.12/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.12/bullseye/Dockerfile b/generated/3.0.12/bullseye/Dockerfile index 8cca737..a95f7cd 100644 --- a/generated/3.0.12/bullseye/Dockerfile +++ b/generated/3.0.12/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.12/jammy/Dockerfile b/generated/3.0.12/jammy/Dockerfile index e7d841a..27c89da 100644 --- a/generated/3.0.12/jammy/Dockerfile +++ b/generated/3.0.12/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.12/noble/Dockerfile b/generated/3.0.12/noble/Dockerfile index e8883d0..9c57e62 100644 --- a/generated/3.0.12/noble/Dockerfile +++ b/generated/3.0.12/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.12/trixie/Dockerfile b/generated/3.0.12/trixie/Dockerfile index 3f2b4d7..32937d7 100644 --- a/generated/3.0.12/trixie/Dockerfile +++ b/generated/3.0.12/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.13/bookworm/Dockerfile b/generated/3.0.13/bookworm/Dockerfile index 8fc958c..95ed430 100644 --- a/generated/3.0.13/bookworm/Dockerfile +++ b/generated/3.0.13/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.13/bullseye/Dockerfile b/generated/3.0.13/bullseye/Dockerfile index 6a33d34..a7c3078 100644 --- a/generated/3.0.13/bullseye/Dockerfile +++ b/generated/3.0.13/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.13/jammy/Dockerfile b/generated/3.0.13/jammy/Dockerfile index 9afb0b4..6f9279a 100644 --- a/generated/3.0.13/jammy/Dockerfile +++ b/generated/3.0.13/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.13/noble/Dockerfile b/generated/3.0.13/noble/Dockerfile index dff334e..4688faa 100644 --- a/generated/3.0.13/noble/Dockerfile +++ b/generated/3.0.13/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.13/trixie/Dockerfile b/generated/3.0.13/trixie/Dockerfile index 5f9f67c..c34b95a 100644 --- a/generated/3.0.13/trixie/Dockerfile +++ b/generated/3.0.13/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.14/bookworm/Dockerfile b/generated/3.0.14/bookworm/Dockerfile index 4c850b0..a14a675 100644 --- a/generated/3.0.14/bookworm/Dockerfile +++ b/generated/3.0.14/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.14/bullseye/Dockerfile b/generated/3.0.14/bullseye/Dockerfile index 4779946..bc74c8f 100644 --- a/generated/3.0.14/bullseye/Dockerfile +++ b/generated/3.0.14/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.14/jammy/Dockerfile b/generated/3.0.14/jammy/Dockerfile index 1c3c449..591ee90 100644 --- a/generated/3.0.14/jammy/Dockerfile +++ b/generated/3.0.14/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.14/noble/Dockerfile b/generated/3.0.14/noble/Dockerfile index eafebd0..2da6264 100644 --- a/generated/3.0.14/noble/Dockerfile +++ b/generated/3.0.14/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.14/trixie/Dockerfile b/generated/3.0.14/trixie/Dockerfile index 96f3f62..c86d032 100644 --- a/generated/3.0.14/trixie/Dockerfile +++ b/generated/3.0.14/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.9/bookworm/Dockerfile b/generated/3.0.9/bookworm/Dockerfile index 1edf8d1..0621dda 100644 --- a/generated/3.0.9/bookworm/Dockerfile +++ b/generated/3.0.9/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.9/bullseye/Dockerfile b/generated/3.0.9/bullseye/Dockerfile index 8c9760f..a840b7c 100644 --- a/generated/3.0.9/bullseye/Dockerfile +++ b/generated/3.0.9/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.9/jammy/Dockerfile b/generated/3.0.9/jammy/Dockerfile index a650711..48a740a 100644 --- a/generated/3.0.9/jammy/Dockerfile +++ b/generated/3.0.9/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.9/noble/Dockerfile b/generated/3.0.9/noble/Dockerfile index e151d28..5001f9f 100644 --- a/generated/3.0.9/noble/Dockerfile +++ b/generated/3.0.9/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/3.0.9/trixie/Dockerfile b/generated/3.0.9/trixie/Dockerfile index 7362a0b..95f68ed 100644 --- a/generated/3.0.9/trixie/Dockerfile +++ b/generated/3.0.9/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.0/bookworm/Dockerfile b/generated/4.0.0/bookworm/Dockerfile index fd0f375..1ef9e7c 100644 --- a/generated/4.0.0/bookworm/Dockerfile +++ b/generated/4.0.0/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.0/bullseye/Dockerfile b/generated/4.0.0/bullseye/Dockerfile index e46610c..a7c8291 100644 --- a/generated/4.0.0/bullseye/Dockerfile +++ b/generated/4.0.0/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.0/jammy/Dockerfile b/generated/4.0.0/jammy/Dockerfile index 4e92ede..548d71f 100644 --- a/generated/4.0.0/jammy/Dockerfile +++ b/generated/4.0.0/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.0/noble/Dockerfile b/generated/4.0.0/noble/Dockerfile index bb272eb..0af0581 100644 --- a/generated/4.0.0/noble/Dockerfile +++ b/generated/4.0.0/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.0/trixie/Dockerfile b/generated/4.0.0/trixie/Dockerfile index ead67a4..ade1478 100644 --- a/generated/4.0.0/trixie/Dockerfile +++ b/generated/4.0.0/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.1/bookworm/Dockerfile b/generated/4.0.1/bookworm/Dockerfile index b07bb8c..5d2f367 100644 --- a/generated/4.0.1/bookworm/Dockerfile +++ b/generated/4.0.1/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.1/bullseye/Dockerfile b/generated/4.0.1/bullseye/Dockerfile index d685b6c..7c1538a 100644 --- a/generated/4.0.1/bullseye/Dockerfile +++ b/generated/4.0.1/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.1/jammy/Dockerfile b/generated/4.0.1/jammy/Dockerfile index dcdf5cc..5df9c7c 100644 --- a/generated/4.0.1/jammy/Dockerfile +++ b/generated/4.0.1/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.1/noble/Dockerfile b/generated/4.0.1/noble/Dockerfile index a0c96fb..29460fe 100644 --- a/generated/4.0.1/noble/Dockerfile +++ b/generated/4.0.1/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.1/trixie/Dockerfile b/generated/4.0.1/trixie/Dockerfile index e05defa..3cecc31 100644 --- a/generated/4.0.1/trixie/Dockerfile +++ b/generated/4.0.1/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.2/bookworm/Dockerfile b/generated/4.0.2/bookworm/Dockerfile index d72ad5f..33212ec 100644 --- a/generated/4.0.2/bookworm/Dockerfile +++ b/generated/4.0.2/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.2/bullseye/Dockerfile b/generated/4.0.2/bullseye/Dockerfile index ffec909..bbf82e7 100644 --- a/generated/4.0.2/bullseye/Dockerfile +++ b/generated/4.0.2/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.2/jammy/Dockerfile b/generated/4.0.2/jammy/Dockerfile index 054feb1..1776057 100644 --- a/generated/4.0.2/jammy/Dockerfile +++ b/generated/4.0.2/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.2/noble/Dockerfile b/generated/4.0.2/noble/Dockerfile index ff8914e..d8d2cdf 100644 --- a/generated/4.0.2/noble/Dockerfile +++ b/generated/4.0.2/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.2/trixie/Dockerfile b/generated/4.0.2/trixie/Dockerfile index 877ca13..bac207b 100644 --- a/generated/4.0.2/trixie/Dockerfile +++ b/generated/4.0.2/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.3/bookworm/Dockerfile b/generated/4.0.3/bookworm/Dockerfile index 4884ae3..bbe3c5a 100644 --- a/generated/4.0.3/bookworm/Dockerfile +++ b/generated/4.0.3/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.3/bullseye/Dockerfile b/generated/4.0.3/bullseye/Dockerfile index 03484db..4a02782 100644 --- a/generated/4.0.3/bullseye/Dockerfile +++ b/generated/4.0.3/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.3/jammy/Dockerfile b/generated/4.0.3/jammy/Dockerfile index 6d8cae3..ac27afa 100644 --- a/generated/4.0.3/jammy/Dockerfile +++ b/generated/4.0.3/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.3/noble/Dockerfile b/generated/4.0.3/noble/Dockerfile index 6e9e7b8..7b036c1 100644 --- a/generated/4.0.3/noble/Dockerfile +++ b/generated/4.0.3/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.3/trixie/Dockerfile b/generated/4.0.3/trixie/Dockerfile index 3d03792..ffef6ea 100644 --- a/generated/4.0.3/trixie/Dockerfile +++ b/generated/4.0.3/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.4/bookworm/Dockerfile b/generated/4.0.4/bookworm/Dockerfile index 9a355b5..7aaa144 100644 --- a/generated/4.0.4/bookworm/Dockerfile +++ b/generated/4.0.4/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.4/bullseye/Dockerfile b/generated/4.0.4/bullseye/Dockerfile index 84ca99f..d3efd84 100644 --- a/generated/4.0.4/bullseye/Dockerfile +++ b/generated/4.0.4/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.4/jammy/Dockerfile b/generated/4.0.4/jammy/Dockerfile index f0c5992..56068af 100644 --- a/generated/4.0.4/jammy/Dockerfile +++ b/generated/4.0.4/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.4/noble/Dockerfile b/generated/4.0.4/noble/Dockerfile index 51ef49f..5614d29 100644 --- a/generated/4.0.4/noble/Dockerfile +++ b/generated/4.0.4/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.4/trixie/Dockerfile b/generated/4.0.4/trixie/Dockerfile index 2906a6e..69e683f 100644 --- a/generated/4.0.4/trixie/Dockerfile +++ b/generated/4.0.4/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.5/bookworm/Dockerfile b/generated/4.0.5/bookworm/Dockerfile index e9b450f..d301eae 100644 --- a/generated/4.0.5/bookworm/Dockerfile +++ b/generated/4.0.5/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.5/bullseye/Dockerfile b/generated/4.0.5/bullseye/Dockerfile index fa82a48..60f3d51 100644 --- a/generated/4.0.5/bullseye/Dockerfile +++ b/generated/4.0.5/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.5/jammy/Dockerfile b/generated/4.0.5/jammy/Dockerfile index ef6f30d..3b955e9 100644 --- a/generated/4.0.5/jammy/Dockerfile +++ b/generated/4.0.5/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.5/noble/Dockerfile b/generated/4.0.5/noble/Dockerfile index 35e9467..6c11f6c 100644 --- a/generated/4.0.5/noble/Dockerfile +++ b/generated/4.0.5/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.5/trixie/Dockerfile b/generated/4.0.5/trixie/Dockerfile index 105e14e..1ea1c0a 100644 --- a/generated/4.0.5/trixie/Dockerfile +++ b/generated/4.0.5/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.6/bookworm/Dockerfile b/generated/4.0.6/bookworm/Dockerfile index f64e601..30e81f8 100644 --- a/generated/4.0.6/bookworm/Dockerfile +++ b/generated/4.0.6/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.6/bullseye/Dockerfile b/generated/4.0.6/bullseye/Dockerfile index 733b01b..ec9493b 100644 --- a/generated/4.0.6/bullseye/Dockerfile +++ b/generated/4.0.6/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.6/jammy/Dockerfile b/generated/4.0.6/jammy/Dockerfile index 2e507c4..63ef5e0 100644 --- a/generated/4.0.6/jammy/Dockerfile +++ b/generated/4.0.6/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.6/noble/Dockerfile b/generated/4.0.6/noble/Dockerfile index 7469096..a332a8a 100644 --- a/generated/4.0.6/noble/Dockerfile +++ b/generated/4.0.6/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.6/trixie/Dockerfile b/generated/4.0.6/trixie/Dockerfile index cb094ff..0d299b6 100644 --- a/generated/4.0.6/trixie/Dockerfile +++ b/generated/4.0.6/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.7/bookworm/Dockerfile b/generated/4.0.7/bookworm/Dockerfile index cb02b6e..eb35210 100644 --- a/generated/4.0.7/bookworm/Dockerfile +++ b/generated/4.0.7/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.7/bullseye/Dockerfile b/generated/4.0.7/bullseye/Dockerfile index d490cad..c716300 100644 --- a/generated/4.0.7/bullseye/Dockerfile +++ b/generated/4.0.7/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.7/jammy/Dockerfile b/generated/4.0.7/jammy/Dockerfile index 914f687..d29f1d6 100644 --- a/generated/4.0.7/jammy/Dockerfile +++ b/generated/4.0.7/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.7/noble/Dockerfile b/generated/4.0.7/noble/Dockerfile index b3a5c6b..e5a339b 100644 --- a/generated/4.0.7/noble/Dockerfile +++ b/generated/4.0.7/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -68,54 +102,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/4.0.7/trixie/Dockerfile b/generated/4.0.7/trixie/Dockerfile index 2d006c0..b387eb7 100644 --- a/generated/4.0.7/trixie/Dockerfile +++ b/generated/4.0.7/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.0/bookworm/Dockerfile b/generated/5.0.0/bookworm/Dockerfile index 785100b..6b9333c 100644 --- a/generated/5.0.0/bookworm/Dockerfile +++ b/generated/5.0.0/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.0/bullseye/Dockerfile b/generated/5.0.0/bullseye/Dockerfile index a9fcc69..e134999 100644 --- a/generated/5.0.0/bullseye/Dockerfile +++ b/generated/5.0.0/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.0/jammy/Dockerfile b/generated/5.0.0/jammy/Dockerfile index 0266f19..97969b8 100644 --- a/generated/5.0.0/jammy/Dockerfile +++ b/generated/5.0.0/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.0/noble/Dockerfile b/generated/5.0.0/noble/Dockerfile index f541232..733e00a 100644 --- a/generated/5.0.0/noble/Dockerfile +++ b/generated/5.0.0/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.0/trixie/Dockerfile b/generated/5.0.0/trixie/Dockerfile index 1a0f1ca..2cd1e42 100644 --- a/generated/5.0.0/trixie/Dockerfile +++ b/generated/5.0.0/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.1/bookworm/Dockerfile b/generated/5.0.1/bookworm/Dockerfile index f12214e..16bb84b 100644 --- a/generated/5.0.1/bookworm/Dockerfile +++ b/generated/5.0.1/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.1/bullseye/Dockerfile b/generated/5.0.1/bullseye/Dockerfile index 9eb494c..25f0a2d 100644 --- a/generated/5.0.1/bullseye/Dockerfile +++ b/generated/5.0.1/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.1/jammy/Dockerfile b/generated/5.0.1/jammy/Dockerfile index b232966..8fc837f 100644 --- a/generated/5.0.1/jammy/Dockerfile +++ b/generated/5.0.1/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.1/noble/Dockerfile b/generated/5.0.1/noble/Dockerfile index 712a51f..5b544d1 100644 --- a/generated/5.0.1/noble/Dockerfile +++ b/generated/5.0.1/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.1/trixie/Dockerfile b/generated/5.0.1/trixie/Dockerfile index f470973..92f7a29 100644 --- a/generated/5.0.1/trixie/Dockerfile +++ b/generated/5.0.1/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.2/bookworm/Dockerfile b/generated/5.0.2/bookworm/Dockerfile index 6fb9081..556c8eb 100644 --- a/generated/5.0.2/bookworm/Dockerfile +++ b/generated/5.0.2/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.2/bullseye/Dockerfile b/generated/5.0.2/bullseye/Dockerfile index 0de59be..4e42dae 100644 --- a/generated/5.0.2/bullseye/Dockerfile +++ b/generated/5.0.2/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.2/jammy/Dockerfile b/generated/5.0.2/jammy/Dockerfile index 14c6815..0e10378 100644 --- a/generated/5.0.2/jammy/Dockerfile +++ b/generated/5.0.2/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.2/noble/Dockerfile b/generated/5.0.2/noble/Dockerfile index dacf5b6..866e0f0 100644 --- a/generated/5.0.2/noble/Dockerfile +++ b/generated/5.0.2/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.2/trixie/Dockerfile b/generated/5.0.2/trixie/Dockerfile index 4b17087..21a2b1b 100644 --- a/generated/5.0.2/trixie/Dockerfile +++ b/generated/5.0.2/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.3/bookworm/Dockerfile b/generated/5.0.3/bookworm/Dockerfile index cba1ef7..80e6cb1 100644 --- a/generated/5.0.3/bookworm/Dockerfile +++ b/generated/5.0.3/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.3/bullseye/Dockerfile b/generated/5.0.3/bullseye/Dockerfile index c397c41..b2cdcd5 100644 --- a/generated/5.0.3/bullseye/Dockerfile +++ b/generated/5.0.3/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.3/jammy/Dockerfile b/generated/5.0.3/jammy/Dockerfile index 52eed8d..7cefae7 100644 --- a/generated/5.0.3/jammy/Dockerfile +++ b/generated/5.0.3/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.3/noble/Dockerfile b/generated/5.0.3/noble/Dockerfile index f47b26d..65d4190 100644 --- a/generated/5.0.3/noble/Dockerfile +++ b/generated/5.0.3/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.3/trixie/Dockerfile b/generated/5.0.3/trixie/Dockerfile index 0df8a3a..19e48f8 100644 --- a/generated/5.0.3/trixie/Dockerfile +++ b/generated/5.0.3/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.4/bookworm/Dockerfile b/generated/5.0.4/bookworm/Dockerfile index 1c9b378..f65f6ac 100644 --- a/generated/5.0.4/bookworm/Dockerfile +++ b/generated/5.0.4/bookworm/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.4/bullseye/Dockerfile b/generated/5.0.4/bullseye/Dockerfile index 3e63ebe..eb96e46 100644 --- a/generated/5.0.4/bullseye/Dockerfile +++ b/generated/5.0.4/bullseye/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.4/jammy/Dockerfile b/generated/5.0.4/jammy/Dockerfile index bb11a63..0afa542 100644 --- a/generated/5.0.4/jammy/Dockerfile +++ b/generated/5.0.4/jammy/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.4/noble/Dockerfile b/generated/5.0.4/noble/Dockerfile index fa12063..e2d1b08 100644 --- a/generated/5.0.4/noble/Dockerfile +++ b/generated/5.0.4/noble/Dockerfile @@ -35,6 +35,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -72,54 +106,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/generated/5.0.4/trixie/Dockerfile b/generated/5.0.4/trixie/Dockerfile index 2d6ae21..70398bc 100644 --- a/generated/5.0.4/trixie/Dockerfile +++ b/generated/5.0.4/trixie/Dockerfile @@ -34,6 +34,40 @@ RUN set -eux; \ ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -71,54 +105,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/src/Dockerfile.template b/src/Dockerfile.template index f1764a5..1c77ab0 100644 --- a/src/Dockerfile.template +++ b/src/Dockerfile.template @@ -30,6 +30,40 @@ RUN set -eux; \ {{EXTRA_PACKAGES}} ca-certificates \ curl; \ \ + # FB 3.0 only: provide libtommath.so.0 and libncurses5/libtinfo5 BEFORE running the installer. + # The installer sets the SYSDBA password with 'gsec', which cannot start without them. + # See DECISIONS.md D-019 and https://github.com/FirebirdSQL/firebird-docker/issues/47 + if [ "$FIREBIRD_MAJOR" = "3" ]; then \ + # Fix libtommath -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 + MULTIARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ + ln -sf /usr/lib/$MULTIARCH/libtommath.so.1 /usr/lib/$MULTIARCH/libtommath.so.0; \ + \ + # libncurses5/libtinfo5 were dropped from apt on Debian Trixie and Ubuntu Noble; pull them from the previous release pool. + # See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 + . /etc/os-release; \ + case "$ID-$VERSION_CODENAME" in \ + debian-bookworm|debian-bullseye|ubuntu-jammy) \ + apt-get install -y --no-install-recommends libtinfo5 libncurses5 \ + ;; \ + debian-trixie) \ + curl -fSL -o /tmp/libtinfo5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + ubuntu-noble) \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ + rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ + ;; \ + *) \ + echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ + exit 1 \ + ;; \ + esac; \ + fi; \ + \ # Download ARCH=$(dpkg --print-architecture); \ case "$ARCH" in \ @@ -67,54 +101,6 @@ RUN set -eux; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* -# Fix libtommath for FB 3.0 -- https://github.com/FirebirdSQL/firebird/issues/5716#issuecomment-826239174 -RUN set -eux; \ - ARCH=$(dpkg-architecture -qDEB_HOST_MULTIARCH 2>/dev/null || echo "$(uname -m)-linux-gnu"); \ - [ $FIREBIRD_MAJOR -eq 3 ] && ln -sf /usr/lib/$ARCH/libtommath.so.1 /usr/lib/$ARCH/libtommath.so.0 || true - -# FB 3.0 needs libncurses5/libtinfo5. On Debian Trixie and Ubuntu Noble those -# packages were dropped from apt; pull them from the previous release pool. -# See DECISIONS.md D-017 and https://github.com/FirebirdSQL/firebird-docker/issues/42 -RUN set -eux; \ - if [ "$FIREBIRD_MAJOR" = "3" ]; then \ - . /etc/os-release; \ - case "$ID-$VERSION_CODENAME" in \ - debian-bookworm|debian-bullseye|ubuntu-jammy) \ - apt-get update; \ - apt-get install -y --no-install-recommends libtinfo5 libncurses5; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - debian-trixie) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo5_6.4-4_amd64.deb; \ - curl -fSL -O http://deb.debian.org/debian/pool/main/n/ncurses/libncurses5_6.4-4_amd64.deb; \ - dpkg -i libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - rm -f libtinfo5_6.4-4_amd64.deb libncurses5_6.4-4_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - ubuntu-noble) \ - apt-get update; \ - apt-get install -y --no-install-recommends ca-certificates curl; \ - cd /tmp; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -O http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - dpkg -i libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - rm -f libtinfo5_6.3-2ubuntu0.2_amd64.deb libncurses5_6.3-2ubuntu0.2_amd64.deb; \ - apt-get purge -y --auto-remove curl ca-certificates; \ - apt-get clean; \ - rm -rf /var/lib/apt/lists/* \ - ;; \ - *) \ - echo "FB3: no libncurses5 provisioning path for $ID-$VERSION_CODENAME" >&2; \ - exit 1 \ - ;; \ - esac; \ - fi - # System path ENV PATH=/opt/firebird/bin:$PATH diff --git a/src/image.tests.ps1 b/src/image.tests.ps1 index 3689c07..709a493 100644 --- a/src/image.tests.ps1 +++ b/src/image.tests.ps1 @@ -284,11 +284,42 @@ task FIREBIRD_USER_can_create_user { docker exec $cId test -f /opt/firebird/SYSDBA.password | ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected SYSDBA.password file to exist when a new user is created." + # SYSDBA password from SYSDBA.password file still works? + $sysdbaPassword = docker exec $cId awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p $sysdbaPassword inet:///var/lib/firebird/data/test.fdb | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected successful login with SYSDBA password from SYSDBA.password file when a new user is created." + docker logs $cId | Contains -Pattern "Creating user 'alice'" -ErrorMessage "Expected log message indicating creation of user 'alice'." } } +task SYSDBA_password_file_allows_remote_login { + # Stock container, no environment variables: the password generated by the Firebird installer must work. + # https://github.com/FirebirdSQL/firebird-docker/issues/47 + Use-Container -ScriptBlock { + param($cId) + + $sysdbaPassword = docker exec $cId awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password + assert $sysdbaPassword "Expected SYSDBA.password file to contain ISC_PASSWORD." + + # Correct password (creates the database through the server, which authenticates the user) + "CREATE DATABASE 'inet:///var/lib/firebird/data/test.fdb' USER 'SYSDBA' PASSWORD '$sysdbaPassword';" | + docker exec -i $cId isql -b -q | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected CREATE DATABASE over the network to succeed with SYSDBA password from SYSDBA.password file." + + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p $sysdbaPassword inet:///var/lib/firebird/data/test.fdb | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected successful login with SYSDBA password from SYSDBA.password file." + + # Incorrect password + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p tiger inet:///var/lib/firebird/data/test.fdb 2>&1 | + ExitCodeIs -ExpectedValue 1 -ErrorMessage "Expected failed login with incorrect SYSDBA password." + } +} + task FIREBIRD_ROOT_PASSWORD_can_change_sysdba_password { Use-Container -Parameters '-e', 'FIREBIRD_DATABASE=test.fdb', '-e', 'FIREBIRD_ROOT_PASSWORD=passw0rd' { param($cId) From 3d3ed634915838db0a02a22564d85309b460be22 Mon Sep 17 00:00:00 2001 From: "F.D.Castel" Date: Wed, 23 Sep 2026 15:01:33 +0000 Subject: [PATCH 2/4] fix(fb3): bump libncurses5/libtinfo5 pin for Noble to 6.3-2ubuntu0.3 archive.ubuntu.com superseded 6.3-2ubuntu0.2 and the old .deb now returns 404, breaking the Firebird 3 Noble build. --- generated/3.0.10/bookworm/Dockerfile | 4 ++-- generated/3.0.10/bullseye/Dockerfile | 4 ++-- generated/3.0.10/jammy/Dockerfile | 4 ++-- generated/3.0.10/noble/Dockerfile | 4 ++-- generated/3.0.10/trixie/Dockerfile | 4 ++-- generated/3.0.11/bookworm/Dockerfile | 4 ++-- generated/3.0.11/bullseye/Dockerfile | 4 ++-- generated/3.0.11/jammy/Dockerfile | 4 ++-- generated/3.0.11/noble/Dockerfile | 4 ++-- generated/3.0.11/trixie/Dockerfile | 4 ++-- generated/3.0.12/bookworm/Dockerfile | 4 ++-- generated/3.0.12/bullseye/Dockerfile | 4 ++-- generated/3.0.12/jammy/Dockerfile | 4 ++-- generated/3.0.12/noble/Dockerfile | 4 ++-- generated/3.0.12/trixie/Dockerfile | 4 ++-- generated/3.0.13/bookworm/Dockerfile | 4 ++-- generated/3.0.13/bullseye/Dockerfile | 4 ++-- generated/3.0.13/jammy/Dockerfile | 4 ++-- generated/3.0.13/noble/Dockerfile | 4 ++-- generated/3.0.13/trixie/Dockerfile | 4 ++-- generated/3.0.14/bookworm/Dockerfile | 4 ++-- generated/3.0.14/bullseye/Dockerfile | 4 ++-- generated/3.0.14/jammy/Dockerfile | 4 ++-- generated/3.0.14/noble/Dockerfile | 4 ++-- generated/3.0.14/trixie/Dockerfile | 4 ++-- generated/3.0.9/bookworm/Dockerfile | 4 ++-- generated/3.0.9/bullseye/Dockerfile | 4 ++-- generated/3.0.9/jammy/Dockerfile | 4 ++-- generated/3.0.9/noble/Dockerfile | 4 ++-- generated/3.0.9/trixie/Dockerfile | 4 ++-- generated/4.0.0/bookworm/Dockerfile | 4 ++-- generated/4.0.0/bullseye/Dockerfile | 4 ++-- generated/4.0.0/jammy/Dockerfile | 4 ++-- generated/4.0.0/noble/Dockerfile | 4 ++-- generated/4.0.0/trixie/Dockerfile | 4 ++-- generated/4.0.1/bookworm/Dockerfile | 4 ++-- generated/4.0.1/bullseye/Dockerfile | 4 ++-- generated/4.0.1/jammy/Dockerfile | 4 ++-- generated/4.0.1/noble/Dockerfile | 4 ++-- generated/4.0.1/trixie/Dockerfile | 4 ++-- generated/4.0.2/bookworm/Dockerfile | 4 ++-- generated/4.0.2/bullseye/Dockerfile | 4 ++-- generated/4.0.2/jammy/Dockerfile | 4 ++-- generated/4.0.2/noble/Dockerfile | 4 ++-- generated/4.0.2/trixie/Dockerfile | 4 ++-- generated/4.0.3/bookworm/Dockerfile | 4 ++-- generated/4.0.3/bullseye/Dockerfile | 4 ++-- generated/4.0.3/jammy/Dockerfile | 4 ++-- generated/4.0.3/noble/Dockerfile | 4 ++-- generated/4.0.3/trixie/Dockerfile | 4 ++-- generated/4.0.4/bookworm/Dockerfile | 4 ++-- generated/4.0.4/bullseye/Dockerfile | 4 ++-- generated/4.0.4/jammy/Dockerfile | 4 ++-- generated/4.0.4/noble/Dockerfile | 4 ++-- generated/4.0.4/trixie/Dockerfile | 4 ++-- generated/4.0.5/bookworm/Dockerfile | 4 ++-- generated/4.0.5/bullseye/Dockerfile | 4 ++-- generated/4.0.5/jammy/Dockerfile | 4 ++-- generated/4.0.5/noble/Dockerfile | 4 ++-- generated/4.0.5/trixie/Dockerfile | 4 ++-- generated/4.0.6/bookworm/Dockerfile | 4 ++-- generated/4.0.6/bullseye/Dockerfile | 4 ++-- generated/4.0.6/jammy/Dockerfile | 4 ++-- generated/4.0.6/noble/Dockerfile | 4 ++-- generated/4.0.6/trixie/Dockerfile | 4 ++-- generated/4.0.7/bookworm/Dockerfile | 4 ++-- generated/4.0.7/bullseye/Dockerfile | 4 ++-- generated/4.0.7/jammy/Dockerfile | 4 ++-- generated/4.0.7/noble/Dockerfile | 4 ++-- generated/4.0.7/trixie/Dockerfile | 4 ++-- generated/5.0.0/bookworm/Dockerfile | 4 ++-- generated/5.0.0/bullseye/Dockerfile | 4 ++-- generated/5.0.0/jammy/Dockerfile | 4 ++-- generated/5.0.0/noble/Dockerfile | 4 ++-- generated/5.0.0/trixie/Dockerfile | 4 ++-- generated/5.0.1/bookworm/Dockerfile | 4 ++-- generated/5.0.1/bullseye/Dockerfile | 4 ++-- generated/5.0.1/jammy/Dockerfile | 4 ++-- generated/5.0.1/noble/Dockerfile | 4 ++-- generated/5.0.1/trixie/Dockerfile | 4 ++-- generated/5.0.2/bookworm/Dockerfile | 4 ++-- generated/5.0.2/bullseye/Dockerfile | 4 ++-- generated/5.0.2/jammy/Dockerfile | 4 ++-- generated/5.0.2/noble/Dockerfile | 4 ++-- generated/5.0.2/trixie/Dockerfile | 4 ++-- generated/5.0.3/bookworm/Dockerfile | 4 ++-- generated/5.0.3/bullseye/Dockerfile | 4 ++-- generated/5.0.3/jammy/Dockerfile | 4 ++-- generated/5.0.3/noble/Dockerfile | 4 ++-- generated/5.0.3/trixie/Dockerfile | 4 ++-- generated/5.0.4/bookworm/Dockerfile | 4 ++-- generated/5.0.4/bullseye/Dockerfile | 4 ++-- generated/5.0.4/jammy/Dockerfile | 4 ++-- generated/5.0.4/noble/Dockerfile | 4 ++-- generated/5.0.4/trixie/Dockerfile | 4 ++-- src/Dockerfile.template | 4 ++-- 96 files changed, 192 insertions(+), 192 deletions(-) diff --git a/generated/3.0.10/bookworm/Dockerfile b/generated/3.0.10/bookworm/Dockerfile index 5df1048..fa88aa4 100644 --- a/generated/3.0.10/bookworm/Dockerfile +++ b/generated/3.0.10/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.10/bullseye/Dockerfile b/generated/3.0.10/bullseye/Dockerfile index df267bf..9228d35 100644 --- a/generated/3.0.10/bullseye/Dockerfile +++ b/generated/3.0.10/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.10/jammy/Dockerfile b/generated/3.0.10/jammy/Dockerfile index e269427..01d4774 100644 --- a/generated/3.0.10/jammy/Dockerfile +++ b/generated/3.0.10/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.10/noble/Dockerfile b/generated/3.0.10/noble/Dockerfile index de260fe..956b545 100644 --- a/generated/3.0.10/noble/Dockerfile +++ b/generated/3.0.10/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.10/trixie/Dockerfile b/generated/3.0.10/trixie/Dockerfile index e7af19f..d1d9fec 100644 --- a/generated/3.0.10/trixie/Dockerfile +++ b/generated/3.0.10/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.11/bookworm/Dockerfile b/generated/3.0.11/bookworm/Dockerfile index adaefe1..4904288 100644 --- a/generated/3.0.11/bookworm/Dockerfile +++ b/generated/3.0.11/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.11/bullseye/Dockerfile b/generated/3.0.11/bullseye/Dockerfile index f2bb148..787dd84 100644 --- a/generated/3.0.11/bullseye/Dockerfile +++ b/generated/3.0.11/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.11/jammy/Dockerfile b/generated/3.0.11/jammy/Dockerfile index 26bbf47..f07c2d9 100644 --- a/generated/3.0.11/jammy/Dockerfile +++ b/generated/3.0.11/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.11/noble/Dockerfile b/generated/3.0.11/noble/Dockerfile index 5a538f7..b189edf 100644 --- a/generated/3.0.11/noble/Dockerfile +++ b/generated/3.0.11/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.11/trixie/Dockerfile b/generated/3.0.11/trixie/Dockerfile index 3d5bd41..fb8ad84 100644 --- a/generated/3.0.11/trixie/Dockerfile +++ b/generated/3.0.11/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.12/bookworm/Dockerfile b/generated/3.0.12/bookworm/Dockerfile index cc97d5b..1b31557 100644 --- a/generated/3.0.12/bookworm/Dockerfile +++ b/generated/3.0.12/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.12/bullseye/Dockerfile b/generated/3.0.12/bullseye/Dockerfile index a95f7cd..b57adf7 100644 --- a/generated/3.0.12/bullseye/Dockerfile +++ b/generated/3.0.12/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.12/jammy/Dockerfile b/generated/3.0.12/jammy/Dockerfile index 27c89da..f4306ed 100644 --- a/generated/3.0.12/jammy/Dockerfile +++ b/generated/3.0.12/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.12/noble/Dockerfile b/generated/3.0.12/noble/Dockerfile index 9c57e62..ce4de96 100644 --- a/generated/3.0.12/noble/Dockerfile +++ b/generated/3.0.12/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.12/trixie/Dockerfile b/generated/3.0.12/trixie/Dockerfile index 32937d7..1059a19 100644 --- a/generated/3.0.12/trixie/Dockerfile +++ b/generated/3.0.12/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.13/bookworm/Dockerfile b/generated/3.0.13/bookworm/Dockerfile index 95ed430..921784c 100644 --- a/generated/3.0.13/bookworm/Dockerfile +++ b/generated/3.0.13/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.13/bullseye/Dockerfile b/generated/3.0.13/bullseye/Dockerfile index a7c3078..8564200 100644 --- a/generated/3.0.13/bullseye/Dockerfile +++ b/generated/3.0.13/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.13/jammy/Dockerfile b/generated/3.0.13/jammy/Dockerfile index 6f9279a..b6dcad5 100644 --- a/generated/3.0.13/jammy/Dockerfile +++ b/generated/3.0.13/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.13/noble/Dockerfile b/generated/3.0.13/noble/Dockerfile index 4688faa..98756f6 100644 --- a/generated/3.0.13/noble/Dockerfile +++ b/generated/3.0.13/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.13/trixie/Dockerfile b/generated/3.0.13/trixie/Dockerfile index c34b95a..e995583 100644 --- a/generated/3.0.13/trixie/Dockerfile +++ b/generated/3.0.13/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.14/bookworm/Dockerfile b/generated/3.0.14/bookworm/Dockerfile index a14a675..9241c5b 100644 --- a/generated/3.0.14/bookworm/Dockerfile +++ b/generated/3.0.14/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.14/bullseye/Dockerfile b/generated/3.0.14/bullseye/Dockerfile index bc74c8f..3d923ac 100644 --- a/generated/3.0.14/bullseye/Dockerfile +++ b/generated/3.0.14/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.14/jammy/Dockerfile b/generated/3.0.14/jammy/Dockerfile index 591ee90..ec5f14f 100644 --- a/generated/3.0.14/jammy/Dockerfile +++ b/generated/3.0.14/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.14/noble/Dockerfile b/generated/3.0.14/noble/Dockerfile index 2da6264..6cd728a 100644 --- a/generated/3.0.14/noble/Dockerfile +++ b/generated/3.0.14/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.14/trixie/Dockerfile b/generated/3.0.14/trixie/Dockerfile index c86d032..83e532c 100644 --- a/generated/3.0.14/trixie/Dockerfile +++ b/generated/3.0.14/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.9/bookworm/Dockerfile b/generated/3.0.9/bookworm/Dockerfile index 0621dda..2d52fbd 100644 --- a/generated/3.0.9/bookworm/Dockerfile +++ b/generated/3.0.9/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.9/bullseye/Dockerfile b/generated/3.0.9/bullseye/Dockerfile index a840b7c..ef2ca1e 100644 --- a/generated/3.0.9/bullseye/Dockerfile +++ b/generated/3.0.9/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.9/jammy/Dockerfile b/generated/3.0.9/jammy/Dockerfile index 48a740a..8c44d8f 100644 --- a/generated/3.0.9/jammy/Dockerfile +++ b/generated/3.0.9/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.9/noble/Dockerfile b/generated/3.0.9/noble/Dockerfile index 5001f9f..8177c6b 100644 --- a/generated/3.0.9/noble/Dockerfile +++ b/generated/3.0.9/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/3.0.9/trixie/Dockerfile b/generated/3.0.9/trixie/Dockerfile index 95f68ed..374d8ca 100644 --- a/generated/3.0.9/trixie/Dockerfile +++ b/generated/3.0.9/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.0/bookworm/Dockerfile b/generated/4.0.0/bookworm/Dockerfile index 1ef9e7c..3c15f8d 100644 --- a/generated/4.0.0/bookworm/Dockerfile +++ b/generated/4.0.0/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.0/bullseye/Dockerfile b/generated/4.0.0/bullseye/Dockerfile index a7c8291..b34ef4b 100644 --- a/generated/4.0.0/bullseye/Dockerfile +++ b/generated/4.0.0/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.0/jammy/Dockerfile b/generated/4.0.0/jammy/Dockerfile index 548d71f..3f6fb51 100644 --- a/generated/4.0.0/jammy/Dockerfile +++ b/generated/4.0.0/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.0/noble/Dockerfile b/generated/4.0.0/noble/Dockerfile index 0af0581..0135fcf 100644 --- a/generated/4.0.0/noble/Dockerfile +++ b/generated/4.0.0/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.0/trixie/Dockerfile b/generated/4.0.0/trixie/Dockerfile index ade1478..f4a3cd3 100644 --- a/generated/4.0.0/trixie/Dockerfile +++ b/generated/4.0.0/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.1/bookworm/Dockerfile b/generated/4.0.1/bookworm/Dockerfile index 5d2f367..2745250 100644 --- a/generated/4.0.1/bookworm/Dockerfile +++ b/generated/4.0.1/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.1/bullseye/Dockerfile b/generated/4.0.1/bullseye/Dockerfile index 7c1538a..6ae2bc7 100644 --- a/generated/4.0.1/bullseye/Dockerfile +++ b/generated/4.0.1/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.1/jammy/Dockerfile b/generated/4.0.1/jammy/Dockerfile index 5df9c7c..73dfbd0 100644 --- a/generated/4.0.1/jammy/Dockerfile +++ b/generated/4.0.1/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.1/noble/Dockerfile b/generated/4.0.1/noble/Dockerfile index 29460fe..1055c42 100644 --- a/generated/4.0.1/noble/Dockerfile +++ b/generated/4.0.1/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.1/trixie/Dockerfile b/generated/4.0.1/trixie/Dockerfile index 3cecc31..8780e9f 100644 --- a/generated/4.0.1/trixie/Dockerfile +++ b/generated/4.0.1/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.2/bookworm/Dockerfile b/generated/4.0.2/bookworm/Dockerfile index 33212ec..7d05f98 100644 --- a/generated/4.0.2/bookworm/Dockerfile +++ b/generated/4.0.2/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.2/bullseye/Dockerfile b/generated/4.0.2/bullseye/Dockerfile index bbf82e7..2d2cb47 100644 --- a/generated/4.0.2/bullseye/Dockerfile +++ b/generated/4.0.2/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.2/jammy/Dockerfile b/generated/4.0.2/jammy/Dockerfile index 1776057..e967f18 100644 --- a/generated/4.0.2/jammy/Dockerfile +++ b/generated/4.0.2/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.2/noble/Dockerfile b/generated/4.0.2/noble/Dockerfile index d8d2cdf..f7367e5 100644 --- a/generated/4.0.2/noble/Dockerfile +++ b/generated/4.0.2/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.2/trixie/Dockerfile b/generated/4.0.2/trixie/Dockerfile index bac207b..c0720b2 100644 --- a/generated/4.0.2/trixie/Dockerfile +++ b/generated/4.0.2/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.3/bookworm/Dockerfile b/generated/4.0.3/bookworm/Dockerfile index bbe3c5a..4c049d3 100644 --- a/generated/4.0.3/bookworm/Dockerfile +++ b/generated/4.0.3/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.3/bullseye/Dockerfile b/generated/4.0.3/bullseye/Dockerfile index 4a02782..cd671f7 100644 --- a/generated/4.0.3/bullseye/Dockerfile +++ b/generated/4.0.3/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.3/jammy/Dockerfile b/generated/4.0.3/jammy/Dockerfile index ac27afa..0b5443f 100644 --- a/generated/4.0.3/jammy/Dockerfile +++ b/generated/4.0.3/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.3/noble/Dockerfile b/generated/4.0.3/noble/Dockerfile index 7b036c1..c72b285 100644 --- a/generated/4.0.3/noble/Dockerfile +++ b/generated/4.0.3/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.3/trixie/Dockerfile b/generated/4.0.3/trixie/Dockerfile index ffef6ea..796ac22 100644 --- a/generated/4.0.3/trixie/Dockerfile +++ b/generated/4.0.3/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.4/bookworm/Dockerfile b/generated/4.0.4/bookworm/Dockerfile index 7aaa144..c5ec139 100644 --- a/generated/4.0.4/bookworm/Dockerfile +++ b/generated/4.0.4/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.4/bullseye/Dockerfile b/generated/4.0.4/bullseye/Dockerfile index d3efd84..7705202 100644 --- a/generated/4.0.4/bullseye/Dockerfile +++ b/generated/4.0.4/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.4/jammy/Dockerfile b/generated/4.0.4/jammy/Dockerfile index 56068af..29bec27 100644 --- a/generated/4.0.4/jammy/Dockerfile +++ b/generated/4.0.4/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.4/noble/Dockerfile b/generated/4.0.4/noble/Dockerfile index 5614d29..918eb07 100644 --- a/generated/4.0.4/noble/Dockerfile +++ b/generated/4.0.4/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.4/trixie/Dockerfile b/generated/4.0.4/trixie/Dockerfile index 69e683f..e265c8d 100644 --- a/generated/4.0.4/trixie/Dockerfile +++ b/generated/4.0.4/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.5/bookworm/Dockerfile b/generated/4.0.5/bookworm/Dockerfile index d301eae..666b38c 100644 --- a/generated/4.0.5/bookworm/Dockerfile +++ b/generated/4.0.5/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.5/bullseye/Dockerfile b/generated/4.0.5/bullseye/Dockerfile index 60f3d51..b68d574 100644 --- a/generated/4.0.5/bullseye/Dockerfile +++ b/generated/4.0.5/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.5/jammy/Dockerfile b/generated/4.0.5/jammy/Dockerfile index 3b955e9..794432e 100644 --- a/generated/4.0.5/jammy/Dockerfile +++ b/generated/4.0.5/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.5/noble/Dockerfile b/generated/4.0.5/noble/Dockerfile index 6c11f6c..febfa47 100644 --- a/generated/4.0.5/noble/Dockerfile +++ b/generated/4.0.5/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.5/trixie/Dockerfile b/generated/4.0.5/trixie/Dockerfile index 1ea1c0a..69b2600 100644 --- a/generated/4.0.5/trixie/Dockerfile +++ b/generated/4.0.5/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.6/bookworm/Dockerfile b/generated/4.0.6/bookworm/Dockerfile index 30e81f8..1b1e8d1 100644 --- a/generated/4.0.6/bookworm/Dockerfile +++ b/generated/4.0.6/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.6/bullseye/Dockerfile b/generated/4.0.6/bullseye/Dockerfile index ec9493b..db05dc3 100644 --- a/generated/4.0.6/bullseye/Dockerfile +++ b/generated/4.0.6/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.6/jammy/Dockerfile b/generated/4.0.6/jammy/Dockerfile index 63ef5e0..a43dabd 100644 --- a/generated/4.0.6/jammy/Dockerfile +++ b/generated/4.0.6/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.6/noble/Dockerfile b/generated/4.0.6/noble/Dockerfile index a332a8a..b7c7c55 100644 --- a/generated/4.0.6/noble/Dockerfile +++ b/generated/4.0.6/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.6/trixie/Dockerfile b/generated/4.0.6/trixie/Dockerfile index 0d299b6..5673c8b 100644 --- a/generated/4.0.6/trixie/Dockerfile +++ b/generated/4.0.6/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.7/bookworm/Dockerfile b/generated/4.0.7/bookworm/Dockerfile index eb35210..550e030 100644 --- a/generated/4.0.7/bookworm/Dockerfile +++ b/generated/4.0.7/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.7/bullseye/Dockerfile b/generated/4.0.7/bullseye/Dockerfile index c716300..5e4fb0a 100644 --- a/generated/4.0.7/bullseye/Dockerfile +++ b/generated/4.0.7/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.7/jammy/Dockerfile b/generated/4.0.7/jammy/Dockerfile index d29f1d6..41a499a 100644 --- a/generated/4.0.7/jammy/Dockerfile +++ b/generated/4.0.7/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.7/noble/Dockerfile b/generated/4.0.7/noble/Dockerfile index e5a339b..98bf804 100644 --- a/generated/4.0.7/noble/Dockerfile +++ b/generated/4.0.7/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/4.0.7/trixie/Dockerfile b/generated/4.0.7/trixie/Dockerfile index b387eb7..f7747c7 100644 --- a/generated/4.0.7/trixie/Dockerfile +++ b/generated/4.0.7/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.0/bookworm/Dockerfile b/generated/5.0.0/bookworm/Dockerfile index 6b9333c..4b93170 100644 --- a/generated/5.0.0/bookworm/Dockerfile +++ b/generated/5.0.0/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.0/bullseye/Dockerfile b/generated/5.0.0/bullseye/Dockerfile index e134999..dfc17c4 100644 --- a/generated/5.0.0/bullseye/Dockerfile +++ b/generated/5.0.0/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.0/jammy/Dockerfile b/generated/5.0.0/jammy/Dockerfile index 97969b8..0b214e5 100644 --- a/generated/5.0.0/jammy/Dockerfile +++ b/generated/5.0.0/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.0/noble/Dockerfile b/generated/5.0.0/noble/Dockerfile index 733e00a..88c1a7b 100644 --- a/generated/5.0.0/noble/Dockerfile +++ b/generated/5.0.0/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.0/trixie/Dockerfile b/generated/5.0.0/trixie/Dockerfile index 2cd1e42..4a4ddd8 100644 --- a/generated/5.0.0/trixie/Dockerfile +++ b/generated/5.0.0/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.1/bookworm/Dockerfile b/generated/5.0.1/bookworm/Dockerfile index 16bb84b..8273db9 100644 --- a/generated/5.0.1/bookworm/Dockerfile +++ b/generated/5.0.1/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.1/bullseye/Dockerfile b/generated/5.0.1/bullseye/Dockerfile index 25f0a2d..f727565 100644 --- a/generated/5.0.1/bullseye/Dockerfile +++ b/generated/5.0.1/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.1/jammy/Dockerfile b/generated/5.0.1/jammy/Dockerfile index 8fc837f..a753018 100644 --- a/generated/5.0.1/jammy/Dockerfile +++ b/generated/5.0.1/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.1/noble/Dockerfile b/generated/5.0.1/noble/Dockerfile index 5b544d1..cae9820 100644 --- a/generated/5.0.1/noble/Dockerfile +++ b/generated/5.0.1/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.1/trixie/Dockerfile b/generated/5.0.1/trixie/Dockerfile index 92f7a29..0f35e70 100644 --- a/generated/5.0.1/trixie/Dockerfile +++ b/generated/5.0.1/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.2/bookworm/Dockerfile b/generated/5.0.2/bookworm/Dockerfile index 556c8eb..1f77c73 100644 --- a/generated/5.0.2/bookworm/Dockerfile +++ b/generated/5.0.2/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.2/bullseye/Dockerfile b/generated/5.0.2/bullseye/Dockerfile index 4e42dae..0cbbb1c 100644 --- a/generated/5.0.2/bullseye/Dockerfile +++ b/generated/5.0.2/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.2/jammy/Dockerfile b/generated/5.0.2/jammy/Dockerfile index 0e10378..ad8ddca 100644 --- a/generated/5.0.2/jammy/Dockerfile +++ b/generated/5.0.2/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.2/noble/Dockerfile b/generated/5.0.2/noble/Dockerfile index 866e0f0..8c5576d 100644 --- a/generated/5.0.2/noble/Dockerfile +++ b/generated/5.0.2/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.2/trixie/Dockerfile b/generated/5.0.2/trixie/Dockerfile index 21a2b1b..b68cff8 100644 --- a/generated/5.0.2/trixie/Dockerfile +++ b/generated/5.0.2/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.3/bookworm/Dockerfile b/generated/5.0.3/bookworm/Dockerfile index 80e6cb1..c84b9f3 100644 --- a/generated/5.0.3/bookworm/Dockerfile +++ b/generated/5.0.3/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.3/bullseye/Dockerfile b/generated/5.0.3/bullseye/Dockerfile index b2cdcd5..b5f887c 100644 --- a/generated/5.0.3/bullseye/Dockerfile +++ b/generated/5.0.3/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.3/jammy/Dockerfile b/generated/5.0.3/jammy/Dockerfile index 7cefae7..c98b86b 100644 --- a/generated/5.0.3/jammy/Dockerfile +++ b/generated/5.0.3/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.3/noble/Dockerfile b/generated/5.0.3/noble/Dockerfile index 65d4190..ee209a9 100644 --- a/generated/5.0.3/noble/Dockerfile +++ b/generated/5.0.3/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.3/trixie/Dockerfile b/generated/5.0.3/trixie/Dockerfile index 19e48f8..a21ce26 100644 --- a/generated/5.0.3/trixie/Dockerfile +++ b/generated/5.0.3/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.4/bookworm/Dockerfile b/generated/5.0.4/bookworm/Dockerfile index f65f6ac..e66d400 100644 --- a/generated/5.0.4/bookworm/Dockerfile +++ b/generated/5.0.4/bookworm/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.4/bullseye/Dockerfile b/generated/5.0.4/bullseye/Dockerfile index eb96e46..01b2519 100644 --- a/generated/5.0.4/bullseye/Dockerfile +++ b/generated/5.0.4/bullseye/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.4/jammy/Dockerfile b/generated/5.0.4/jammy/Dockerfile index 0afa542..b8b2998 100644 --- a/generated/5.0.4/jammy/Dockerfile +++ b/generated/5.0.4/jammy/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.4/noble/Dockerfile b/generated/5.0.4/noble/Dockerfile index e2d1b08..cc61e88 100644 --- a/generated/5.0.4/noble/Dockerfile +++ b/generated/5.0.4/noble/Dockerfile @@ -57,8 +57,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/generated/5.0.4/trixie/Dockerfile b/generated/5.0.4/trixie/Dockerfile index 70398bc..d1a642a 100644 --- a/generated/5.0.4/trixie/Dockerfile +++ b/generated/5.0.4/trixie/Dockerfile @@ -56,8 +56,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ diff --git a/src/Dockerfile.template b/src/Dockerfile.template index 1c77ab0..81f7445 100644 --- a/src/Dockerfile.template +++ b/src/Dockerfile.template @@ -52,8 +52,8 @@ RUN set -eux; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ ubuntu-noble) \ - curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.2_amd64.deb; \ - curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.2_amd64.deb; \ + curl -fSL -o /tmp/libtinfo5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libtinfo5_6.3-2ubuntu0.3_amd64.deb; \ + curl -fSL -o /tmp/libncurses5.deb http://archive.ubuntu.com/ubuntu/pool/universe/n/ncurses/libncurses5_6.3-2ubuntu0.3_amd64.deb; \ dpkg -i /tmp/libtinfo5.deb /tmp/libncurses5.deb; \ rm -f /tmp/libtinfo5.deb /tmp/libncurses5.deb \ ;; \ From 2a1e2560f7042a40b3408f23fb9b35a3e0dd7c71 Mon Sep 17 00:00:00 2001 From: "F.D.Castel" Date: Sat, 26 Sep 2026 21:04:31 +0000 Subject: [PATCH 3/4] fix(entrypoint): generate a random SYSDBA password on container first start (issue #48) When FIREBIRD_ROOT_PASSWORD is not set, the SYSDBA password was the one generated by the Firebird installer at image build time: the same for every container of an image, and readable by anyone who can pull it. The entrypoint now generates a random password, sets it (Srp, plus Legacy_UserManager with FIREBIRD_USE_LEGACY_AUTH=true) and rewrites /opt/firebird/SYSDBA.password. Only the file's path is logged, not the password. It does so only while the security database still matches the checksum recorded at build time, so restarts keep the password and a bind-mounted security database (issue #5) is never touched. See DECISIONS.md D-021. --- DECISIONS.md | 6 ++ README.md | 12 +++- generated/3.0.10/bookworm/Dockerfile | 4 ++ generated/3.0.10/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.10/bullseye/Dockerfile | 4 ++ generated/3.0.10/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.10/jammy/Dockerfile | 4 ++ generated/3.0.10/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.10/noble/Dockerfile | 4 ++ generated/3.0.10/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.10/trixie/Dockerfile | 4 ++ generated/3.0.10/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.11/bookworm/Dockerfile | 4 ++ generated/3.0.11/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.11/bullseye/Dockerfile | 4 ++ generated/3.0.11/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.11/jammy/Dockerfile | 4 ++ generated/3.0.11/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.11/noble/Dockerfile | 4 ++ generated/3.0.11/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.11/trixie/Dockerfile | 4 ++ generated/3.0.11/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.12/bookworm/Dockerfile | 4 ++ generated/3.0.12/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.12/bullseye/Dockerfile | 4 ++ generated/3.0.12/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.12/jammy/Dockerfile | 4 ++ generated/3.0.12/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.12/noble/Dockerfile | 4 ++ generated/3.0.12/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.12/trixie/Dockerfile | 4 ++ generated/3.0.12/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.13/bookworm/Dockerfile | 4 ++ generated/3.0.13/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.13/bullseye/Dockerfile | 4 ++ generated/3.0.13/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.13/jammy/Dockerfile | 4 ++ generated/3.0.13/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.13/noble/Dockerfile | 4 ++ generated/3.0.13/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.13/trixie/Dockerfile | 4 ++ generated/3.0.13/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.14/bookworm/Dockerfile | 4 ++ generated/3.0.14/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.14/bullseye/Dockerfile | 4 ++ generated/3.0.14/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.14/jammy/Dockerfile | 4 ++ generated/3.0.14/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.14/noble/Dockerfile | 4 ++ generated/3.0.14/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.14/trixie/Dockerfile | 4 ++ generated/3.0.14/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.9/bookworm/Dockerfile | 4 ++ generated/3.0.9/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.9/bullseye/Dockerfile | 4 ++ generated/3.0.9/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.9/jammy/Dockerfile | 4 ++ generated/3.0.9/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.9/noble/Dockerfile | 4 ++ generated/3.0.9/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/3.0.9/trixie/Dockerfile | 4 ++ generated/3.0.9/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.0/bookworm/Dockerfile | 4 ++ generated/4.0.0/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.0/bullseye/Dockerfile | 4 ++ generated/4.0.0/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.0/jammy/Dockerfile | 4 ++ generated/4.0.0/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.0/noble/Dockerfile | 4 ++ generated/4.0.0/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.0/trixie/Dockerfile | 4 ++ generated/4.0.0/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.1/bookworm/Dockerfile | 4 ++ generated/4.0.1/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.1/bullseye/Dockerfile | 4 ++ generated/4.0.1/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.1/jammy/Dockerfile | 4 ++ generated/4.0.1/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.1/noble/Dockerfile | 4 ++ generated/4.0.1/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.1/trixie/Dockerfile | 4 ++ generated/4.0.1/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.2/bookworm/Dockerfile | 4 ++ generated/4.0.2/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.2/bullseye/Dockerfile | 4 ++ generated/4.0.2/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.2/jammy/Dockerfile | 4 ++ generated/4.0.2/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.2/noble/Dockerfile | 4 ++ generated/4.0.2/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.2/trixie/Dockerfile | 4 ++ generated/4.0.2/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.3/bookworm/Dockerfile | 4 ++ generated/4.0.3/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.3/bullseye/Dockerfile | 4 ++ generated/4.0.3/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.3/jammy/Dockerfile | 4 ++ generated/4.0.3/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.3/noble/Dockerfile | 4 ++ generated/4.0.3/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.3/trixie/Dockerfile | 4 ++ generated/4.0.3/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.4/bookworm/Dockerfile | 4 ++ generated/4.0.4/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.4/bullseye/Dockerfile | 4 ++ generated/4.0.4/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.4/jammy/Dockerfile | 4 ++ generated/4.0.4/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.4/noble/Dockerfile | 4 ++ generated/4.0.4/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.4/trixie/Dockerfile | 4 ++ generated/4.0.4/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.5/bookworm/Dockerfile | 4 ++ generated/4.0.5/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.5/bullseye/Dockerfile | 4 ++ generated/4.0.5/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.5/jammy/Dockerfile | 4 ++ generated/4.0.5/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.5/noble/Dockerfile | 4 ++ generated/4.0.5/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.5/trixie/Dockerfile | 4 ++ generated/4.0.5/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.6/bookworm/Dockerfile | 4 ++ generated/4.0.6/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.6/bullseye/Dockerfile | 4 ++ generated/4.0.6/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.6/jammy/Dockerfile | 4 ++ generated/4.0.6/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.6/noble/Dockerfile | 4 ++ generated/4.0.6/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.6/trixie/Dockerfile | 4 ++ generated/4.0.6/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.7/bookworm/Dockerfile | 4 ++ generated/4.0.7/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.7/bullseye/Dockerfile | 4 ++ generated/4.0.7/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.7/jammy/Dockerfile | 4 ++ generated/4.0.7/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.7/noble/Dockerfile | 4 ++ generated/4.0.7/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/4.0.7/trixie/Dockerfile | 4 ++ generated/4.0.7/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.0/bookworm/Dockerfile | 4 ++ generated/5.0.0/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.0/bullseye/Dockerfile | 4 ++ generated/5.0.0/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.0/jammy/Dockerfile | 4 ++ generated/5.0.0/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.0/noble/Dockerfile | 4 ++ generated/5.0.0/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.0/trixie/Dockerfile | 4 ++ generated/5.0.0/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.1/bookworm/Dockerfile | 4 ++ generated/5.0.1/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.1/bullseye/Dockerfile | 4 ++ generated/5.0.1/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.1/jammy/Dockerfile | 4 ++ generated/5.0.1/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.1/noble/Dockerfile | 4 ++ generated/5.0.1/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.1/trixie/Dockerfile | 4 ++ generated/5.0.1/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.2/bookworm/Dockerfile | 4 ++ generated/5.0.2/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.2/bullseye/Dockerfile | 4 ++ generated/5.0.2/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.2/jammy/Dockerfile | 4 ++ generated/5.0.2/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.2/noble/Dockerfile | 4 ++ generated/5.0.2/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.2/trixie/Dockerfile | 4 ++ generated/5.0.2/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.3/bookworm/Dockerfile | 4 ++ generated/5.0.3/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.3/bullseye/Dockerfile | 4 ++ generated/5.0.3/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.3/jammy/Dockerfile | 4 ++ generated/5.0.3/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.3/noble/Dockerfile | 4 ++ generated/5.0.3/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.3/trixie/Dockerfile | 4 ++ generated/5.0.3/trixie/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.4/bookworm/Dockerfile | 4 ++ generated/5.0.4/bookworm/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.4/bullseye/Dockerfile | 4 ++ generated/5.0.4/bullseye/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.4/jammy/Dockerfile | 4 ++ generated/5.0.4/jammy/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.4/noble/Dockerfile | 4 ++ generated/5.0.4/noble/entrypoint.sh | 79 +++++++++++++++++---- generated/5.0.4/trixie/Dockerfile | 4 ++ generated/5.0.4/trixie/entrypoint.sh | 79 +++++++++++++++++---- src/Dockerfile.template | 4 ++ src/README.md.template | 12 +++- src/entrypoint.sh | 79 +++++++++++++++++---- src/image.tests.ps1 | 94 +++++++++++++++++++++++++ 196 files changed, 6840 insertions(+), 1252 deletions(-) diff --git a/DECISIONS.md b/DECISIONS.md index e8a9194..6313474 100644 --- a/DECISIONS.md +++ b/DECISIONS.md @@ -127,3 +127,9 @@ Also adds `tzdata` to Noble's distro `extraPackages` (matching Jammy). FB3 relie **Decision:** The FB3-only `libtommath.so.0` symlink and the `libncurses5`/`libtinfo5` provisioning (D-017) run inside the main `RUN` step, after the prerequisite `apt-get install` and before `./install.sh -silent`. They are no longer separate `RUN` steps after the install. Amends the placement described in D-017; the provisioning logic itself is unchanged. **Rationale:** The FB3 installer sets the generated SYSDBA password with `gsec -add sysdba -pw `, and then writes that password to `/opt/firebird/SYSDBA.password`. FB3's `gsec` (and `libfbclient`, `libSrp.so`) link against `libtommath.so.0` and `libncurses.so.5`/`libtinfo.so.5`. With the libraries provisioned only after the install, `gsec` failed with `error while loading shared libraries: libtommath.so.0`; the installer's `runSilent` wrapper printed the error and carried on. The image therefore shipped the tarball's pristine `security3.fdb` — no Srp user, no `PLG$SRP` table — alongside a `SYSDBA.password` file holding a password that was never set. Any Srp login then failed with the misleading `Install incomplete, please read the Compatibility chapter in the release notes for this version`. The defect stayed hidden because `FIREBIRD_ROOT_PASSWORD` (used in every documented example) and `FIREBIRD_USER` both go through the Srp user manager at container start, which creates the missing structures. The test suite now covers the stock, no-environment container. FB4+ is unaffected: its binaries' dependencies are satisfied by the prerequisite packages. See [issue #47](https://github.com/FirebirdSQL/firebird-docker/issues/47). + +## D-021: Random SYSDBA password on first start, gated by the security database checksum + +**Decision:** When `FIREBIRD_ROOT_PASSWORD` is not set, the entrypoint generates a random 20-character alphanumeric SYSDBA password, sets it with `CREATE OR ALTER USER SYSDBA ... USING PLUGIN Srp` (and `Legacy_UserManager` when `FIREBIRD_USE_LEGACY_AUTH=true`), and rewrites `/opt/firebird/SYSDBA.password` in the installer's format. This happens only while the security database still matches the SHA-256 checksum recorded at image build time (`/opt/firebird/.security.fdb.sha256`). Only the file's path is logged, not the password: container logs are often readable by more people than the container itself (log aggregators, CI output), so printing the password to stdout would re-expose it. The behaviour when `FIREBIRD_ROOT_PASSWORD` is set is unchanged. + +**Rationale:** The Firebird installer generates the SYSDBA password at image build time, so every container of an image shared the same password, readable by anyone who can pull the image. The security database lives in the container's writable layer, so the password must be replaced once per container: restarts keep it, recreated containers get a new one. The checksum is what makes the change idempotent and safe. After the first start the database no longer matches, so restarts leave it alone, with no marker file needed. A security database persisted outside the container and bind-mounted in ([issue #5](https://github.com/FirebirdSQL/firebird-docker/issues/5)) doesn't match either, so its SYSDBA password is never overwritten. A plain "first start" marker would have broken that use case on every container recreation. See [issue #48](https://github.com/FirebirdSQL/firebird-docker/issues/48). diff --git a/README.md b/README.md index afa59ea..ae2cbbf 100644 --- a/README.md +++ b/README.md @@ -199,10 +199,18 @@ The following environment variables can be used to customize the container. ### `FIREBIRD_ROOT_PASSWORD` -Firebird installer generates a one-off password for `SYSDBA` and stores it in `/opt/firebird/SYSDBA.password`. - If `FIREBIRD_ROOT_PASSWORD` is set, `SYSDBA` password will be changed. And the file `/opt/firebird/SYSDBA.password` will be removed. +Otherwise, a random password for `SYSDBA` is generated on the container's first start and stored in `/opt/firebird/SYSDBA.password`. It is not printed to the container log. To read it: + +```bash +docker exec MY_CONTAINER_NAME_OR_ID cat /opt/firebird/SYSDBA.password +``` + +The security database lives in the container (not in the data volume). Therefore, restarting a container keeps its password, while recreating it (e.g. `docker compose up` after an image update) generates a new one. Set `FIREBIRD_ROOT_PASSWORD` if you need a stable `SYSDBA` password. + +A security database changed since the image was built (e.g. a persisted `/opt/firebird/security5.fdb` bind-mounted into the container) is left untouched. + ### `FIREBIRD_USER` diff --git a/generated/3.0.10/bookworm/Dockerfile b/generated/3.0.10/bookworm/Dockerfile index fa88aa4..9e9c5aa 100644 --- a/generated/3.0.10/bookworm/Dockerfile +++ b/generated/3.0.10/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.10/bookworm/entrypoint.sh b/generated/3.0.10/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.10/bookworm/entrypoint.sh +++ b/generated/3.0.10/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.10/bullseye/Dockerfile b/generated/3.0.10/bullseye/Dockerfile index 9228d35..9f1664c 100644 --- a/generated/3.0.10/bullseye/Dockerfile +++ b/generated/3.0.10/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.10/bullseye/entrypoint.sh b/generated/3.0.10/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.10/bullseye/entrypoint.sh +++ b/generated/3.0.10/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.10/jammy/Dockerfile b/generated/3.0.10/jammy/Dockerfile index 01d4774..3500386 100644 --- a/generated/3.0.10/jammy/Dockerfile +++ b/generated/3.0.10/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.10/jammy/entrypoint.sh b/generated/3.0.10/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.10/jammy/entrypoint.sh +++ b/generated/3.0.10/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.10/noble/Dockerfile b/generated/3.0.10/noble/Dockerfile index 956b545..17f16b6 100644 --- a/generated/3.0.10/noble/Dockerfile +++ b/generated/3.0.10/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.10/noble/entrypoint.sh b/generated/3.0.10/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.10/noble/entrypoint.sh +++ b/generated/3.0.10/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.10/trixie/Dockerfile b/generated/3.0.10/trixie/Dockerfile index d1d9fec..16be858 100644 --- a/generated/3.0.10/trixie/Dockerfile +++ b/generated/3.0.10/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.10/trixie/entrypoint.sh b/generated/3.0.10/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.10/trixie/entrypoint.sh +++ b/generated/3.0.10/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.11/bookworm/Dockerfile b/generated/3.0.11/bookworm/Dockerfile index 4904288..83e6790 100644 --- a/generated/3.0.11/bookworm/Dockerfile +++ b/generated/3.0.11/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.11/bookworm/entrypoint.sh b/generated/3.0.11/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.11/bookworm/entrypoint.sh +++ b/generated/3.0.11/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.11/bullseye/Dockerfile b/generated/3.0.11/bullseye/Dockerfile index 787dd84..aa5843d 100644 --- a/generated/3.0.11/bullseye/Dockerfile +++ b/generated/3.0.11/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.11/bullseye/entrypoint.sh b/generated/3.0.11/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.11/bullseye/entrypoint.sh +++ b/generated/3.0.11/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.11/jammy/Dockerfile b/generated/3.0.11/jammy/Dockerfile index f07c2d9..43db329 100644 --- a/generated/3.0.11/jammy/Dockerfile +++ b/generated/3.0.11/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.11/jammy/entrypoint.sh b/generated/3.0.11/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.11/jammy/entrypoint.sh +++ b/generated/3.0.11/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.11/noble/Dockerfile b/generated/3.0.11/noble/Dockerfile index b189edf..a20bb11 100644 --- a/generated/3.0.11/noble/Dockerfile +++ b/generated/3.0.11/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.11/noble/entrypoint.sh b/generated/3.0.11/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.11/noble/entrypoint.sh +++ b/generated/3.0.11/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.11/trixie/Dockerfile b/generated/3.0.11/trixie/Dockerfile index fb8ad84..e84e1ad 100644 --- a/generated/3.0.11/trixie/Dockerfile +++ b/generated/3.0.11/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.11/trixie/entrypoint.sh b/generated/3.0.11/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.11/trixie/entrypoint.sh +++ b/generated/3.0.11/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.12/bookworm/Dockerfile b/generated/3.0.12/bookworm/Dockerfile index 1b31557..9b982de 100644 --- a/generated/3.0.12/bookworm/Dockerfile +++ b/generated/3.0.12/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.12/bookworm/entrypoint.sh b/generated/3.0.12/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.12/bookworm/entrypoint.sh +++ b/generated/3.0.12/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.12/bullseye/Dockerfile b/generated/3.0.12/bullseye/Dockerfile index b57adf7..d43cb28 100644 --- a/generated/3.0.12/bullseye/Dockerfile +++ b/generated/3.0.12/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.12/bullseye/entrypoint.sh b/generated/3.0.12/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.12/bullseye/entrypoint.sh +++ b/generated/3.0.12/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.12/jammy/Dockerfile b/generated/3.0.12/jammy/Dockerfile index f4306ed..ae6865a 100644 --- a/generated/3.0.12/jammy/Dockerfile +++ b/generated/3.0.12/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.12/jammy/entrypoint.sh b/generated/3.0.12/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.12/jammy/entrypoint.sh +++ b/generated/3.0.12/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.12/noble/Dockerfile b/generated/3.0.12/noble/Dockerfile index ce4de96..0c49bd3 100644 --- a/generated/3.0.12/noble/Dockerfile +++ b/generated/3.0.12/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.12/noble/entrypoint.sh b/generated/3.0.12/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.12/noble/entrypoint.sh +++ b/generated/3.0.12/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.12/trixie/Dockerfile b/generated/3.0.12/trixie/Dockerfile index 1059a19..32cf682 100644 --- a/generated/3.0.12/trixie/Dockerfile +++ b/generated/3.0.12/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.12/trixie/entrypoint.sh b/generated/3.0.12/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.12/trixie/entrypoint.sh +++ b/generated/3.0.12/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.13/bookworm/Dockerfile b/generated/3.0.13/bookworm/Dockerfile index 921784c..04b39d4 100644 --- a/generated/3.0.13/bookworm/Dockerfile +++ b/generated/3.0.13/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.13/bookworm/entrypoint.sh b/generated/3.0.13/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.13/bookworm/entrypoint.sh +++ b/generated/3.0.13/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.13/bullseye/Dockerfile b/generated/3.0.13/bullseye/Dockerfile index 8564200..b4da81c 100644 --- a/generated/3.0.13/bullseye/Dockerfile +++ b/generated/3.0.13/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.13/bullseye/entrypoint.sh b/generated/3.0.13/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.13/bullseye/entrypoint.sh +++ b/generated/3.0.13/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.13/jammy/Dockerfile b/generated/3.0.13/jammy/Dockerfile index b6dcad5..8d28ff1 100644 --- a/generated/3.0.13/jammy/Dockerfile +++ b/generated/3.0.13/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.13/jammy/entrypoint.sh b/generated/3.0.13/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.13/jammy/entrypoint.sh +++ b/generated/3.0.13/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.13/noble/Dockerfile b/generated/3.0.13/noble/Dockerfile index 98756f6..c911d2b 100644 --- a/generated/3.0.13/noble/Dockerfile +++ b/generated/3.0.13/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.13/noble/entrypoint.sh b/generated/3.0.13/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.13/noble/entrypoint.sh +++ b/generated/3.0.13/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.13/trixie/Dockerfile b/generated/3.0.13/trixie/Dockerfile index e995583..71e0ad2 100644 --- a/generated/3.0.13/trixie/Dockerfile +++ b/generated/3.0.13/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.13/trixie/entrypoint.sh b/generated/3.0.13/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.13/trixie/entrypoint.sh +++ b/generated/3.0.13/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.14/bookworm/Dockerfile b/generated/3.0.14/bookworm/Dockerfile index 9241c5b..6012c42 100644 --- a/generated/3.0.14/bookworm/Dockerfile +++ b/generated/3.0.14/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.14/bookworm/entrypoint.sh b/generated/3.0.14/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.14/bookworm/entrypoint.sh +++ b/generated/3.0.14/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.14/bullseye/Dockerfile b/generated/3.0.14/bullseye/Dockerfile index 3d923ac..d7430a9 100644 --- a/generated/3.0.14/bullseye/Dockerfile +++ b/generated/3.0.14/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.14/bullseye/entrypoint.sh b/generated/3.0.14/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.14/bullseye/entrypoint.sh +++ b/generated/3.0.14/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.14/jammy/Dockerfile b/generated/3.0.14/jammy/Dockerfile index ec5f14f..ce3dd1c 100644 --- a/generated/3.0.14/jammy/Dockerfile +++ b/generated/3.0.14/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.14/jammy/entrypoint.sh b/generated/3.0.14/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.14/jammy/entrypoint.sh +++ b/generated/3.0.14/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.14/noble/Dockerfile b/generated/3.0.14/noble/Dockerfile index 6cd728a..0a199a4 100644 --- a/generated/3.0.14/noble/Dockerfile +++ b/generated/3.0.14/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.14/noble/entrypoint.sh b/generated/3.0.14/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.14/noble/entrypoint.sh +++ b/generated/3.0.14/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.14/trixie/Dockerfile b/generated/3.0.14/trixie/Dockerfile index 83e532c..283aac8 100644 --- a/generated/3.0.14/trixie/Dockerfile +++ b/generated/3.0.14/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.14/trixie/entrypoint.sh b/generated/3.0.14/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.14/trixie/entrypoint.sh +++ b/generated/3.0.14/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.9/bookworm/Dockerfile b/generated/3.0.9/bookworm/Dockerfile index 2d52fbd..2d9f3ca 100644 --- a/generated/3.0.9/bookworm/Dockerfile +++ b/generated/3.0.9/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.9/bookworm/entrypoint.sh b/generated/3.0.9/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.9/bookworm/entrypoint.sh +++ b/generated/3.0.9/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.9/bullseye/Dockerfile b/generated/3.0.9/bullseye/Dockerfile index ef2ca1e..2c94a58 100644 --- a/generated/3.0.9/bullseye/Dockerfile +++ b/generated/3.0.9/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.9/bullseye/entrypoint.sh b/generated/3.0.9/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.9/bullseye/entrypoint.sh +++ b/generated/3.0.9/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.9/jammy/Dockerfile b/generated/3.0.9/jammy/Dockerfile index 8c44d8f..3d558ba 100644 --- a/generated/3.0.9/jammy/Dockerfile +++ b/generated/3.0.9/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.9/jammy/entrypoint.sh b/generated/3.0.9/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.9/jammy/entrypoint.sh +++ b/generated/3.0.9/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.9/noble/Dockerfile b/generated/3.0.9/noble/Dockerfile index 8177c6b..4f8b678 100644 --- a/generated/3.0.9/noble/Dockerfile +++ b/generated/3.0.9/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.9/noble/entrypoint.sh b/generated/3.0.9/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.9/noble/entrypoint.sh +++ b/generated/3.0.9/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/3.0.9/trixie/Dockerfile b/generated/3.0.9/trixie/Dockerfile index 374d8ca..a419b66 100644 --- a/generated/3.0.9/trixie/Dockerfile +++ b/generated/3.0.9/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/3.0.9/trixie/entrypoint.sh b/generated/3.0.9/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/3.0.9/trixie/entrypoint.sh +++ b/generated/3.0.9/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.0/bookworm/Dockerfile b/generated/4.0.0/bookworm/Dockerfile index 3c15f8d..7eeb44e 100644 --- a/generated/4.0.0/bookworm/Dockerfile +++ b/generated/4.0.0/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.0/bookworm/entrypoint.sh b/generated/4.0.0/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.0/bookworm/entrypoint.sh +++ b/generated/4.0.0/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.0/bullseye/Dockerfile b/generated/4.0.0/bullseye/Dockerfile index b34ef4b..d769a29 100644 --- a/generated/4.0.0/bullseye/Dockerfile +++ b/generated/4.0.0/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.0/bullseye/entrypoint.sh b/generated/4.0.0/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.0/bullseye/entrypoint.sh +++ b/generated/4.0.0/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.0/jammy/Dockerfile b/generated/4.0.0/jammy/Dockerfile index 3f6fb51..183ddc7 100644 --- a/generated/4.0.0/jammy/Dockerfile +++ b/generated/4.0.0/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.0/jammy/entrypoint.sh b/generated/4.0.0/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.0/jammy/entrypoint.sh +++ b/generated/4.0.0/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.0/noble/Dockerfile b/generated/4.0.0/noble/Dockerfile index 0135fcf..1f5c8de 100644 --- a/generated/4.0.0/noble/Dockerfile +++ b/generated/4.0.0/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.0/noble/entrypoint.sh b/generated/4.0.0/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.0/noble/entrypoint.sh +++ b/generated/4.0.0/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.0/trixie/Dockerfile b/generated/4.0.0/trixie/Dockerfile index f4a3cd3..98bba71 100644 --- a/generated/4.0.0/trixie/Dockerfile +++ b/generated/4.0.0/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.0/trixie/entrypoint.sh b/generated/4.0.0/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.0/trixie/entrypoint.sh +++ b/generated/4.0.0/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.1/bookworm/Dockerfile b/generated/4.0.1/bookworm/Dockerfile index 2745250..4f96547 100644 --- a/generated/4.0.1/bookworm/Dockerfile +++ b/generated/4.0.1/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.1/bookworm/entrypoint.sh b/generated/4.0.1/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.1/bookworm/entrypoint.sh +++ b/generated/4.0.1/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.1/bullseye/Dockerfile b/generated/4.0.1/bullseye/Dockerfile index 6ae2bc7..4e16df5 100644 --- a/generated/4.0.1/bullseye/Dockerfile +++ b/generated/4.0.1/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.1/bullseye/entrypoint.sh b/generated/4.0.1/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.1/bullseye/entrypoint.sh +++ b/generated/4.0.1/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.1/jammy/Dockerfile b/generated/4.0.1/jammy/Dockerfile index 73dfbd0..f6c47b5 100644 --- a/generated/4.0.1/jammy/Dockerfile +++ b/generated/4.0.1/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.1/jammy/entrypoint.sh b/generated/4.0.1/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.1/jammy/entrypoint.sh +++ b/generated/4.0.1/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.1/noble/Dockerfile b/generated/4.0.1/noble/Dockerfile index 1055c42..16759be 100644 --- a/generated/4.0.1/noble/Dockerfile +++ b/generated/4.0.1/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.1/noble/entrypoint.sh b/generated/4.0.1/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.1/noble/entrypoint.sh +++ b/generated/4.0.1/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.1/trixie/Dockerfile b/generated/4.0.1/trixie/Dockerfile index 8780e9f..9b0c216 100644 --- a/generated/4.0.1/trixie/Dockerfile +++ b/generated/4.0.1/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.1/trixie/entrypoint.sh b/generated/4.0.1/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.1/trixie/entrypoint.sh +++ b/generated/4.0.1/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.2/bookworm/Dockerfile b/generated/4.0.2/bookworm/Dockerfile index 7d05f98..5b750ee 100644 --- a/generated/4.0.2/bookworm/Dockerfile +++ b/generated/4.0.2/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.2/bookworm/entrypoint.sh b/generated/4.0.2/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.2/bookworm/entrypoint.sh +++ b/generated/4.0.2/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.2/bullseye/Dockerfile b/generated/4.0.2/bullseye/Dockerfile index 2d2cb47..b3ee048 100644 --- a/generated/4.0.2/bullseye/Dockerfile +++ b/generated/4.0.2/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.2/bullseye/entrypoint.sh b/generated/4.0.2/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.2/bullseye/entrypoint.sh +++ b/generated/4.0.2/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.2/jammy/Dockerfile b/generated/4.0.2/jammy/Dockerfile index e967f18..32d5f7f 100644 --- a/generated/4.0.2/jammy/Dockerfile +++ b/generated/4.0.2/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.2/jammy/entrypoint.sh b/generated/4.0.2/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.2/jammy/entrypoint.sh +++ b/generated/4.0.2/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.2/noble/Dockerfile b/generated/4.0.2/noble/Dockerfile index f7367e5..d08afd1 100644 --- a/generated/4.0.2/noble/Dockerfile +++ b/generated/4.0.2/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.2/noble/entrypoint.sh b/generated/4.0.2/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.2/noble/entrypoint.sh +++ b/generated/4.0.2/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.2/trixie/Dockerfile b/generated/4.0.2/trixie/Dockerfile index c0720b2..c24f045 100644 --- a/generated/4.0.2/trixie/Dockerfile +++ b/generated/4.0.2/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.2/trixie/entrypoint.sh b/generated/4.0.2/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.2/trixie/entrypoint.sh +++ b/generated/4.0.2/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.3/bookworm/Dockerfile b/generated/4.0.3/bookworm/Dockerfile index 4c049d3..b778ed3 100644 --- a/generated/4.0.3/bookworm/Dockerfile +++ b/generated/4.0.3/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.3/bookworm/entrypoint.sh b/generated/4.0.3/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.3/bookworm/entrypoint.sh +++ b/generated/4.0.3/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.3/bullseye/Dockerfile b/generated/4.0.3/bullseye/Dockerfile index cd671f7..de3e5b7 100644 --- a/generated/4.0.3/bullseye/Dockerfile +++ b/generated/4.0.3/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.3/bullseye/entrypoint.sh b/generated/4.0.3/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.3/bullseye/entrypoint.sh +++ b/generated/4.0.3/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.3/jammy/Dockerfile b/generated/4.0.3/jammy/Dockerfile index 0b5443f..d1cc4ce 100644 --- a/generated/4.0.3/jammy/Dockerfile +++ b/generated/4.0.3/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.3/jammy/entrypoint.sh b/generated/4.0.3/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.3/jammy/entrypoint.sh +++ b/generated/4.0.3/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.3/noble/Dockerfile b/generated/4.0.3/noble/Dockerfile index c72b285..0b21b84 100644 --- a/generated/4.0.3/noble/Dockerfile +++ b/generated/4.0.3/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.3/noble/entrypoint.sh b/generated/4.0.3/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.3/noble/entrypoint.sh +++ b/generated/4.0.3/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.3/trixie/Dockerfile b/generated/4.0.3/trixie/Dockerfile index 796ac22..2ce6f70 100644 --- a/generated/4.0.3/trixie/Dockerfile +++ b/generated/4.0.3/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.3/trixie/entrypoint.sh b/generated/4.0.3/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.3/trixie/entrypoint.sh +++ b/generated/4.0.3/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.4/bookworm/Dockerfile b/generated/4.0.4/bookworm/Dockerfile index c5ec139..2de02c3 100644 --- a/generated/4.0.4/bookworm/Dockerfile +++ b/generated/4.0.4/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.4/bookworm/entrypoint.sh b/generated/4.0.4/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.4/bookworm/entrypoint.sh +++ b/generated/4.0.4/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.4/bullseye/Dockerfile b/generated/4.0.4/bullseye/Dockerfile index 7705202..3af45ec 100644 --- a/generated/4.0.4/bullseye/Dockerfile +++ b/generated/4.0.4/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.4/bullseye/entrypoint.sh b/generated/4.0.4/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.4/bullseye/entrypoint.sh +++ b/generated/4.0.4/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.4/jammy/Dockerfile b/generated/4.0.4/jammy/Dockerfile index 29bec27..6c137b4 100644 --- a/generated/4.0.4/jammy/Dockerfile +++ b/generated/4.0.4/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.4/jammy/entrypoint.sh b/generated/4.0.4/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.4/jammy/entrypoint.sh +++ b/generated/4.0.4/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.4/noble/Dockerfile b/generated/4.0.4/noble/Dockerfile index 918eb07..87684ea 100644 --- a/generated/4.0.4/noble/Dockerfile +++ b/generated/4.0.4/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.4/noble/entrypoint.sh b/generated/4.0.4/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.4/noble/entrypoint.sh +++ b/generated/4.0.4/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.4/trixie/Dockerfile b/generated/4.0.4/trixie/Dockerfile index e265c8d..a25974c 100644 --- a/generated/4.0.4/trixie/Dockerfile +++ b/generated/4.0.4/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.4/trixie/entrypoint.sh b/generated/4.0.4/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.4/trixie/entrypoint.sh +++ b/generated/4.0.4/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.5/bookworm/Dockerfile b/generated/4.0.5/bookworm/Dockerfile index 666b38c..822417b 100644 --- a/generated/4.0.5/bookworm/Dockerfile +++ b/generated/4.0.5/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.5/bookworm/entrypoint.sh b/generated/4.0.5/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.5/bookworm/entrypoint.sh +++ b/generated/4.0.5/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.5/bullseye/Dockerfile b/generated/4.0.5/bullseye/Dockerfile index b68d574..a8bca6c 100644 --- a/generated/4.0.5/bullseye/Dockerfile +++ b/generated/4.0.5/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.5/bullseye/entrypoint.sh b/generated/4.0.5/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.5/bullseye/entrypoint.sh +++ b/generated/4.0.5/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.5/jammy/Dockerfile b/generated/4.0.5/jammy/Dockerfile index 794432e..cc7e221 100644 --- a/generated/4.0.5/jammy/Dockerfile +++ b/generated/4.0.5/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.5/jammy/entrypoint.sh b/generated/4.0.5/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.5/jammy/entrypoint.sh +++ b/generated/4.0.5/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.5/noble/Dockerfile b/generated/4.0.5/noble/Dockerfile index febfa47..1f9f8dd 100644 --- a/generated/4.0.5/noble/Dockerfile +++ b/generated/4.0.5/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.5/noble/entrypoint.sh b/generated/4.0.5/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.5/noble/entrypoint.sh +++ b/generated/4.0.5/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.5/trixie/Dockerfile b/generated/4.0.5/trixie/Dockerfile index 69b2600..8710724 100644 --- a/generated/4.0.5/trixie/Dockerfile +++ b/generated/4.0.5/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.5/trixie/entrypoint.sh b/generated/4.0.5/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.5/trixie/entrypoint.sh +++ b/generated/4.0.5/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.6/bookworm/Dockerfile b/generated/4.0.6/bookworm/Dockerfile index 1b1e8d1..f27c320 100644 --- a/generated/4.0.6/bookworm/Dockerfile +++ b/generated/4.0.6/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.6/bookworm/entrypoint.sh b/generated/4.0.6/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.6/bookworm/entrypoint.sh +++ b/generated/4.0.6/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.6/bullseye/Dockerfile b/generated/4.0.6/bullseye/Dockerfile index db05dc3..8b350fa 100644 --- a/generated/4.0.6/bullseye/Dockerfile +++ b/generated/4.0.6/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.6/bullseye/entrypoint.sh b/generated/4.0.6/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.6/bullseye/entrypoint.sh +++ b/generated/4.0.6/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.6/jammy/Dockerfile b/generated/4.0.6/jammy/Dockerfile index a43dabd..1bb9c49 100644 --- a/generated/4.0.6/jammy/Dockerfile +++ b/generated/4.0.6/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.6/jammy/entrypoint.sh b/generated/4.0.6/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.6/jammy/entrypoint.sh +++ b/generated/4.0.6/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.6/noble/Dockerfile b/generated/4.0.6/noble/Dockerfile index b7c7c55..48ee51e 100644 --- a/generated/4.0.6/noble/Dockerfile +++ b/generated/4.0.6/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.6/noble/entrypoint.sh b/generated/4.0.6/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.6/noble/entrypoint.sh +++ b/generated/4.0.6/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.6/trixie/Dockerfile b/generated/4.0.6/trixie/Dockerfile index 5673c8b..0044323 100644 --- a/generated/4.0.6/trixie/Dockerfile +++ b/generated/4.0.6/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.6/trixie/entrypoint.sh b/generated/4.0.6/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.6/trixie/entrypoint.sh +++ b/generated/4.0.6/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.7/bookworm/Dockerfile b/generated/4.0.7/bookworm/Dockerfile index 550e030..bf8a32f 100644 --- a/generated/4.0.7/bookworm/Dockerfile +++ b/generated/4.0.7/bookworm/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.7/bookworm/entrypoint.sh b/generated/4.0.7/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.7/bookworm/entrypoint.sh +++ b/generated/4.0.7/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.7/bullseye/Dockerfile b/generated/4.0.7/bullseye/Dockerfile index 5e4fb0a..dd2002f 100644 --- a/generated/4.0.7/bullseye/Dockerfile +++ b/generated/4.0.7/bullseye/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.7/bullseye/entrypoint.sh b/generated/4.0.7/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.7/bullseye/entrypoint.sh +++ b/generated/4.0.7/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.7/jammy/Dockerfile b/generated/4.0.7/jammy/Dockerfile index 41a499a..38c23a7 100644 --- a/generated/4.0.7/jammy/Dockerfile +++ b/generated/4.0.7/jammy/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.7/jammy/entrypoint.sh b/generated/4.0.7/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.7/jammy/entrypoint.sh +++ b/generated/4.0.7/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.7/noble/Dockerfile b/generated/4.0.7/noble/Dockerfile index 98bf804..3692bc7 100644 --- a/generated/4.0.7/noble/Dockerfile +++ b/generated/4.0.7/noble/Dockerfile @@ -96,6 +96,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.7/noble/entrypoint.sh b/generated/4.0.7/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.7/noble/entrypoint.sh +++ b/generated/4.0.7/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/4.0.7/trixie/Dockerfile b/generated/4.0.7/trixie/Dockerfile index f7747c7..34ec817 100644 --- a/generated/4.0.7/trixie/Dockerfile +++ b/generated/4.0.7/trixie/Dockerfile @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/4.0.7/trixie/entrypoint.sh b/generated/4.0.7/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/4.0.7/trixie/entrypoint.sh +++ b/generated/4.0.7/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.0/bookworm/Dockerfile b/generated/5.0.0/bookworm/Dockerfile index 4b93170..dbda187 100644 --- a/generated/5.0.0/bookworm/Dockerfile +++ b/generated/5.0.0/bookworm/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.0/bookworm/entrypoint.sh b/generated/5.0.0/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.0/bookworm/entrypoint.sh +++ b/generated/5.0.0/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.0/bullseye/Dockerfile b/generated/5.0.0/bullseye/Dockerfile index dfc17c4..243e56f 100644 --- a/generated/5.0.0/bullseye/Dockerfile +++ b/generated/5.0.0/bullseye/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.0/bullseye/entrypoint.sh b/generated/5.0.0/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.0/bullseye/entrypoint.sh +++ b/generated/5.0.0/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.0/jammy/Dockerfile b/generated/5.0.0/jammy/Dockerfile index 0b214e5..d2405de 100644 --- a/generated/5.0.0/jammy/Dockerfile +++ b/generated/5.0.0/jammy/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.0/jammy/entrypoint.sh b/generated/5.0.0/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.0/jammy/entrypoint.sh +++ b/generated/5.0.0/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.0/noble/Dockerfile b/generated/5.0.0/noble/Dockerfile index 88c1a7b..c7b9383 100644 --- a/generated/5.0.0/noble/Dockerfile +++ b/generated/5.0.0/noble/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.0/noble/entrypoint.sh b/generated/5.0.0/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.0/noble/entrypoint.sh +++ b/generated/5.0.0/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.0/trixie/Dockerfile b/generated/5.0.0/trixie/Dockerfile index 4a4ddd8..bb239de 100644 --- a/generated/5.0.0/trixie/Dockerfile +++ b/generated/5.0.0/trixie/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.0/trixie/entrypoint.sh b/generated/5.0.0/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.0/trixie/entrypoint.sh +++ b/generated/5.0.0/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.1/bookworm/Dockerfile b/generated/5.0.1/bookworm/Dockerfile index 8273db9..3f8df01 100644 --- a/generated/5.0.1/bookworm/Dockerfile +++ b/generated/5.0.1/bookworm/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.1/bookworm/entrypoint.sh b/generated/5.0.1/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.1/bookworm/entrypoint.sh +++ b/generated/5.0.1/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.1/bullseye/Dockerfile b/generated/5.0.1/bullseye/Dockerfile index f727565..82a895b 100644 --- a/generated/5.0.1/bullseye/Dockerfile +++ b/generated/5.0.1/bullseye/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.1/bullseye/entrypoint.sh b/generated/5.0.1/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.1/bullseye/entrypoint.sh +++ b/generated/5.0.1/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.1/jammy/Dockerfile b/generated/5.0.1/jammy/Dockerfile index a753018..e74e184 100644 --- a/generated/5.0.1/jammy/Dockerfile +++ b/generated/5.0.1/jammy/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.1/jammy/entrypoint.sh b/generated/5.0.1/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.1/jammy/entrypoint.sh +++ b/generated/5.0.1/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.1/noble/Dockerfile b/generated/5.0.1/noble/Dockerfile index cae9820..99e838f 100644 --- a/generated/5.0.1/noble/Dockerfile +++ b/generated/5.0.1/noble/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.1/noble/entrypoint.sh b/generated/5.0.1/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.1/noble/entrypoint.sh +++ b/generated/5.0.1/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.1/trixie/Dockerfile b/generated/5.0.1/trixie/Dockerfile index 0f35e70..1abd43c 100644 --- a/generated/5.0.1/trixie/Dockerfile +++ b/generated/5.0.1/trixie/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.1/trixie/entrypoint.sh b/generated/5.0.1/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.1/trixie/entrypoint.sh +++ b/generated/5.0.1/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.2/bookworm/Dockerfile b/generated/5.0.2/bookworm/Dockerfile index 1f77c73..cff72e2 100644 --- a/generated/5.0.2/bookworm/Dockerfile +++ b/generated/5.0.2/bookworm/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.2/bookworm/entrypoint.sh b/generated/5.0.2/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.2/bookworm/entrypoint.sh +++ b/generated/5.0.2/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.2/bullseye/Dockerfile b/generated/5.0.2/bullseye/Dockerfile index 0cbbb1c..991acea 100644 --- a/generated/5.0.2/bullseye/Dockerfile +++ b/generated/5.0.2/bullseye/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.2/bullseye/entrypoint.sh b/generated/5.0.2/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.2/bullseye/entrypoint.sh +++ b/generated/5.0.2/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.2/jammy/Dockerfile b/generated/5.0.2/jammy/Dockerfile index ad8ddca..95db732 100644 --- a/generated/5.0.2/jammy/Dockerfile +++ b/generated/5.0.2/jammy/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.2/jammy/entrypoint.sh b/generated/5.0.2/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.2/jammy/entrypoint.sh +++ b/generated/5.0.2/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.2/noble/Dockerfile b/generated/5.0.2/noble/Dockerfile index 8c5576d..d9251ec 100644 --- a/generated/5.0.2/noble/Dockerfile +++ b/generated/5.0.2/noble/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.2/noble/entrypoint.sh b/generated/5.0.2/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.2/noble/entrypoint.sh +++ b/generated/5.0.2/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.2/trixie/Dockerfile b/generated/5.0.2/trixie/Dockerfile index b68cff8..0eb720f 100644 --- a/generated/5.0.2/trixie/Dockerfile +++ b/generated/5.0.2/trixie/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.2/trixie/entrypoint.sh b/generated/5.0.2/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.2/trixie/entrypoint.sh +++ b/generated/5.0.2/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.3/bookworm/Dockerfile b/generated/5.0.3/bookworm/Dockerfile index c84b9f3..11719d3 100644 --- a/generated/5.0.3/bookworm/Dockerfile +++ b/generated/5.0.3/bookworm/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.3/bookworm/entrypoint.sh b/generated/5.0.3/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.3/bookworm/entrypoint.sh +++ b/generated/5.0.3/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.3/bullseye/Dockerfile b/generated/5.0.3/bullseye/Dockerfile index b5f887c..ff98503 100644 --- a/generated/5.0.3/bullseye/Dockerfile +++ b/generated/5.0.3/bullseye/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.3/bullseye/entrypoint.sh b/generated/5.0.3/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.3/bullseye/entrypoint.sh +++ b/generated/5.0.3/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.3/jammy/Dockerfile b/generated/5.0.3/jammy/Dockerfile index c98b86b..289c612 100644 --- a/generated/5.0.3/jammy/Dockerfile +++ b/generated/5.0.3/jammy/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.3/jammy/entrypoint.sh b/generated/5.0.3/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.3/jammy/entrypoint.sh +++ b/generated/5.0.3/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.3/noble/Dockerfile b/generated/5.0.3/noble/Dockerfile index ee209a9..ab0feaa 100644 --- a/generated/5.0.3/noble/Dockerfile +++ b/generated/5.0.3/noble/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.3/noble/entrypoint.sh b/generated/5.0.3/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.3/noble/entrypoint.sh +++ b/generated/5.0.3/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.3/trixie/Dockerfile b/generated/5.0.3/trixie/Dockerfile index a21ce26..7ef5e5c 100644 --- a/generated/5.0.3/trixie/Dockerfile +++ b/generated/5.0.3/trixie/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.3/trixie/entrypoint.sh b/generated/5.0.3/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.3/trixie/entrypoint.sh +++ b/generated/5.0.3/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.4/bookworm/Dockerfile b/generated/5.0.4/bookworm/Dockerfile index e66d400..69240de 100644 --- a/generated/5.0.4/bookworm/Dockerfile +++ b/generated/5.0.4/bookworm/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.4/bookworm/entrypoint.sh b/generated/5.0.4/bookworm/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.4/bookworm/entrypoint.sh +++ b/generated/5.0.4/bookworm/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.4/bullseye/Dockerfile b/generated/5.0.4/bullseye/Dockerfile index 01b2519..538a80f 100644 --- a/generated/5.0.4/bullseye/Dockerfile +++ b/generated/5.0.4/bullseye/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.4/bullseye/entrypoint.sh b/generated/5.0.4/bullseye/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.4/bullseye/entrypoint.sh +++ b/generated/5.0.4/bullseye/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.4/jammy/Dockerfile b/generated/5.0.4/jammy/Dockerfile index b8b2998..585ab43 100644 --- a/generated/5.0.4/jammy/Dockerfile +++ b/generated/5.0.4/jammy/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.4/jammy/entrypoint.sh b/generated/5.0.4/jammy/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.4/jammy/entrypoint.sh +++ b/generated/5.0.4/jammy/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.4/noble/Dockerfile b/generated/5.0.4/noble/Dockerfile index cc61e88..39feec7 100644 --- a/generated/5.0.4/noble/Dockerfile +++ b/generated/5.0.4/noble/Dockerfile @@ -100,6 +100,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.4/noble/entrypoint.sh b/generated/5.0.4/noble/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.4/noble/entrypoint.sh +++ b/generated/5.0.4/noble/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/generated/5.0.4/trixie/Dockerfile b/generated/5.0.4/trixie/Dockerfile index d1a642a..086bd65 100644 --- a/generated/5.0.4/trixie/Dockerfile +++ b/generated/5.0.4/trixie/Dockerfile @@ -99,6 +99,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/generated/5.0.4/trixie/entrypoint.sh b/generated/5.0.4/trixie/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/generated/5.0.4/trixie/entrypoint.sh +++ b/generated/5.0.4/trixie/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/src/Dockerfile.template b/src/Dockerfile.template index 81f7445..a798b66 100644 --- a/src/Dockerfile.template +++ b/src/Dockerfile.template @@ -95,6 +95,10 @@ RUN set -eux; \ /opt/firebird/include; \ # Remove 'employee' sample database from 'databases.conf' sed -i '/^employee/d' /opt/firebird/databases.conf; \ + # Record the checksum of the security database as shipped in the image. The entrypoint replaces the SYSDBA + # password generated by the installer (the same for every container of this image) only while the security + # database still matches it. See DECISIONS.md D-021 and https://github.com/FirebirdSQL/firebird-docker/issues/48 + sha256sum /opt/firebird/security${FIREBIRD_MAJOR}.fdb > /opt/firebird/.security.fdb.sha256; \ \ # Clean up temporary packages (curl, ca-certificates) and apt lists apt-get purge -y --auto-remove curl ca-certificates; \ diff --git a/src/README.md.template b/src/README.md.template index 42506ac..622eca2 100644 --- a/src/README.md.template +++ b/src/README.md.template @@ -101,10 +101,18 @@ The following environment variables can be used to customize the container. ### `FIREBIRD_ROOT_PASSWORD` -Firebird installer generates a one-off password for `SYSDBA` and stores it in `/opt/firebird/SYSDBA.password`. - If `FIREBIRD_ROOT_PASSWORD` is set, `SYSDBA` password will be changed. And the file `/opt/firebird/SYSDBA.password` will be removed. +Otherwise, a random password for `SYSDBA` is generated on the container's first start and stored in `/opt/firebird/SYSDBA.password`. It is not printed to the container log. To read it: + +```bash +docker exec MY_CONTAINER_NAME_OR_ID cat /opt/firebird/SYSDBA.password +``` + +The security database lives in the container (not in the data volume). Therefore, restarting a container keeps its password, while recreating it (e.g. `docker compose up` after an image update) generates a new one. Set `FIREBIRD_ROOT_PASSWORD` if you need a stable `SYSDBA` password. + +A security database changed since the image was built (e.g. a persisted `/opt/firebird/security5.fdb` bind-mounted into the container) is left untouched. + ### `FIREBIRD_USER` diff --git a/src/entrypoint.sh b/src/entrypoint.sh index 21a0cfa..5a7f4e3 100644 --- a/src/entrypoint.sh +++ b/src/entrypoint.sh @@ -142,34 +142,87 @@ set_config() { fi } -# Changes SYSDBA password if FIREBIRD_ROOT_PASSWORD variable is set. -set_sysdba() { - read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' - if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then - echo 'Changing SYSDBA password.' +# Security database as shipped in the image, and its checksum recorded at image build time. +SECURITY_DB_CHECKSUM_FILE=/opt/firebird/.security.fdb.sha256 + +# usage: generate_password +# Prints a random 20-character alphanumeric password. +generate_password() { + local password + password=$(head -c 512 /dev/urandom | LC_ALL=C tr -dc 'A-Za-z0-9') + printf '%s' "${password:0:20}" +} - local escaped_password - escaped_password=$(escape_sql_string "$FIREBIRD_ROOT_PASSWORD") +# usage: change_sysdba_password PASSWORD +# Sets SYSDBA password in the security database (also for Legacy_UserManager if FIREBIRD_USE_LEGACY_AUTH is 'true'). +change_sysdba_password() { + local escaped_password + escaped_password=$(escape_sql_string "$1") - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Srp; EXIT; EOL - if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then - # [Tabs ahead] - /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL + if [ "$FIREBIRD_USE_LEGACY_AUTH" == 'true' ]; then + # [Tabs ahead] + /opt/firebird/bin/isql -b -user SYSDBA security.db <<-EOL CREATE OR ALTER USER SYSDBA PASSWORD '${escaped_password}' USING PLUGIN Legacy_UserManager; EXIT; EOL - fi + fi +} +# Sets SYSDBA password. +# If FIREBIRD_ROOT_PASSWORD variable is set, uses it and removes /opt/firebird/SYSDBA.password. +# Otherwise, if the security database is still the one shipped in the image, generates a random password and stores it +# in /opt/firebird/SYSDBA.password. The password generated by the Firebird installer at image build time is the same +# for every container of an image. See https://github.com/FirebirdSQL/firebird-docker/issues/48 +# A security database changed since the image build (by a previous start of this container, or bind-mounted by +# the user) is left untouched. +set_sysdba() { + read_from_file_or_env 'FIREBIRD_ROOT_PASSWORD' + if [ -n "$FIREBIRD_ROOT_PASSWORD" ]; then + echo 'Changing SYSDBA password.' + change_sysdba_password "$FIREBIRD_ROOT_PASSWORD" rm -rf /opt/firebird/SYSDBA.password + elif sha256sum --status --check "$SECURITY_DB_CHECKSUM_FILE" 2>/dev/null; then + echo 'Generating random SYSDBA password.' + + local password + password=$(generate_password) + change_sysdba_password "$password" + + # Stores it using the same format of Firebird installer. + # The file is read-only (0440): removes and recreates it. + rm -f /opt/firebird/SYSDBA.password + # [Tabs ahead] + (umask 0337; cat > /opt/firebird/SYSDBA.password <<-EOL + # + # Firebird generated password for user SYSDBA is: + # + ISC_USER=sysdba + ISC_PASSWORD=${password} + # + # Also set legacy variable though it can't be exported directly + # + ISC_PASSWD=${password} + # + # generated on ${HOSTNAME} at time $(date) + # + # Your password can be changed to a more suitable one using + # SQL operator ALTER USER. + # + EOL + ) + + # The password is not printed: container logs are often readable by more people than the container itself. + echo 'SYSDBA password stored in /opt/firebird/SYSDBA.password.' fi } diff --git a/src/image.tests.ps1 b/src/image.tests.ps1 index 709a493..f8243c5 100644 --- a/src/image.tests.ps1 +++ b/src/image.tests.ps1 @@ -320,6 +320,100 @@ task SYSDBA_password_file_allows_remote_login { } } +task SYSDBA_password_is_generated_on_container_first_start { + # The password generated by the Firebird installer at image build time is the same for every container of an image. + # https://github.com/FirebirdSQL/firebird-docker/issues/48 + $imagePassword = docker run --rm $env:FULL_IMAGE_NAME awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password + assert $imagePassword "Expected SYSDBA.password file in the image to contain ISC_PASSWORD." + + Use-Container -Parameters '-e', 'FIREBIRD_DATABASE=test.fdb' { + param($cId) + + $sysdbaPassword = docker exec $cId awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password + assert ($sysdbaPassword -cmatch '^[A-Za-z0-9]{20}$') "Expected a 20-character alphanumeric SYSDBA password, got '$sysdbaPassword'." + assert ($sysdbaPassword -cne $imagePassword) "Expected SYSDBA password to differ from the one generated at image build time." + + # Generated password + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p $sysdbaPassword inet:///var/lib/firebird/data/test.fdb | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected successful login with generated SYSDBA password." + + # Password generated at image build time + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p $imagePassword inet:///var/lib/firebird/data/test.fdb 2>&1 | + ExitCodeIs -ExpectedValue 1 -ErrorMessage "Expected failed login with SYSDBA password generated at image build time." + + $logs = docker logs $cId + $logs | Contains -Pattern 'SYSDBA password stored in /opt/firebird/SYSDBA.password' -ErrorMessage "Expected log message indicating where the generated SYSDBA password is stored." + $logs | ContainsExactly -Pattern $sysdbaPassword -ExpectedCount 0 -ErrorMessage "Expected generated SYSDBA password to not be printed in the log." + + # Restarting the container keeps the password. + docker restart --time 5 $cId > $null + Wait-Port -ContainerName $cId -Port 3050 + + $passwordAfterRestart = docker exec $cId awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password + assert ($passwordAfterRestart -ceq $sysdbaPassword) "Expected SYSDBA password to be kept after container restart." + + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p $sysdbaPassword inet:///var/lib/firebird/data/test.fdb | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected successful login with generated SYSDBA password after container restart." + + docker logs $cId | + ContainsExactly -Pattern 'Generating random SYSDBA password' -ExpectedCount 1 -ErrorMessage "Expected SYSDBA password to be generated only once." + } +} + +task FIREBIRD_USE_LEGACY_AUTH_generated_sysdba_password_works_with_legacy_auth { + # Only Legacy_Auth is accepted by the server: the generated password must also be set for Legacy_UserManager. + Use-Container -Parameters '-e', 'FIREBIRD_DATABASE=test.fdb', '-e', 'FIREBIRD_USE_LEGACY_AUTH=true', '-e', 'FIREBIRD_CONF_AuthServer=Legacy_Auth' { + param($cId) + + $sysdbaPassword = docker exec $cId awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password + + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p $sysdbaPassword inet:///var/lib/firebird/data/test.fdb | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected successful Legacy_Auth login with generated SYSDBA password." + + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p tiger inet:///var/lib/firebird/data/test.fdb 2>&1 | + ExitCodeIs -ExpectedValue 1 -ErrorMessage "Expected failed Legacy_Auth login with incorrect SYSDBA password." + } +} + +task SYSDBA_password_is_kept_for_bind_mounted_security_database { + # A security database persisted outside the container (changed since the image build) must be left untouched. + # https://github.com/FirebirdSQL/firebird-docker/issues/5 + $securityDbFolder = New-TemporaryDirectory + try { + $securityDb = "security$(docker run --rm $env:FULL_IMAGE_NAME printenv FIREBIRD_MAJOR).fdb" + + # Extract a security database with a known SYSDBA password. + $cId = docker run --detach --tmpfs /var/lib/firebird/data -e FIREBIRD_ROOT_PASSWORD=passw0rd $env:FULL_IMAGE_NAME + try { + Wait-Port -ContainerName $cId -Port 3050 + docker stop --time 5 $cId > $null + docker cp "$($cId):/opt/firebird/$securityDb" "$securityDbFolder" > $null + } + finally { + docker rm --force $cId > $null + } + + Use-Container -Parameters '-e', 'FIREBIRD_DATABASE=test.fdb', '-v', "$(Join-Path $securityDbFolder $securityDb):/opt/firebird/$securityDb" { + param($cId) + + 'SELECT 1 FROM rdb$database;' | + docker exec -i $cId isql -b -q -u SYSDBA -p passw0rd inet:///var/lib/firebird/data/test.fdb | + ExitCodeIs -ExpectedValue 0 -ErrorMessage "Expected successful login with SYSDBA password stored in the bind-mounted security database." + + docker logs $cId | + ContainsExactly -Pattern 'Generating random SYSDBA password' -ExpectedCount 0 -ErrorMessage "Expected no SYSDBA password generation for a bind-mounted security database." + } + } + finally { + Remove-Item $securityDbFolder -Force -Recurse + } +} + task FIREBIRD_ROOT_PASSWORD_can_change_sysdba_password { Use-Container -Parameters '-e', 'FIREBIRD_DATABASE=test.fdb', '-e', 'FIREBIRD_ROOT_PASSWORD=passw0rd' { param($cId) From 9199898090f9f6b3c7f4f85f9daf37ac9cd434b2 Mon Sep 17 00:00:00 2001 From: "F.D.Castel" Date: Sat, 26 Sep 2026 21:22:55 +0000 Subject: [PATCH 4/4] fix(entrypoint): validate FIREBIRD_USER/FIREBIRD_PASSWORD before any initialization step set_sysdba now changes the security database even without FIREBIRD_ROOT_PASSWORD, so a missing FIREBIRD_PASSWORD was only detected after SYSDBA had been changed. Fail first, without changing anything (restores FIREBIRD_USER_fails_without_password). --- generated/3.0.10/bookworm/entrypoint.sh | 9 +++++---- generated/3.0.10/bullseye/entrypoint.sh | 9 +++++---- generated/3.0.10/jammy/entrypoint.sh | 9 +++++---- generated/3.0.10/noble/entrypoint.sh | 9 +++++---- generated/3.0.10/trixie/entrypoint.sh | 9 +++++---- generated/3.0.11/bookworm/entrypoint.sh | 9 +++++---- generated/3.0.11/bullseye/entrypoint.sh | 9 +++++---- generated/3.0.11/jammy/entrypoint.sh | 9 +++++---- generated/3.0.11/noble/entrypoint.sh | 9 +++++---- generated/3.0.11/trixie/entrypoint.sh | 9 +++++---- generated/3.0.12/bookworm/entrypoint.sh | 9 +++++---- generated/3.0.12/bullseye/entrypoint.sh | 9 +++++---- generated/3.0.12/jammy/entrypoint.sh | 9 +++++---- generated/3.0.12/noble/entrypoint.sh | 9 +++++---- generated/3.0.12/trixie/entrypoint.sh | 9 +++++---- generated/3.0.13/bookworm/entrypoint.sh | 9 +++++---- generated/3.0.13/bullseye/entrypoint.sh | 9 +++++---- generated/3.0.13/jammy/entrypoint.sh | 9 +++++---- generated/3.0.13/noble/entrypoint.sh | 9 +++++---- generated/3.0.13/trixie/entrypoint.sh | 9 +++++---- generated/3.0.14/bookworm/entrypoint.sh | 9 +++++---- generated/3.0.14/bullseye/entrypoint.sh | 9 +++++---- generated/3.0.14/jammy/entrypoint.sh | 9 +++++---- generated/3.0.14/noble/entrypoint.sh | 9 +++++---- generated/3.0.14/trixie/entrypoint.sh | 9 +++++---- generated/3.0.9/bookworm/entrypoint.sh | 9 +++++---- generated/3.0.9/bullseye/entrypoint.sh | 9 +++++---- generated/3.0.9/jammy/entrypoint.sh | 9 +++++---- generated/3.0.9/noble/entrypoint.sh | 9 +++++---- generated/3.0.9/trixie/entrypoint.sh | 9 +++++---- generated/4.0.0/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.0/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.0/jammy/entrypoint.sh | 9 +++++---- generated/4.0.0/noble/entrypoint.sh | 9 +++++---- generated/4.0.0/trixie/entrypoint.sh | 9 +++++---- generated/4.0.1/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.1/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.1/jammy/entrypoint.sh | 9 +++++---- generated/4.0.1/noble/entrypoint.sh | 9 +++++---- generated/4.0.1/trixie/entrypoint.sh | 9 +++++---- generated/4.0.2/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.2/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.2/jammy/entrypoint.sh | 9 +++++---- generated/4.0.2/noble/entrypoint.sh | 9 +++++---- generated/4.0.2/trixie/entrypoint.sh | 9 +++++---- generated/4.0.3/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.3/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.3/jammy/entrypoint.sh | 9 +++++---- generated/4.0.3/noble/entrypoint.sh | 9 +++++---- generated/4.0.3/trixie/entrypoint.sh | 9 +++++---- generated/4.0.4/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.4/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.4/jammy/entrypoint.sh | 9 +++++---- generated/4.0.4/noble/entrypoint.sh | 9 +++++---- generated/4.0.4/trixie/entrypoint.sh | 9 +++++---- generated/4.0.5/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.5/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.5/jammy/entrypoint.sh | 9 +++++---- generated/4.0.5/noble/entrypoint.sh | 9 +++++---- generated/4.0.5/trixie/entrypoint.sh | 9 +++++---- generated/4.0.6/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.6/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.6/jammy/entrypoint.sh | 9 +++++---- generated/4.0.6/noble/entrypoint.sh | 9 +++++---- generated/4.0.6/trixie/entrypoint.sh | 9 +++++---- generated/4.0.7/bookworm/entrypoint.sh | 9 +++++---- generated/4.0.7/bullseye/entrypoint.sh | 9 +++++---- generated/4.0.7/jammy/entrypoint.sh | 9 +++++---- generated/4.0.7/noble/entrypoint.sh | 9 +++++---- generated/4.0.7/trixie/entrypoint.sh | 9 +++++---- generated/5.0.0/bookworm/entrypoint.sh | 9 +++++---- generated/5.0.0/bullseye/entrypoint.sh | 9 +++++---- generated/5.0.0/jammy/entrypoint.sh | 9 +++++---- generated/5.0.0/noble/entrypoint.sh | 9 +++++---- generated/5.0.0/trixie/entrypoint.sh | 9 +++++---- generated/5.0.1/bookworm/entrypoint.sh | 9 +++++---- generated/5.0.1/bullseye/entrypoint.sh | 9 +++++---- generated/5.0.1/jammy/entrypoint.sh | 9 +++++---- generated/5.0.1/noble/entrypoint.sh | 9 +++++---- generated/5.0.1/trixie/entrypoint.sh | 9 +++++---- generated/5.0.2/bookworm/entrypoint.sh | 9 +++++---- generated/5.0.2/bullseye/entrypoint.sh | 9 +++++---- generated/5.0.2/jammy/entrypoint.sh | 9 +++++---- generated/5.0.2/noble/entrypoint.sh | 9 +++++---- generated/5.0.2/trixie/entrypoint.sh | 9 +++++---- generated/5.0.3/bookworm/entrypoint.sh | 9 +++++---- generated/5.0.3/bullseye/entrypoint.sh | 9 +++++---- generated/5.0.3/jammy/entrypoint.sh | 9 +++++---- generated/5.0.3/noble/entrypoint.sh | 9 +++++---- generated/5.0.3/trixie/entrypoint.sh | 9 +++++---- generated/5.0.4/bookworm/entrypoint.sh | 9 +++++---- generated/5.0.4/bullseye/entrypoint.sh | 9 +++++---- generated/5.0.4/jammy/entrypoint.sh | 9 +++++---- generated/5.0.4/noble/entrypoint.sh | 9 +++++---- generated/5.0.4/trixie/entrypoint.sh | 9 +++++---- src/entrypoint.sh | 9 +++++---- 96 files changed, 480 insertions(+), 384 deletions(-) diff --git a/generated/3.0.10/bookworm/entrypoint.sh b/generated/3.0.10/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.10/bookworm/entrypoint.sh +++ b/generated/3.0.10/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.10/bullseye/entrypoint.sh b/generated/3.0.10/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.10/bullseye/entrypoint.sh +++ b/generated/3.0.10/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.10/jammy/entrypoint.sh b/generated/3.0.10/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.10/jammy/entrypoint.sh +++ b/generated/3.0.10/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.10/noble/entrypoint.sh b/generated/3.0.10/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.10/noble/entrypoint.sh +++ b/generated/3.0.10/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.10/trixie/entrypoint.sh b/generated/3.0.10/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.10/trixie/entrypoint.sh +++ b/generated/3.0.10/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.11/bookworm/entrypoint.sh b/generated/3.0.11/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.11/bookworm/entrypoint.sh +++ b/generated/3.0.11/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.11/bullseye/entrypoint.sh b/generated/3.0.11/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.11/bullseye/entrypoint.sh +++ b/generated/3.0.11/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.11/jammy/entrypoint.sh b/generated/3.0.11/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.11/jammy/entrypoint.sh +++ b/generated/3.0.11/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.11/noble/entrypoint.sh b/generated/3.0.11/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.11/noble/entrypoint.sh +++ b/generated/3.0.11/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.11/trixie/entrypoint.sh b/generated/3.0.11/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.11/trixie/entrypoint.sh +++ b/generated/3.0.11/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.12/bookworm/entrypoint.sh b/generated/3.0.12/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.12/bookworm/entrypoint.sh +++ b/generated/3.0.12/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.12/bullseye/entrypoint.sh b/generated/3.0.12/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.12/bullseye/entrypoint.sh +++ b/generated/3.0.12/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.12/jammy/entrypoint.sh b/generated/3.0.12/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.12/jammy/entrypoint.sh +++ b/generated/3.0.12/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.12/noble/entrypoint.sh b/generated/3.0.12/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.12/noble/entrypoint.sh +++ b/generated/3.0.12/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.12/trixie/entrypoint.sh b/generated/3.0.12/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.12/trixie/entrypoint.sh +++ b/generated/3.0.12/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.13/bookworm/entrypoint.sh b/generated/3.0.13/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.13/bookworm/entrypoint.sh +++ b/generated/3.0.13/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.13/bullseye/entrypoint.sh b/generated/3.0.13/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.13/bullseye/entrypoint.sh +++ b/generated/3.0.13/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.13/jammy/entrypoint.sh b/generated/3.0.13/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.13/jammy/entrypoint.sh +++ b/generated/3.0.13/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.13/noble/entrypoint.sh b/generated/3.0.13/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.13/noble/entrypoint.sh +++ b/generated/3.0.13/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.13/trixie/entrypoint.sh b/generated/3.0.13/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.13/trixie/entrypoint.sh +++ b/generated/3.0.13/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.14/bookworm/entrypoint.sh b/generated/3.0.14/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.14/bookworm/entrypoint.sh +++ b/generated/3.0.14/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.14/bullseye/entrypoint.sh b/generated/3.0.14/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.14/bullseye/entrypoint.sh +++ b/generated/3.0.14/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.14/jammy/entrypoint.sh b/generated/3.0.14/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.14/jammy/entrypoint.sh +++ b/generated/3.0.14/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.14/noble/entrypoint.sh b/generated/3.0.14/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.14/noble/entrypoint.sh +++ b/generated/3.0.14/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.14/trixie/entrypoint.sh b/generated/3.0.14/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.14/trixie/entrypoint.sh +++ b/generated/3.0.14/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.9/bookworm/entrypoint.sh b/generated/3.0.9/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.9/bookworm/entrypoint.sh +++ b/generated/3.0.9/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.9/bullseye/entrypoint.sh b/generated/3.0.9/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.9/bullseye/entrypoint.sh +++ b/generated/3.0.9/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.9/jammy/entrypoint.sh b/generated/3.0.9/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.9/jammy/entrypoint.sh +++ b/generated/3.0.9/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.9/noble/entrypoint.sh b/generated/3.0.9/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.9/noble/entrypoint.sh +++ b/generated/3.0.9/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/3.0.9/trixie/entrypoint.sh b/generated/3.0.9/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/3.0.9/trixie/entrypoint.sh +++ b/generated/3.0.9/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.0/bookworm/entrypoint.sh b/generated/4.0.0/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.0/bookworm/entrypoint.sh +++ b/generated/4.0.0/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.0/bullseye/entrypoint.sh b/generated/4.0.0/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.0/bullseye/entrypoint.sh +++ b/generated/4.0.0/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.0/jammy/entrypoint.sh b/generated/4.0.0/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.0/jammy/entrypoint.sh +++ b/generated/4.0.0/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.0/noble/entrypoint.sh b/generated/4.0.0/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.0/noble/entrypoint.sh +++ b/generated/4.0.0/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.0/trixie/entrypoint.sh b/generated/4.0.0/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.0/trixie/entrypoint.sh +++ b/generated/4.0.0/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.1/bookworm/entrypoint.sh b/generated/4.0.1/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.1/bookworm/entrypoint.sh +++ b/generated/4.0.1/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.1/bullseye/entrypoint.sh b/generated/4.0.1/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.1/bullseye/entrypoint.sh +++ b/generated/4.0.1/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.1/jammy/entrypoint.sh b/generated/4.0.1/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.1/jammy/entrypoint.sh +++ b/generated/4.0.1/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.1/noble/entrypoint.sh b/generated/4.0.1/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.1/noble/entrypoint.sh +++ b/generated/4.0.1/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.1/trixie/entrypoint.sh b/generated/4.0.1/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.1/trixie/entrypoint.sh +++ b/generated/4.0.1/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.2/bookworm/entrypoint.sh b/generated/4.0.2/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.2/bookworm/entrypoint.sh +++ b/generated/4.0.2/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.2/bullseye/entrypoint.sh b/generated/4.0.2/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.2/bullseye/entrypoint.sh +++ b/generated/4.0.2/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.2/jammy/entrypoint.sh b/generated/4.0.2/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.2/jammy/entrypoint.sh +++ b/generated/4.0.2/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.2/noble/entrypoint.sh b/generated/4.0.2/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.2/noble/entrypoint.sh +++ b/generated/4.0.2/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.2/trixie/entrypoint.sh b/generated/4.0.2/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.2/trixie/entrypoint.sh +++ b/generated/4.0.2/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.3/bookworm/entrypoint.sh b/generated/4.0.3/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.3/bookworm/entrypoint.sh +++ b/generated/4.0.3/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.3/bullseye/entrypoint.sh b/generated/4.0.3/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.3/bullseye/entrypoint.sh +++ b/generated/4.0.3/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.3/jammy/entrypoint.sh b/generated/4.0.3/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.3/jammy/entrypoint.sh +++ b/generated/4.0.3/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.3/noble/entrypoint.sh b/generated/4.0.3/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.3/noble/entrypoint.sh +++ b/generated/4.0.3/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.3/trixie/entrypoint.sh b/generated/4.0.3/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.3/trixie/entrypoint.sh +++ b/generated/4.0.3/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.4/bookworm/entrypoint.sh b/generated/4.0.4/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.4/bookworm/entrypoint.sh +++ b/generated/4.0.4/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.4/bullseye/entrypoint.sh b/generated/4.0.4/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.4/bullseye/entrypoint.sh +++ b/generated/4.0.4/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.4/jammy/entrypoint.sh b/generated/4.0.4/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.4/jammy/entrypoint.sh +++ b/generated/4.0.4/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.4/noble/entrypoint.sh b/generated/4.0.4/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.4/noble/entrypoint.sh +++ b/generated/4.0.4/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.4/trixie/entrypoint.sh b/generated/4.0.4/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.4/trixie/entrypoint.sh +++ b/generated/4.0.4/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.5/bookworm/entrypoint.sh b/generated/4.0.5/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.5/bookworm/entrypoint.sh +++ b/generated/4.0.5/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.5/bullseye/entrypoint.sh b/generated/4.0.5/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.5/bullseye/entrypoint.sh +++ b/generated/4.0.5/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.5/jammy/entrypoint.sh b/generated/4.0.5/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.5/jammy/entrypoint.sh +++ b/generated/4.0.5/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.5/noble/entrypoint.sh b/generated/4.0.5/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.5/noble/entrypoint.sh +++ b/generated/4.0.5/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.5/trixie/entrypoint.sh b/generated/4.0.5/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.5/trixie/entrypoint.sh +++ b/generated/4.0.5/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.6/bookworm/entrypoint.sh b/generated/4.0.6/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.6/bookworm/entrypoint.sh +++ b/generated/4.0.6/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.6/bullseye/entrypoint.sh b/generated/4.0.6/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.6/bullseye/entrypoint.sh +++ b/generated/4.0.6/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.6/jammy/entrypoint.sh b/generated/4.0.6/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.6/jammy/entrypoint.sh +++ b/generated/4.0.6/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.6/noble/entrypoint.sh b/generated/4.0.6/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.6/noble/entrypoint.sh +++ b/generated/4.0.6/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.6/trixie/entrypoint.sh b/generated/4.0.6/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.6/trixie/entrypoint.sh +++ b/generated/4.0.6/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.7/bookworm/entrypoint.sh b/generated/4.0.7/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.7/bookworm/entrypoint.sh +++ b/generated/4.0.7/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.7/bullseye/entrypoint.sh b/generated/4.0.7/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.7/bullseye/entrypoint.sh +++ b/generated/4.0.7/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.7/jammy/entrypoint.sh b/generated/4.0.7/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.7/jammy/entrypoint.sh +++ b/generated/4.0.7/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.7/noble/entrypoint.sh b/generated/4.0.7/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.7/noble/entrypoint.sh +++ b/generated/4.0.7/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/4.0.7/trixie/entrypoint.sh b/generated/4.0.7/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/4.0.7/trixie/entrypoint.sh +++ b/generated/4.0.7/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.0/bookworm/entrypoint.sh b/generated/5.0.0/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.0/bookworm/entrypoint.sh +++ b/generated/5.0.0/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.0/bullseye/entrypoint.sh b/generated/5.0.0/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.0/bullseye/entrypoint.sh +++ b/generated/5.0.0/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.0/jammy/entrypoint.sh b/generated/5.0.0/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.0/jammy/entrypoint.sh +++ b/generated/5.0.0/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.0/noble/entrypoint.sh b/generated/5.0.0/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.0/noble/entrypoint.sh +++ b/generated/5.0.0/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.0/trixie/entrypoint.sh b/generated/5.0.0/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.0/trixie/entrypoint.sh +++ b/generated/5.0.0/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.1/bookworm/entrypoint.sh b/generated/5.0.1/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.1/bookworm/entrypoint.sh +++ b/generated/5.0.1/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.1/bullseye/entrypoint.sh b/generated/5.0.1/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.1/bullseye/entrypoint.sh +++ b/generated/5.0.1/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.1/jammy/entrypoint.sh b/generated/5.0.1/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.1/jammy/entrypoint.sh +++ b/generated/5.0.1/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.1/noble/entrypoint.sh b/generated/5.0.1/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.1/noble/entrypoint.sh +++ b/generated/5.0.1/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.1/trixie/entrypoint.sh b/generated/5.0.1/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.1/trixie/entrypoint.sh +++ b/generated/5.0.1/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.2/bookworm/entrypoint.sh b/generated/5.0.2/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.2/bookworm/entrypoint.sh +++ b/generated/5.0.2/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.2/bullseye/entrypoint.sh b/generated/5.0.2/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.2/bullseye/entrypoint.sh +++ b/generated/5.0.2/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.2/jammy/entrypoint.sh b/generated/5.0.2/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.2/jammy/entrypoint.sh +++ b/generated/5.0.2/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.2/noble/entrypoint.sh b/generated/5.0.2/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.2/noble/entrypoint.sh +++ b/generated/5.0.2/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.2/trixie/entrypoint.sh b/generated/5.0.2/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.2/trixie/entrypoint.sh +++ b/generated/5.0.2/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.3/bookworm/entrypoint.sh b/generated/5.0.3/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.3/bookworm/entrypoint.sh +++ b/generated/5.0.3/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.3/bullseye/entrypoint.sh b/generated/5.0.3/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.3/bullseye/entrypoint.sh +++ b/generated/5.0.3/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.3/jammy/entrypoint.sh b/generated/5.0.3/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.3/jammy/entrypoint.sh +++ b/generated/5.0.3/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.3/noble/entrypoint.sh b/generated/5.0.3/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.3/noble/entrypoint.sh +++ b/generated/5.0.3/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.3/trixie/entrypoint.sh b/generated/5.0.3/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.3/trixie/entrypoint.sh +++ b/generated/5.0.3/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.4/bookworm/entrypoint.sh b/generated/5.0.4/bookworm/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.4/bookworm/entrypoint.sh +++ b/generated/5.0.4/bookworm/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.4/bullseye/entrypoint.sh b/generated/5.0.4/bullseye/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.4/bullseye/entrypoint.sh +++ b/generated/5.0.4/bullseye/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.4/jammy/entrypoint.sh b/generated/5.0.4/jammy/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.4/jammy/entrypoint.sh +++ b/generated/5.0.4/jammy/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.4/noble/entrypoint.sh b/generated/5.0.4/noble/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.4/noble/entrypoint.sh +++ b/generated/5.0.4/noble/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/generated/5.0.4/trixie/entrypoint.sh b/generated/5.0.4/trixie/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/generated/5.0.4/trixie/entrypoint.sh +++ b/generated/5.0.4/trixie/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba diff --git a/src/entrypoint.sh b/src/entrypoint.sh index 5a7f4e3..f249fd7 100644 --- a/src/entrypoint.sh +++ b/src/entrypoint.sh @@ -227,7 +227,11 @@ set_sysdba() { } # Requires FIREBIRD_PASSWORD if FIREBIRD_USER is set. +# Runs before any other initialization step, so an invalid configuration fails without changing anything. requires_user_password() { + read_from_file_or_env 'FIREBIRD_USER' + read_from_file_or_env 'FIREBIRD_PASSWORD' + if [ -n "$FIREBIRD_USER" ] && [ -z "$FIREBIRD_PASSWORD" ]; then # [Tabs ahead] cat >&2 <<-EOL @@ -243,11 +247,7 @@ requires_user_password() { # Create Firebird user. create_user() { - read_from_file_or_env 'FIREBIRD_USER' - read_from_file_or_env 'FIREBIRD_PASSWORD' - if [ -n "$FIREBIRD_USER" ]; then - requires_user_password echo "Creating user '$FIREBIRD_USER'..." local quoted_user @@ -398,6 +398,7 @@ run_daemon_and_wait() { # main() # if [ "$1" = 'firebird' ]; then + requires_user_password set_config set_sysdba