mariadb: entrypoint hardcodes _mariadb_version() to 11.5.2, silently disabling upgrade detection
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 75/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- docker, mariadb, shell
- Ambito
- databases, devops, infrastructure
Direzione di ricerca
Il problema si trova in mariadb-13.1/docker-entrypoint.sh riga 230, dove _mariadb_version() restituisce una stringa hardcoded. La correzione comporta l'aggiornamento della pipeline YAML per sostituire il segnaposto %%MARIADB_VERSION_BASIC%% con la versione effettiva del pacchetto. Inizia esaminando il file mariadb-13.1.yaml intorno alla riga 278 per comprendere il passaggio di copia corrente, quindi applica la sostituzione sed suggerita. Verifica la correzione compilando il pacchetto e controllando che lo script di entrypoint generato contenga la versione corretta e nessun segnaposto residuo.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
mariadb-13.1/docker-entrypoint.sh:230 returns 11.5.2-MariaDB while the package builds 13.1.1. _check_if_upgrade_is_needed() compares the datadir's mariadb_upgrade_info stamp against that and nothing else, so the real test is "older than 11.5". Any datadir from 11.5 up is skipped and MARIADB_AUTO_UPGRADE=1 is a no-op.
Upstream keeps the line as %%MARIADB_VERSION_BASIC%%-MariaDB and substitutes per branch in update.sh. This copy was vendored from the substituted 11.5/ output (#26785, #31170) rather than the template, so it froze.
Reproduction
docker volume create repro
docker run -d --name seed -v repro:/var/lib/mysql \
-e MARIADB_ALLOW_EMPTY_ROOT_PASSWORD=yes mariadb:11.8
# wait for "ready for connections"
docker exec seed mariadb --protocol=socket -uroot -e "CREATE DATABASE main"
docker stop seed
docker run --rm -v repro:/d --user 0 --entrypoint /bin/sh \
cgr.dev/chainguard/mariadb:latest -c 'chown -R 65532:65532 /d'
docker run -d --name repro -v repro:/var/lib/mysql \
-e MARIADB_ALLOW_EMPTY_ROOT_PASSWORD=yes -e MARIADB_AUTO_UPGRADE=1 \
cgr.dev/chainguard/mariadb:latest
$ docker logs repro | grep -i upgrade
[Note] [Entrypoint]: MariaDB upgrade not required
$ docker exec repro cat /var/lib/mysql/mariadb_upgrade_info
11.8.9-MariaDB # server is 13.1.1
$ docker exec repro mariadb --protocol=socket -uroot -e "CREATE PROCEDURE main.p() SELECT 1"
ERROR 1558 (HY000): Column count of mysql.proc is wrong. Expected 22, found 21.
Created with MariaDB 110809, now running 130101. Please use mariadb-upgrade to fix this error
mysql.proc is the only table that differs from a correctly upgraded instance — 13.1 added path. Stored routines are unusable; grants are fine. A different version pairing would strand a different table. Correcting only _mariadb_version() upgrades the same datadir cleanly.
Recurrence
#78623 (mariadb-12.2 stream, octo-sts[bot], open) adds the same literal, so the stream generator is seeding from a pre-substituted copy. Fixing 13.1 alone won't hold.
Suggested fix
Restore the upstream placeholder and substitute it in the -oci-entrypoint pipeline, mirroring update.sh. Verified by hand at 13.1.1: the shipped file changes by exactly one line and no placeholders remain.
--- a/mariadb-13.1/docker-entrypoint.sh
+++ b/mariadb-13.1/docker-entrypoint.sh
@@ -227,7 +227,7 @@
}
_mariadb_version() {
- echo -n "11.5.2-MariaDB"
+ echo -n "%%MARIADB_VERSION_BASIC%%-MariaDB"
}
# initializes the database directory
--- a/mariadb-13.1.yaml
+++ b/mariadb-13.1.yaml
@@ -278,9 +278,16 @@
pipeline:
- runs: |
mkdir -p ${{targets.subpkgdir}}/usr/local/bin/
- cp docker-entrypoint.sh ${{targets.subpkgdir}}/usr/local/bin/
- chmod +x ${{targets.subpkgdir}}/usr/local/bin/docker-entrypoint.sh
+ out="${{targets.subpkgdir}}/usr/local/bin/docker-entrypoint.sh"
+ # Upstream ships this as a template and substitutes the version per
+ # branch in update.sh. Do the same rather than vendoring a
+ # pre-substituted copy: the value feeds _check_if_upgrade_is_needed(),
+ # so a stale literal silently disables upgrade detection.
+ sed -e 's!%%MARIADB_VERSION_BASIC%%!${{package.version}}!g' \
+ docker-entrypoint.sh > "$out"
+ chmod +x "$out"
+ if grep -q '%%MARIADB_' "$out"; then
+ echo "unsubstituted placeholder left in $out" >&2
+ exit 1
+ fi
Filing as an issue rather than a PR per the note in .github/pull-request-template.md. Filed here rather than chainguard-images/images since the script ships via the mariadb-*-oci-entrypoint apk. Separately, this copy has drifted ~18 months from upstream on top of two intentional local changes (date without --rfc-3339, --basedir=/usr); re-vendoring would fix that too but is a much larger change, so I have kept it out of scope here.
- Lingua principale
- Shell
- Stelle
- 1.3k
- Fork
- 443
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di wolfi-dev/os
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
py3-ecdsa: add new packageAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
-
needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
needs-triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 68/100
Tutte le issue di wolfi-dev/os
Issue simili
-
Feature Needs Triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
project-chip/certification-tool#1154 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
beehive-lab/TornadoVM#1151 ·
I maintainer di solito rispondono entro 1 giorno
-
writing-plans: user-facing text that describes app behaviour should cite the code it describesAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
obra/superpowers#2433 ·
I maintainer di solito rispondono entro 5 giorni
-
area/release kind/bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
kubernetes-sigs/kueue#16455 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno