-
Notifications
You must be signed in to change notification settings - Fork 10
fix: remove shell wrap for exec form RUN commands
#242
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
fix: remove shell wrap for exec form RUN commands
#242
Conversation
Summary of ChangesHello @RoryDunne-Voyager, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request provides a crucial fix for the Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request correctly addresses the issue of shell-wrapping exec-form RUN commands, which is particularly problematic for shell-less images. The changes in earthfile2llb/converter.go are logical, and the addition of a test case using a distroless image is an excellent way to verify the fix. I have one suggestion to enhance the implementation by restoring debugger functionality for exec-form commands, which appears to be unintentionally disabled by the current changes.
c1ed62e to
2fd0150
Compare
tests/run-exec-form.earth
Outdated
| @@ -0,0 +1,5 @@ | |||
| VERSION 0.8 | |||
| FROM gcr.io/distroless/python3-debian12:latest | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you please bump debian to 13? To avoid @renovate-bot from bumping this to
| FROM gcr.io/distroless/python3-debian12:latest | |
| FROM gcr.io/distroless/python3-debian13@sha256:cc3bb44755599d4c25c26c43b05761eeb1da2e779172cee258c2202ca071abfa |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this digest hash correct? I'm seeing: gcr.io/distroless/python3-debian13@sha256:6a4de1cbdac6b94b74b71a33298a9c7fed918161ff686bd501bfe9454113ae58
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
My bad, sha provided by me is for distroless/java25-debian13. Please use the correct sha!
dfa8580 to
0ddadf3
Compare
0ddadf3 to
f4df92f
Compare
|
@RoryDunne-Voyager, can you please check the failing GHA jobs (all except Security / Go Vulnerabilities Report (push))? Your changes cause them. PS. Initially, I assumed that user permissions were causing the failures. |
Yes, sorry for not getting to this sooner, I'm going to move this PR to WIP to fix. |
RUN commandsRUN commands
RUN commandsRUN commands
An old issue: earthly#2618 reared up recently when trying to use a Docker Hardened Image.
I went and found that the
shellWrapfunction was always being called on the arguments passed to aRUNcommand so I added some guards for it. This does not affect things likeIFstatements or arg expansion. Though it could definitely be worth further discussion.