Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions ops/Dockerfile.db
Original file line number Diff line number Diff line change
Expand Up @@ -51,3 +51,4 @@ RUN rm -rf /tmp/* && \

# Run schema/init on first database startup.
COPY db/*.sql /docker-entrypoint-initdb.d/
RUN chmod 0644 /docker-entrypoint-initdb.d/*.sql
49 changes: 49 additions & 0 deletions tests/cli/test_deterministic_images.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
from __future__ import annotations

import re
from pathlib import Path


Expand All @@ -22,6 +23,54 @@ def test_python_runtime_images_install_only_from_committed_uv_lock():
assert "sha256sum" in dockerfile


def test_database_image_makes_init_scripts_world_readable_and_non_executable():
instructions = [
line.strip()
for line in (ROOT / "ops/Dockerfile.db").read_text().splitlines()
if line.strip() and not line.lstrip().startswith("#")
]

copy_index = next(
(
index
for index, instruction in enumerate(instructions)
if re.fullmatch(
r"COPY\s+db/\*\.sql\s+/docker-entrypoint-initdb\.d/?",
instruction,
re.IGNORECASE,
)
),
None,
)
assert copy_index is not None

chmod_pattern = re.compile(
r"RUN\s+chmod\s+(?P<mode>0?[0-7]{3})\s+"
r"/docker-entrypoint-initdb\.d/\*\.sql",
re.IGNORECASE,
)
chmod_instruction = next(
(
(index, match)
for index, instruction in enumerate(instructions)
if (match := chmod_pattern.fullmatch(instruction))
),
None,
)

assert chmod_instruction is not None
chmod_index, chmod_match = chmod_instruction
assert copy_index < chmod_index
assert not any(
"/docker-entrypoint-initdb.d" in instruction
for instruction in instructions[chmod_index + 1 :]
)

mode = int(chmod_match.group("mode"), 8)
assert mode & 0o444 == 0o444
assert mode & 0o111 == 0


def test_uv_lock_covers_runtime_and_channel_only_dependencies():
lock = (ROOT / "uv.lock").read_text()

Expand Down