Skip to content

Ship the ionCube Loader in the image - #335

Merged
jakub-przepiora merged 1 commit into
developfrom
feat/ioncube-loader
Oct 3, 2026
Merged

jakub-przepiora merged 1 commit into
developfrom
feat/ioncube-loader

Conversation

@jakub-przepiora

Copy link
Copy Markdown
Contributor

Co to zmienia

backend/Dockerfile instaluje loader ionCube (15.5.1, build musl) do obrazu backendu.

Dlaczego w obrazie standardowym, a nie za flagą builda

Moduł wgrywa się do działającej instalacji przez panel (Admin → Moduły → Zainstaluj). Jeśli moduł jest rozprowadzany jako kod zakodowany ionCube'em, to bez loadera w obrazie jego instalacja oznacza najpierw podmianę całego obrazu instalacji — co przekreśla sens instalowania modułu przez panel.

Loader bez zakodowanych plików jest bezczynny: kosztuje kilka MB i nie robi nic, dopóki nic nie poprosi go o uruchomienie zakodowanego pliku. Flaga builda rozdzieliłaby dystrybucję na dwie i przeniosła decyzję na osobę budującą obraz — na długo przed tym, nim wiadomo, jakie moduły dostanie instalacja.

Dwie rzeczy wyprowadzane, nie zakładane

  • Architektura. ionCube nie publikuje loadera musl dla arm64 (tylko glibc). Krok jest osłonięty apk --print-arch i na arm64 pomijany z komunikatem — reszta builda bez zmian. Konsekwencja do odnotowania: zakodowane moduły nie uruchomią się na Alpine/arm64.
  • ABI PHP. Ten obraz wystawia PHP_VERSION, ale nie PHP_MAJOR_VERSION/PHP_MINOR_VERSION, więc ABI liczę przez php -r. Wpisanie 8.3 na sztywno przy następnym podbiciu obrazu bazowego cicho nie zainstalowałoby niczego.

Krok kończy się php -v | grep -q 'ionCube', więc pobranie, które się udało, ale dało nieużywalny loader, wywala build — zamiast wypuścić obraz, który psuje się dopiero, gdy klient zainstaluje zakodowany moduł.

Weryfikacja

Dokładna sekwencja komend uruchomiona w php:8.3-fpm-alpine:

arch=x86_64 abi=8.3
    with the ionCube PHP Loader v15.5.1, Copyright (c) 2002-2026, by ionCube Ltd.
bool(true)   // extension_loaded("ionCube Loader")

Źródło: downloads.ioncube.com/loader_downloads/ioncube_loaders_lin-musl_x86-64.tar.gz → HTTP 200, 9 685 513 B; w archiwum ioncube/ioncube_loader_lin-musl_8.3.so (2 390 464 B).

Samo kodowanie jest poza tym PR — nie dotyka CI i nie wymaga żadnych sekretów.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QRWsLoNeVWdsSHve6vUmxs

A module can be installed into a running OpenMES through the admin panel, so
the stock image has to be able to run whatever a licensed module ships. A
module distributed as encoded PHP cannot run without the ionCube Loader, and
without it in the image, installing one would mean first swapping the whole
installation for a different image — which defeats the point of installing a
module through the panel at all.

The loader is inert without encoded files: it costs a couple of MB and does
nothing until something asks it to run one. That is why it goes in the stock
image rather than behind a build flag; a flag would split the distribution in
two and push the choice onto whoever builds, long before anyone knows which
modules the installation will get.

Alpine means the musl build. Two things are derived rather than assumed: the
architecture, because ionCube publishes no musl loader for arm64 and the step
is skipped there with everything else unaffected, and the PHP ABI, because
this image exposes PHP_VERSION but not its major/minor parts — hardcoding
`8.3` would silently install nothing on the next base-image bump.

`php -v | grep ionCube` ends the step, so a download that succeeds but
produces an unusable loader fails the build instead of shipping an image that
only breaks once a customer installs an encoded module.

Verified against php:8.3-fpm-alpine: arch x86_64, ABI 8.3, loader v15.5.1,
extension_loaded('ionCube Loader') true.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QRWsLoNeVWdsSHve6vUmxs
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (1)
  • cla-signed

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: Mes-Open/OpenMes/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 089319d0-3cd4-4089-bc67-b69f1a066cdc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jakub-przepiora
jakub-przepiora merged commit 385d0d2 into develop Oct 3, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant