Ship the ionCube Loader in the image - #335
Conversation
A module can be installed into a running OpenMES through the admin panel, so
the stock image has to be able to run whatever a licensed module ships. A
module distributed as encoded PHP cannot run without the ionCube Loader, and
without it in the image, installing one would mean first swapping the whole
installation for a different image — which defeats the point of installing a
module through the panel at all.
The loader is inert without encoded files: it costs a couple of MB and does
nothing until something asks it to run one. That is why it goes in the stock
image rather than behind a build flag; a flag would split the distribution in
two and push the choice onto whoever builds, long before anyone knows which
modules the installation will get.
Alpine means the musl build. Two things are derived rather than assumed: the
architecture, because ionCube publishes no musl loader for arm64 and the step
is skipped there with everything else unaffected, and the PHP ABI, because
this image exposes PHP_VERSION but not its major/minor parts — hardcoding
`8.3` would silently install nothing on the next base-image bump.
`php -v | grep ionCube` ends the step, so a download that succeeds but
produces an unusable loader fails the build instead of shipping an image that
only breaks once a customer installs an encoded module.
Verified against php:8.3-fpm-alpine: arch x86_64, ABI 8.3, loader v15.5.1,
extension_loaded('ionCube Loader') true.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QRWsLoNeVWdsSHve6vUmxs
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: Mes-Open/OpenMes/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co to zmienia
backend/Dockerfileinstaluje loader ionCube (15.5.1, build musl) do obrazu backendu.Dlaczego w obrazie standardowym, a nie za flagą builda
Moduł wgrywa się do działającej instalacji przez panel (Admin → Moduły → Zainstaluj). Jeśli moduł jest rozprowadzany jako kod zakodowany ionCube'em, to bez loadera w obrazie jego instalacja oznacza najpierw podmianę całego obrazu instalacji — co przekreśla sens instalowania modułu przez panel.
Loader bez zakodowanych plików jest bezczynny: kosztuje kilka MB i nie robi nic, dopóki nic nie poprosi go o uruchomienie zakodowanego pliku. Flaga builda rozdzieliłaby dystrybucję na dwie i przeniosła decyzję na osobę budującą obraz — na długo przed tym, nim wiadomo, jakie moduły dostanie instalacja.
Dwie rzeczy wyprowadzane, nie zakładane
apk --print-archi na arm64 pomijany z komunikatem — reszta builda bez zmian. Konsekwencja do odnotowania: zakodowane moduły nie uruchomią się na Alpine/arm64.PHP_VERSION, ale niePHP_MAJOR_VERSION/PHP_MINOR_VERSION, więc ABI liczę przezphp -r. Wpisanie8.3na sztywno przy następnym podbiciu obrazu bazowego cicho nie zainstalowałoby niczego.Krok kończy się
php -v | grep -q 'ionCube', więc pobranie, które się udało, ale dało nieużywalny loader, wywala build — zamiast wypuścić obraz, który psuje się dopiero, gdy klient zainstaluje zakodowany moduł.Weryfikacja
Dokładna sekwencja komend uruchomiona w
php:8.3-fpm-alpine:Źródło:
downloads.ioncube.com/loader_downloads/ioncube_loaders_lin-musl_x86-64.tar.gz→ HTTP 200, 9 685 513 B; w archiwumioncube/ioncube_loader_lin-musl_8.3.so(2 390 464 B).Samo kodowanie jest poza tym PR — nie dotyka CI i nie wymaga żadnych sekretów.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QRWsLoNeVWdsSHve6vUmxs