mirror of
https://github.com/IfcOpenShell/IfcOpenShell.git
synced 2026-08-05 23:41:44 +00:00
316dace11a
Dockerfile (renamed from Dockerfile_init, Dockerfile_update removed):
- Run as a non-root `builder` user matching the host UID/GID (passed as
--build-arg by create() from id -u/id -g), so build output under the
bind mount stays owned by the host user instead of root.
- Fix CCACHE_MAXSIZE: `ccache -M 5G` wrote its limit to a config file
under /ccache at image-build time, but /ccache is a volume mount
point, so that file gets shadowed by the (empty) volume the moment
the container actually runs - the cap never took effect. Set
CCACHE_MAXSIZE=5G as an image ENV instead.
- Dedupe ccache/libffi-devel, add --setopt=install_weak_deps=False
--setopt=tsflags=nodocs, add `git lfs install --system`, combine the
dnf update+install into one layer.
- Drop Dockerfile_update: it built FROM its own previous output, so
every `update` call made the image strictly larger forever (Docker
layers are append-only, `dnf clean` in a later layer can't shrink an
earlier one). `update` now just calls create(), which already runs
`dnf update -y` FROM a clean rockylinux:9 every time.
compose.yaml: pin platform: linux/amd64 so this doesn't silently run
under emulation on an ARM host.
ifcos_env:
- Split the previously-conflated stop/down into six distinct,
Compose-native lifecycle commands: up (create-or-start), down
(remove), stop, start, restart (stop+start, same container),
recreate (down+up, fresh container). Previously `stop` was aliased
to `down`, which silently removed the container instead of pausing
it.
- Implement try(): copies the built wrapper into a real Blender/Bonsai
install for manual testing, reading the target from a new
BLENDER_USER_RESOURCE .env variable and auto-detecting the built
Python version (disambiguating via PY_TGT for multi-version builds).
Deliberately kept human-only - it mutates a live Blender install, so
it shouldn't run unattended as part of an automated/AI workflow,
which should instead copy the wrapper into the repo's own
src/ifcopenshell-python/ifcopenshell/ (documented in SKILL.md).
- Fix unique(): the "has .env already got a UNIQUE_ID line" check
referenced an unset $FILE instead of $ENV_FILE, so it always
evaluated true and appended a fresh "UNIQUE_ID=dummy" line to .env
on every single `up`.
- Minor: differentiate remove()'s log message from down()'s (no longer
identical now that they're distinct operations), tidy help text
alignment and a stray double-space typo in clean().
SKILL.md: rewritten as current-state documentation (no more "fixed in
this copy" changelog framing) covering the above, plus a migration
note for anyone hitting root-owned leftovers from an older image.
Verified by actually building the image and driving every new
lifecycle command (stop/start/restart keep the same container ID;
down+up and recreate produce a new one) and try() (including the
quoted-tilde BLENDER_USER_RESOURCE edge case) against the real container.
Generated with the assistance of an AI coding tool.
(cherry picked from commit 92c50ed3b4)
57 lines
2.6 KiB
Docker
57 lines
2.6 KiB
Docker
FROM rockylinux:9
|
|
|
|
# Update system, enable CRB (needed by some EPEL packages) and install EPEL,
|
|
# then install required packages + some common tools for a bit of command
|
|
# line comfort. Combined into one layer so a later `create` always installs
|
|
# against packages from the same dnf update, rather than layering fresh
|
|
# installs on top of a stale cached "update" layer.
|
|
RUN dnf update -y && \
|
|
dnf install -y epel-release && \
|
|
dnf config-manager --set-enabled crb && \
|
|
dnf install -y --allowerasing --setopt=install_weak_deps=False --setopt=tsflags=nodocs \
|
|
bash-completion vim git curl wget which tree htop sudo \
|
|
gcc gcc-c++ autoconf automake bison make zip cmake \
|
|
python3 python3-pip \
|
|
bzip2 patch mesa-libGL-devel libffi-devel fontconfig-devel \
|
|
sqlite-devel bzip2-devel zlib-devel openssl-devel xz-devel \
|
|
readline-devel ncurses-devel libuuid-devel git-lfs \
|
|
findutils xz byacc ccache && \
|
|
git lfs install --system && \
|
|
dnf clean all && \
|
|
rm -rf /var/cache/dnf
|
|
|
|
# Trust bind-mounted repos regardless of which user (root or builder) or host
|
|
# UID owns them, rather than a per-user config that only one of them sees.
|
|
RUN git config --system --add safe.directory '*'
|
|
|
|
# Configure ccache. CCACHE_MAXSIZE (not `ccache -M`) because /ccache is a
|
|
# volume mount point at runtime - anything `ccache -M` writes to a config
|
|
# file under it during this build gets shadowed once the real volume is
|
|
# mounted, so the size cap only actually takes effect via the env var.
|
|
ENV CCACHE_DIR=/ccache
|
|
ENV CCACHE_MAXSIZE=5G
|
|
ENV PATH="/usr/lib/ccache:$PATH"
|
|
|
|
# Non-root user matching the host UID/GID that bind-mounts the repo (default
|
|
# 1000:1000, the common single-user-Linux-box case), so files the build
|
|
# creates under the mount keep sane, non-root ownership on the host side.
|
|
# Override with --build-arg USER_UID=$(id -u) --build-arg USER_GID=$(id -g)
|
|
# if your host user has a different UID/GID.
|
|
ARG USER_UID=1000
|
|
ARG USER_GID=1000
|
|
RUN groupadd -g "${USER_GID}" builder \
|
|
&& useradd -m -u "${USER_UID}" -g "${USER_GID}" -s /bin/bash builder \
|
|
&& echo "builder ALL=(ALL) NOPASSWD:ALL" > /etc/sudoers.d/builder
|
|
|
|
# Copied while still root: /bin is not writable by the builder user.
|
|
COPY --from=ghcr.io/astral-sh/uv:0.11.27 /uv /uvx /bin/
|
|
|
|
USER builder
|
|
WORKDIR /__w/IfcOpenShell/IfcOpenShell
|
|
|
|
# Installed as builder so managed Python interpreters land under builder's
|
|
# $HOME, matching the user that actually runs the build.
|
|
RUN uv python install
|
|
|
|
CMD ["sleep", "infinity"]
|