Repository navigation
Conversation
Match the madison version field for Engine and CLI, preserving optional epochs, partial pins and Debian prerelease spelling. Add offline installer-flow regression coverage and a dedicated CI job. Inspired-by: docker#571 Signed-off-by: Su Yang <soulteary@users.noreply.github.com> (cherry picked from commit 149f5e5)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
- What I did
VERSION=24.0can select Docker 28.4.0 on Ubuntu noble because the current lookup searches an entireapt-cache madisonrow. The requested24.0matches24.04in5:28.4.0-1~ubuntu.24.04~noble, and the first row wins even though its Docker version is unrelated to the pin.Anchoring the lookup to the version field alone does not resolve all false positives:
VERSION=24.0.1can still match24.0.10, andVERSION=22.0can match22.02.1. The dots in the requested version are also treated as regular-expression wildcards.This PR matches a literal Docker version prefix at a component boundary within the package version field. A missing version follows the existing error path before Docker package installation.
- How I did it
24.0.1cannot select24.0.10.vshorthand, historical-cereleases, and pre-release forms. Docker's-separators are normalized to Debian's~spelling, including legacy-ce-rc1and modern-rc.1forms; direct~rc.1spelling also works.grepinterprets later fragments as additional expressions: a pin such asbogus\n24could match the Ubuntu suffix and incorrectly select 29.4.0.shandbash, and testing documentation.- How to verify it
The candidate is commit
61e13c3267d663d323e9addeb4f1dd3eb921e875, based directly on upstreammasterat2b32480025b223ebfddae9a3a8bef09027680f53.shandbashin an Ubuntu 24.04 container with networking disabled and a read-only repository mount. The tests execute the installer's APT installation flow against package-list fixtures, fix platform detection to Ubuntu noble, intercept repository/configuration operations, and record the final package installation arguments instead of executing them. Coverage includes independent Engine and CLI false positives, whitespace, optional epochs, partial pins, legacy releases, pre-releases through thetestchannel, unavailable versions, shell metacharacters, and embedded newlines.c57bd823was used only as a regression-control baseline. With the same fixture, it recordsdocker-ce=5:28.4.0-1~ubuntu.24.04~nobleforVERSION=24.0; the fix recordsdocker-ce=5:24.0.9-1~ubuntu.24.04~noble. This fork control is separate from the candidate's upstream base above.VERSION=24.0.1; this implementation selects 24.0.1.sh -nandbash -npass for the installer and regression script. ShellCheck 0.11.0 passes with the repository's existing exclusions, andgit diff --checkpasses.soulteary/docker-install, validating candidate commit61e13c3in the fork.The fixture suite establishes offline package selection: it does not download or install Docker packages or start the daemon. It does not establish repository availability or successful installation for every requested pin.
--dry-runstill does not resolve version pins and is not used as selection evidence. RPM selection, supported distributions, and mirrors are unchanged; the existing fallback when a separate CLI package is unavailable is retained.Source and provenance
Inspired by docker/docker-install#571, authored by fudianchn (付典), and its original signed-off commit. This is a fresh implementation extending the reported fix with literal matching, component boundaries, newline handling, and installer-flow regressions.
The candidate was cherry-picked with provenance from fork commit
149f5e5. It retains theSigned-off-by: Su Yang <soulteary@users.noreply.github.com>DCO trailer and the original fork commit reference in its commit message.- Description for the changelog
Match APT Docker version pins literally within the package version field at component boundaries.