mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: pin Terraform 1.15.5 for all Nix platforms (#25799)
The terraform_1_15_5 derivation previously only handled linux/amd64, falling through to unstablePkgs.terraform on all other platforms. On macOS this meant a different Terraform version was used, which caused the version check in make pre-commit to trigger generate.sh, regenerating all testdata with the host platform's OS/arch (darwin/arm64) instead of the committed linux/amd64 values. Three changes: 1. `flake.nix`: add explicit linux_arm64, darwin_arm64, and darwin_amd64 cases with SHA256 hashes from the official HashiCorp release. Unknown platforms still fall back to unstablePkgs.terraform. 2. `provisioner/terraform/testdata/generate.sh`: guard full regeneration behind a Linux-only check. The committed testdata encodes linux/amd64 values from the coder_provisioner data source, so regenerating on macOS would permanently bake in darwin/arm64. The --check path still runs on all platforms so the version target can detect provider mismatches. Regeneration via CI or an explicit Linux run is unchanged. 3. `scripts/release/check_commit_metadata.sh`: fix a shfmt (>=3.13) false positive. The [install.sh] key in an associative array literal was parsed as floating-point arithmetic (a zsh-only feature). Moving it to a post-declaration assignment satisfies the stricter parser without changing runtime behavior. <!-- If you have used AI to produce some or all of this PR, please ensure you have read our [AI Contribution guidelines](https://coder.com/docs/about/contributing/AI_CONTRIBUTING) before submitting. --> Linear: DOCS-279
This commit is contained in:
@@ -148,15 +148,36 @@
|
|||||||
vendorHash = "sha256-OuQWmZmofdJKq1hvk43RPkILQwAuFzqhmB22Xf6Z3lA=";
|
vendorHash = "sha256-OuQWmZmofdJKq1hvk43RPkILQwAuFzqhmB22Xf6Z3lA=";
|
||||||
};
|
};
|
||||||
|
|
||||||
# Keep Terraform aligned with provisioner/terraform/testdata/version.txt
|
# Pin to provisioner/terraform/testdata/version.txt for deterministic
|
||||||
# so `make gen` remains deterministic in Nix shells.
|
# `make gen` across platforms.
|
||||||
terraform_1_15_5 =
|
terraform_1_15_5 =
|
||||||
if pkgs.stdenv.isLinux && pkgs.stdenv.hostPlatform.isx86_64 then
|
let
|
||||||
|
releases = {
|
||||||
|
x86_64-linux = {
|
||||||
|
platform = "linux_amd64";
|
||||||
|
hash = "sha256-cCshNq9nKMj/A3+EPdLbzit62IeGtzgdHXKu+iUPYBw=";
|
||||||
|
};
|
||||||
|
aarch64-linux = {
|
||||||
|
platform = "linux_arm64";
|
||||||
|
hash = "sha256-Bue0jegmFGxtkzG6NbE9oSMy2Dkr4w0d1reJukcT//A=";
|
||||||
|
};
|
||||||
|
aarch64-darwin = {
|
||||||
|
platform = "darwin_arm64";
|
||||||
|
hash = "sha256-ARN2YFEABbkYu6ghVIZvvqxDkxY9gnfCq+hh37WELDw=";
|
||||||
|
};
|
||||||
|
x86_64-darwin = {
|
||||||
|
platform = "darwin_amd64";
|
||||||
|
hash = "sha256-NofQfANLPn3u1bByzYris0g1vLE5uuw/xPX9U02r9e0=";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
target = releases.${system} or null;
|
||||||
|
in
|
||||||
|
if target != null then
|
||||||
pkgs.runCommand "terraform-1.15.5" {
|
pkgs.runCommand "terraform-1.15.5" {
|
||||||
nativeBuildInputs = [ pkgs.unzip ];
|
nativeBuildInputs = [ pkgs.unzip ];
|
||||||
src = pkgs.fetchurl {
|
src = pkgs.fetchurl {
|
||||||
url = "https://releases.hashicorp.com/terraform/1.15.5/terraform_1.15.5_linux_amd64.zip";
|
url = "https://releases.hashicorp.com/terraform/1.15.5/terraform_1.15.5_${target.platform}.zip";
|
||||||
hash = "sha256-cCshNq9nKMj/A3+EPdLbzit62IeGtzgdHXKu+iUPYBw=";
|
hash = target.hash;
|
||||||
};
|
};
|
||||||
} ''
|
} ''
|
||||||
mkdir -p "$out/bin"
|
mkdir -p "$out/bin"
|
||||||
|
|||||||
+11
@@ -140,6 +140,17 @@ if [[ " $* " == *" --check "* ]]; then
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Committed testdata encodes linux/amd64 values from coder_provisioner.
|
||||||
|
# Regenerating elsewhere bakes in the host OS/arch.
|
||||||
|
if [[ "$(uname)" != "Linux" ]]; then
|
||||||
|
if ((upgrade)); then
|
||||||
|
echo "ERROR: --upgrade is not supported on $(uname); run on Linux or via CI."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "Note: skipping testdata regeneration on $(uname); regenerate on Linux or via CI."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
# Filter flags from positional args to get directory names.
|
# Filter flags from positional args to get directory names.
|
||||||
declare -a dirs=()
|
declare -a dirs=()
|
||||||
for arg in "$@"; do
|
for arg in "$@"; do
|
||||||
|
|||||||
@@ -78,7 +78,6 @@ main() {
|
|||||||
[enterprise]="Enterprise"
|
[enterprise]="Enterprise"
|
||||||
[examples]="Examples"
|
[examples]="Examples"
|
||||||
[helm]="Helm"
|
[helm]="Helm"
|
||||||
[install.sh]="Installer"
|
|
||||||
[provisionersdk]="SDK"
|
[provisionersdk]="SDK"
|
||||||
[provisionerd]="Provisioner"
|
[provisionerd]="Provisioner"
|
||||||
[provisioner]="Provisioner"
|
[provisioner]="Provisioner"
|
||||||
@@ -88,6 +87,8 @@ main() {
|
|||||||
[support]="Support"
|
[support]="Support"
|
||||||
[tailnet]="Networking"
|
[tailnet]="Networking"
|
||||||
)
|
)
|
||||||
|
# shfmt (>=3.13) parses [install.sh] as floating-point arithmetic in array literals.
|
||||||
|
humanized_areas["install.sh"]="Installer"
|
||||||
|
|
||||||
# Get hashes for all cherry-picked commits between the selected ref
|
# Get hashes for all cherry-picked commits between the selected ref
|
||||||
# and main. These are sorted by commit title so that we can group
|
# and main. These are sorted by commit title so that we can group
|
||||||
|
|||||||
Reference in New Issue
Block a user