From 9df61b0ebee373c1578aa124da2c61dab2304ac1 Mon Sep 17 00:00:00 2001 From: Emre Date: Sat, 22 Aug 2026 22:51:25 +0300 Subject: [PATCH 1/4] ci: pin actions to commit shas and add dependabot Pins all five actions to full commit SHAs with version comments, so a retagged upstream release cannot change what runs. Adds dependabot for docker and github-actions on a weekly schedule with a 7 day cooldown, which keeps a freshly published version from being adopted immediately. Also moves the actions to current majors: checkout v4 to v7, setup-buildx v3 to v4, metadata v5 to v6, login v3 to v4, build-push v6 to v7. --- .github/dependabot.yml | 17 +++++++++++++++++ .github/workflows/build.yml | 10 +++++----- 2 files changed, 22 insertions(+), 5 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..bf3ef2e --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,17 @@ +version: 2 +updates: + - package-ecosystem: docker + directory: / + schedule: + interval: weekly + cooldown: + default-days: 7 + include: ["*"] + + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + cooldown: + default-days: 7 + include: ["*"] diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 3c2ec90..0421443 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -22,16 +22,16 @@ jobs: build: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check startup.sh parses run: bash -n startup.sh - - uses: docker/setup-buildx-action@v3 + - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: Compute tags id: meta - uses: docker/metadata-action@v5 + uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 with: images: ${{ env.IMAGE }} flavor: latest=false @@ -45,13 +45,13 @@ jobs: - name: Log in to Docker Hub if: github.event_name != 'pull_request' - uses: docker/login-action@v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Build and push - uses: docker/build-push-action@v6 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . platforms: linux/amd64 From a807295bac383fc78b4ab507ffe4ef6ba47400e3 Mon Sep 17 00:00:00 2001 From: Emre Date: Sat, 22 Aug 2026 22:51:25 +0300 Subject: [PATCH 2/4] feat: add MACHINE env var to select the qemu machine type The machine type was whatever the qemu build defaulted to, with no way to override it. Setting it lets a guest keep identical virtual hardware across a qemu upgrade, which matters for guests that treat a hardware change as significant. Defaults to empty so qemu keeps choosing and current behaviour is unchanged. --- startup.sh | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/startup.sh b/startup.sh index b3cc949..df94efe 100755 --- a/startup.sh +++ b/startup.sh @@ -25,6 +25,12 @@ if [ ! -d /data ]; then fi fi +if [ -n "$MACHINE" ]; then + echo "[machine]" + FLAGS_MACHINE="-machine ${MACHINE}" + echo "parameter: ${FLAGS_MACHINE}" +fi + if [ -n "$ACCEL" ]; then echo "[accel]" FLAGS_ACCEL="-accel ${ACCEL}" @@ -293,6 +299,7 @@ fi set -x exec ${QEMU_BINARY} \ + ${FLAGS_MACHINE} \ ${FLAGS_ACCEL} \ ${FLAGS_CPU} \ ${FLAGS_SMP} \ From cddab338b91bca71f19220f467a6b66372f5f405 Mon Sep 17 00:00:00 2001 From: Emre Date: Sat, 22 Aug 2026 22:51:25 +0300 Subject: [PATCH 3/4] feat: base the image on ubuntu 24.04 Moves qemu from 6.2 to 8.2.2 and picks up mature aio=io_uring and better multiqueue virtio-scsi handling. Ubuntu 22.04 standard support ends April 2027. Base is pinned by digest so rebuilds are reproducible and dependabot can propose the bump explicitly. The default machine type moves from pc-i440fx-6.2 to pc-i440fx-8.2, so guest visible hardware changes on the next restart after this ships in a release. Set MACHINE=pc-i440fx-6.2 to hold the old one. --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 2414f40..4a8dbd5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM ubuntu:22.04 +FROM ubuntu:24.04@sha256:33ceb71981b602c1a7443a53469e4dba065f7503eab3078a2d7a57a2ab987517 LABEL org.opencontainers.image.authors="Emre " RUN \ @@ -13,6 +13,7 @@ ADD startup.sh / ENV \ QEMU_BINARY=qemu-system-x86_64 \ + MACHINE="" \ RAM=2048 \ SMP=1 \ CPU=qemu64 \ From 92b14331e5bd3e31aa99c51138dad9565af6e965 Mon Sep 17 00:00:00 2001 From: Emre Date: Sat, 22 Aug 2026 22:58:20 +0300 Subject: [PATCH 4/4] fix: tag pull request builds metadata-action matched no rule on pull_request events, so it emitted no tags and warned "No Docker tag has been generated" on every PR. Adds type=ref,event=pr for a pr-N tag. PR builds still do not push. --- .github/workflows/build.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 0421443..1972a62 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -42,6 +42,7 @@ jobs: type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/v') }} type=edge,branch=main type=sha,prefix=main-,enable=${{ github.ref == 'refs/heads/main' }} + type=ref,event=pr - name: Log in to Docker Hub if: github.event_name != 'pull_request'