Conversation
Contributor
Size Analysis1 component analyzed, 1 component processing iOS Builds
Android Builds
|
Contributor
📲 Install BuildsiOS
Android
|
The container healthchecks used CMD-SHELL and the IPA integration test shelled out to unzip. Neither exists in a distroless image. Use exec-form healthchecks that probe the health file with python3, and read the generated IPA with zipfile. Behaviour is unchanged on the current image. Refs SEC-1090 Co-Authored-By: Claude <noreply@anthropic.com>
Both tools were launched through the shell wrappers that ship with them: a generated /bin/sh shim for bundletool and the upstream /bin/bash launcher for apksigner. A distroless image has no shell, so run the jars with java -jar instead and stop installing the wrappers. apksigner keeps the -Xmx1024M its launcher passed. keytool is resolved next to the java we picked. Refs SEC-1090 Co-Authored-By: Claude <noreply@anthropic.com>
IPA generation ran `zip -r -y` and extensionless files were typed with file(1); neither binary is present in a distroless image. Add zip_directory(), which reproduces what Info-ZIP wrote for us: symlink entries, unix permissions and explicit directory entries. Detect file types from magic bytes instead, covering the categories the previous mapping recognised (Mach-O, ELF and shebangs, Hermes bytecode, text, empty, symlink, directory). Anything else is reported as unknown, where before libmagic's free-text description was passed through; nothing downstream matched on that text. Refs SEC-1090 Co-Authored-By: Claude <noreply@anthropic.com>
oioki
force-pushed
the
alextarasov/sec-1090-launchpad
branch
from
September 28, 2026 19:51
b354e08 to
c255464
Compare
The Apple download size estimate zipped the bundle with `zip -q -r` and parsed the totals out of `unzip -v` output. Neither binary exists in a distroless image, so build the archive with zip_directory() and sum the compressed sizes from the central directory. Info-ZIP also writes UT and ux extra fields into every header, 52 bytes per entry across the local and central records. Those bytes counted as metadata before, so add them back explicitly: reported download sizes stay identical and size comparisons spanning this change do not shift. Refs SEC-1090 Co-Authored-By: Claude <noreply@anthropic.com>
oioki
force-pushed
the
alextarasov/sec-1090-launchpad
branch
from
September 28, 2026 20:38
c255464 to
ac2248d
Compare
oioki
commented
Sep 28, 2026
| metadata_size = total_zip_size - total_compressed | ||
| # Metadata is everything that isn't payload: headers, names, central directory, EOCD. | ||
| # Compressed bytes sit in both terms and cancel, so the compression level can't skew this. | ||
| metadata_size = total_zip_size - total_compressed + _INFOZIP_EXTRA_FIELD_BYTES_PER_ENTRY * len(infos) |
Member
Author
There was a problem hiding this comment.
This _INFOZIP_EXTRA_FIELD_BYTES_PER_ENTRY * len(infos) is a correction term to keep the stats intact after moving from zip binary to pythonic zipfile module. Maybe we could drop it and allow one-time drift for more correct reporting?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remove every dependency on a shell and on OS utilities that a distroless base image does not ship:
zip,unzip,file(1), and thesh/bashlauncher scripts that wrap the bundletool and apksigner jars.This is the first step of moving launchpad onto a Docker Hardened Image (SEC-1090). It is independent of the base image change and safe to land on its own: everything here behaves identically on the current
python:3.14-slim-bookwormimage, and it unblocks the multi-stage DHI Dockerfile that follows.The commits are ordered by how much discussion they are likely to need, so they can be reviewed — or dropped — separately:
build:exec-form container healthchecks, and the IPA test reads the archive withzipfile. Mechanical.ref(android):run the jars withjava -jarinstead of through their shell launchers, and stop installing those launchers inscripts/deps. Same JVM, same jars, same flags. Note for local dev: after re-runningscripts/deps,bundletoolandapksignerare no longer onPATHas commands; only the jars are installed.ref(size):zip_directory()replaceszip -r -yfor IPA generation, and file types for extensionless files are sniffed from magic bytes instead offile(1). Unrecognised files now reportunknownrather than libmagic's free-text description; nothing downstream matched on that text.ref(size):the Apple download-size estimate no longer parsesunzip -voutput. This is the one worth a careful look — it touches a customer-visible number. Info-ZIP writes UT and ux extra fields into every header (52 bytes per entry across the local and central records) which counted toward the metadata size, so the constant is added back explicitly to keep reported download sizes byte-identical. The alternative is to drop the constant and accept a one-time shift of a few KB in reported sizes; that felt worse mid-rollout, when base and head builds would be produced by different images, but I am happy to change it.Verified: the full unit and integration suite passes at each of the four commits, and the affected tests also pass inside the built Linux image (
docker build --build-arg TEST_BUILD=true), which exercises the realjava -jarpaths.Refs SEC-1090