Skip to content

Fix extensions requiring another extension, binaries with docker exec and upgrade Supercronic - #417

Merged
mistraloz merged 8 commits into
thecodingmachine:v5from
mistraloz:fix/extensions-path-and-supercronic
Oct 9, 2026
Merged

mistraloz merged 8 commits into
thecodingmachine:v5from
mistraloz:fix/extensions-path-and-supercronic

Conversation

@mistraloz

@mistraloz mistraloz commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This PR fixes :

  • Bug
  • Feature
  • Breaking changes

Depends on #416 (this branch contains its commits: merge #416 first).

  1. Memcached extension is not working in php8 images #321: extensions that require another extension. memcached could not be loaded (igbinary and msgpack
    not enabled), nor redis with igbinary disabled, mailparse without mbstring or swoole without curl.
    The extensions required by an enabled extension are now enabled with it, even when they are explicitly disabled,
    as was already done for mysqlnd. The dependencies are listed in a single table in setup_extensions.php.
  2. Cannot run Composer binaries without path anymore #363 / Use an absolute path for the global composer bin dir #310: Composer and NodeJS binaries with docker exec. Since Docker 23, docker exec (and
    docker compose exec) refuses to run a binary found with a relative path of the PATH (cannot run executable found relative to current directory): vendor/bin and node_modules/.bin were only added as relative paths, and
    the global Composer binaries were not found outside bash (~ is only expanded by bash). The absolute paths of the
    working directory and of the global Composer binaries are now added before the relative paths, which are kept.
  3. Vulnerabilities found #342: Supercronic is upgraded from 0.1.9 (built with Go 1.14, flagged by vulnerability scanners) to 0.2.49.
    SHA1 checked for amd64 and arm64. No option was removed; a new log line at startup (process reaping disabled, not pid 1) is expected.

Fixes #321
Fixes #363
Fixes #310

Test plan (required)

New tests: test_dependenciesOfExtensionsOnFat (php-extensions.sh) and test_composerBinaryWithDockerExec (new
tool-composer-bin.sh). Supercronic is covered by the existing tool-supercronic.sh.

Checklist

  • I followed the guidelines in CONTRIBUTING guide
  • I have squashed any insignificant commits
  • This change has comments for package types, values, functions, and non-obvious lines of code

…guration

The output of these scripts is written to generated_conf.ini and to the crontab,
or run by bash. A PHP warning (e.g. an extension that cannot be loaded) was
written in this output: syntax error in generated_conf.ini, supercronic exiting
on a "bad crontab line" and bash syntax errors stopping the container. The
warnings are now only logged.
…use sudo

"sudo -u www-data php ..." printed a sudo password error on each call, and
failed with "Unexpected PHP proxy output" when a PHP_* variable had changed
(the cache file is not writable by www-data). The proxy now runs PHP with the
current configuration when sudo is not available.

Fixes thecodingmachine#253
… account has it

The user running the commands is the owner of the working directory. When its ID
belongs to a system account of the image (e.g. 998 is systemd-network in Ubuntu
24.04, and the ID of the gitlab-runner user on many hosts), the commands were run
with this account: no home directory, no sudo ("touch ~/.startup_done:
Permission denied"). Setting DOCKER_USER to such an ID failed ("usermod: UID
'998' already exists").

The system account is now moved to a free ID, so that the docker user takes the
ID of the host user. Its ID is changed in /etc/passwd: usermod would also change
the owner of the files of its home directory ("/").

Also rename a test that had the same name as another one (only the last one was run).

Fixes thecodingmachine#408
memcached requires igbinary and msgpack, redis igbinary, mailparse mbstring and
swoole curl: enabled alone (or with the required extension disabled), the
extension could not be loaded ("undefined symbol: php_msgpack_serialize").
The required extensions are now enabled with it, like mysqlnd for mysqli,
pdo_mysql and swoole.

Fixes thecodingmachine#321
Since Docker 23, "docker exec" (and "docker compose exec") refuses to run a
binary found with a relative path of the PATH ("cannot run executable found
relative to current directory"): vendor/bin and node_modules/.bin were only
added as relative paths. The global Composer binaries were not found at all
outside bash ("~" is only expanded by bash).

The absolute paths of the working directory and of the global Composer binaries
are now added before the relative paths, which are kept for the other
directories.

Fixes thecodingmachine#363
Fixes thecodingmachine#310
Supercronic 0.1.9 (2019) was built with Go 1.14 and is reported by the
vulnerability scanners (e.g. CVE-2022-23806 in the Go standard library).
0.2.49 is built with Go 1.26.

Refs thecodingmachine#342
@mistraloz mistraloz added the bug Something isn't working label Oct 9, 2026
@mistraloz
mistraloz merged commit 7f260e7 into thecodingmachine:v5 Oct 9, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

1 participant