Files
fips/packaging/debian
Johnathan Corgan 01be207274 Embed the source revision in container-built binaries again
The build image had no git, so build.rs could not read the revision and every
binary built through the container carried none: -V printed only the version.
The image now installs git, and trusts the source mounted at /src, which is
owned by the host user while the build runs as root; without that entry git
refuses the repository and the revision is silently empty just the same.

The image tag now includes a hash of Dockerfile.build. Before, the tag named
only the floor image and the toolchain, so a host with the image cached kept
using it after the Dockerfile changed, and this change would never have
reached it.

A build from a git worktree still has no revision, because the worktree's git
directory is outside the mounted tree. That is documented, with the -V
reference noting that the revision is omitted when it could not be read,
rather than worked around; release and CI builds use full checkouts.
2026-09-19 10:08:39 +00:00
..