#!/usr/bin/env bash # CMake, pinned, from Kitware's own download host. # # Shared by all four build images (docker/*/Dockerfile). The build context is docker/, so each # Dockerfile reaches this with COPY common/. Version inputs come from that Dockerfile's ARGs. # # The distro CMake is deliberately NOT installed: the four base images ship three different # versions (EL8 3.26.5, EL9 3.31.8, Jammy 3.22, Noble 3.28.3), and they move under us at every # base-image refresh. That spread is what makes a configure fail on one image and pass on the # next -- policy defaults and FetchContent behaviour both depend on it. One pinned CMake # everywhere removes the whole class of problem, and it is the only such tool the build cannot # pin from inside the repository. # # cmake.org rather than the GitHub release asset: the images already fetch everything else from # GitHub, and GitHub throttles unauthenticated downloads by TLS fingerprint. set -eux : "${CMAKE_VERSION:?set CMAKE_VERSION}" : "${CMAKE_SHA256:?set CMAKE_SHA256}" series=${CMAKE_VERSION%.*} tarball=cmake-${CMAKE_VERSION}-linux-x86_64.tar.gz cd /tmp curl -fLO "https://cmake.org/files/v${series}/${tarball}" echo "${CMAKE_SHA256} ${tarball}" | sha256sum -c - mkdir -p "/opt/cmake-${CMAKE_VERSION}" tar -xzf "${tarball}" -C "/opt/cmake-${CMAKE_VERSION}" --strip-components=1 rm -f "${tarball}" # The Dockerfile puts /opt/cmake-$CMAKE_VERSION/bin on PATH; check the pin took. test "$("/opt/cmake-${CMAKE_VERSION}/bin/cmake" --version | head -1)" = "cmake version ${CMAKE_VERSION}"