The subtree is in place, so everything that used to fetch and patch core at
build time now just copies it.
tools/build.sh copies wordpress/ — no download, no checksum step,
because there is nothing to fetch and nothing to
trust that is not already in the repository
docker/Dockerfile COPY wordpress/ instead of curl + sha256 + patch;
the build args and the `patch` package are gone
docker-compose.yml no WP_VERSION / WP_URL / WP_SHA256 to keep in step
tools/update-wordpress.sh is rewritten around what the subtree makes
possible. It imports the pristine release onto sirius-press/wordpress-upstream
and then `git subtree merge`s that branch, which three-way merges upstream
against the fork's own commit. A patch either applies with fuzz and hopes or
fails and leaves you re-deriving the change by hand; a merge conflict is
resolved once, in the file, and the next release merges against the
resolution.
patches/ survives as documentation rather than mechanism, and is now
generated: tools/refresh-patches.sh diffs the subtree against the pristine
import and rewrites the directory, with --check for CI. It answers the
question anyone auditing a fork asks first — what exactly did you change
inside WordPress? — in a minute, which `git log wordpress/` cannot, because
that log is mostly upstream imports. Generated documentation stays true; a
hand-maintained record of a core diff drifts, and a stale one is worse than
none because people trust it.
One test change worth noting: the syntax sweep no longer walks all of
wordpress/. It lints the fork's own PHP plus every core file patches/ says
the fork touches, which keeps the suite at seven seconds instead of a minute
while still covering the only core file that can break.
77 lines
3 KiB
Docker
77 lines
3 KiB
Docker
# Sirius Press — PHP-FPM image with the patched WordPress baked in.
|
|
#
|
|
# Core comes from this repository's `wordpress/` subtree, not from a download
|
|
# and not from the official `wordpress` image. That image ships whatever
|
|
# version it was tagged with, and the fork's core patch is pinned to an exact
|
|
# one; applying a fork's patch to a different core is how a setup wizard ends
|
|
# up half rewritten. Copying the vendored tree makes the image contain exactly
|
|
# what `git log wordpress/` describes, with nothing fetched at build time.
|
|
#
|
|
# Core is staged at /opt/sirius-press/core, not at the document root. The
|
|
# entrypoint copies it into place on every start, which is what makes
|
|
# `docker compose build --pull && up -d` a real upgrade: the usual layout,
|
|
# where the document root is itself a volume, pins core to whatever version
|
|
# first created that volume and turns every security release into a manual
|
|
# migration.
|
|
#
|
|
# GMP is installed because the wallet cryptography runs in PHP. Without it the
|
|
# fork falls back to BCMath, which works and is roughly twenty times slower —
|
|
# unavoidable on a shared host, wasteful in a container we control.
|
|
|
|
FROM php:8.3-fpm-bookworm
|
|
|
|
RUN set -eux; \
|
|
apt-get update; \
|
|
apt-get install -y --no-install-recommends \
|
|
ca-certificates curl \
|
|
libfreetype6-dev libjpeg62-turbo-dev libpng-dev libwebp-dev \
|
|
libzip-dev libgmp-dev libicu-dev \
|
|
; \
|
|
docker-php-ext-configure gd --with-freetype --with-jpeg --with-webp; \
|
|
docker-php-ext-install -j"$(nproc)" \
|
|
bcmath gd gmp intl mysqli opcache zip exif \
|
|
; \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
# Settings a WordPress host wants and the PHP image does not set.
|
|
RUN { \
|
|
echo 'upload_max_filesize = 64M'; \
|
|
echo 'post_max_size = 64M'; \
|
|
echo 'memory_limit = 256M'; \
|
|
echo 'max_execution_time = 120'; \
|
|
echo 'opcache.memory_consumption = 128'; \
|
|
echo 'opcache.max_accelerated_files = 10000'; \
|
|
echo 'opcache.revalidate_freq = 2'; \
|
|
echo 'expose_php = Off'; \
|
|
} > /usr/local/etc/php/conf.d/sirius-press.ini
|
|
|
|
# --- core, from the subtree --------------------------------------------------
|
|
|
|
COPY wordpress/ /opt/sirius-press/core/
|
|
|
|
RUN set -eux; \
|
|
test -f /opt/sirius-press/core/wp-includes/version.php; \
|
|
sed -n "s/.*wp_version = '\\(.*\\)'.*/\\1/p" \
|
|
/opt/sirius-press/core/wp-includes/version.php \
|
|
> /opt/sirius-press/core/.sirius-core-version; \
|
|
echo "vendored WordPress $(cat /opt/sirius-press/core/.sirius-core-version)"
|
|
|
|
# --- the fork -----------------------------------------------------------------
|
|
#
|
|
# The patch is already applied in the subtree, so there is nothing to patch
|
|
# here. patches/ is carried for auditing, not for building.
|
|
|
|
WORKDIR /opt/sirius-press/core
|
|
|
|
COPY plugins/ /opt/sirius-press/core/wp-content/plugins/
|
|
COPY mu-plugins/ /opt/sirius-press/core/wp-content/mu-plugins/
|
|
|
|
COPY docker/entrypoint.sh /usr/local/bin/sirius-entrypoint
|
|
RUN chmod +x /usr/local/bin/sirius-entrypoint; \
|
|
mkdir -p /var/www/html /var/www/config; \
|
|
chown -R www-data:www-data /var/www/html /var/www/config
|
|
|
|
WORKDIR /var/www/html
|
|
|
|
ENTRYPOINT ["sirius-entrypoint"]
|
|
CMD ["php-fpm"]
|