You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(deps): refresh tmate image and charm packaging tools - #58
Refresh the rock to 1.1 and align the service image tag; require patched setuptools/wheel in the charm. Part of ISD-6336.
Rationale
The deployed image has stale Ubuntu packages and Pebble's Go dependencies. Local Trivy: image High/Critical 41 → 0, with all targeted image CVEs that have fixes gone. The 25 remaining Low/Medium findings have no scanner-listed fixes. Unmodified fresh rebuild → versioned rebuild: High/Critical 0 → 0.
Packed the Ubuntu 22.04 charm before/after and scanned its extracted rootfs: High/Critical 3 → 0. Setuptools is now 84.0.0 and wheel is 0.48.0 (vendored wheel 0.46.3), clearing CVE-2022-40897, CVE-2024-6345, CVE-2025-47273 and CVE-2026-24049. Six existing Low/Medium pip findings remain; no new High/Critical findings. JSON/table scans saved locally. Secscan re-verification after publish.
Image:ghcr.io/canonical/tmate-ssh-server:1.1 is published (digest sha256:c8d9bb93639d9342e25bf5591a947eaa6b0d12cfa3a233422738b199199eb52a), pushed from the same rock that was scanned above; integration tests pass against it. The charm workflow does not publish this hard-coded image, so the publication steps are now documented in CONTRIBUTING.md.
Juju Events Changes
install, update-status and the new upgrade-charm handler all call one idempotent tmate.ensure_daemon_running(address) (replacing start_daemon). It renders the service with the installed container name and keeps a running workload whose service is unchanged, so charm-only upgrades no longer interrupt sessions. Otherwise it pulls the image if not cached (a pull failure aborts with the old workload intact), force-removes the previous container, rewrites/reloads the service and restarts it, preserving SSH keys. The explicit removal is needed because tmate ignores SIGTERM as container PID 1, so a plain service restart leaves the old container holding the port. New containers use --rm to clean themselves up on exit. A restart interrupts active sessions.
Module Changes
Rock version, image tag (now the IMAGE constant in src/tmate.py), Python packaging dependency floors, publication instructions in CONTRIBUTING.md, ensure_daemon_running and upgrade handler with tests, a test_upgrade integration test and changelog. Tox lint/unit/static pass: 60 unit tests, 100% source coverage; rock and charm pack pass.
Addressed the upgrade-path concern in the review body: upgrade-charm now rewrites the unit, reloads systemd and restarts the workload with the refreshed image, preserving SSH keys. Added success, defer, failure and reload-before-restart tests. Tox lint/unit/static pass (53 tests, 100% coverage); rebuilt charm Trivy scan remains 0 High/Critical. The upgrade documentation notes that active sessions are interrupted.
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
Live workload replacement has unresolved availability and regression-coverage concerns, and the published image’s security claims require human validation.
Pin a pre-change charm revision to test image replacement
tests/integration/test_upgrade.py:33
After this change reaches latest/edge, the deployed baseline can already have the same image and service template as the charm under test. Both refreshes can then take the unchanged-service path, leaving legacy-container removal and image replacement untested. Pin a known pre-change charm revision and assert before refreshing that its image differs from the expected replacement.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Applicable spec: ISD-6336 (SSDLC 26.10, SEC0025)
Overview
Refresh the rock to 1.1 and align the service image tag; require patched setuptools/wheel in the charm. Part of ISD-6336.
Rationale
The deployed image has stale Ubuntu packages and Pebble's Go dependencies. Local Trivy: image High/Critical 41 → 0, with all targeted image CVEs that have fixes gone. The 25 remaining Low/Medium findings have no scanner-listed fixes. Unmodified fresh rebuild → versioned rebuild: High/Critical 0 → 0.
Packed the Ubuntu 22.04 charm before/after and scanned its extracted rootfs: High/Critical 3 → 0. Setuptools is now 84.0.0 and wheel is 0.48.0 (vendored wheel 0.46.3), clearing CVE-2022-40897, CVE-2024-6345, CVE-2025-47273 and CVE-2026-24049. Six existing Low/Medium pip findings remain; no new High/Critical findings. JSON/table scans saved locally. Secscan re-verification after publish.
Image:
ghcr.io/canonical/tmate-ssh-server:1.1is published (digestsha256:c8d9bb93639d9342e25bf5591a947eaa6b0d12cfa3a233422738b199199eb52a), pushed from the same rock that was scanned above; integration tests pass against it. The charm workflow does not publish this hard-coded image, so the publication steps are now documented inCONTRIBUTING.md.Juju Events Changes
install,update-statusand the newupgrade-charmhandler all call one idempotenttmate.ensure_daemon_running(address)(replacingstart_daemon). It renders the service with the installed container name and keeps a running workload whose service is unchanged, so charm-only upgrades no longer interrupt sessions. Otherwise it pulls the image if not cached (a pull failure aborts with the old workload intact), force-removes the previous container, rewrites/reloads the service and restarts it, preserving SSH keys. The explicit removal is needed because tmate ignores SIGTERM as container PID 1, so a plain service restart leaves the old container holding the port. New containers use--rmto clean themselves up on exit. A restart interrupts active sessions.Module Changes
Rock version, image tag (now the
IMAGEconstant insrc/tmate.py), Python packaging dependency floors, publication instructions inCONTRIBUTING.md,ensure_daemon_runningand upgrade handler with tests, atest_upgradeintegration test and changelog. Tox lint/unit/static pass: 60 unit tests, 100% source coverage; rock and charm pack pass.Library Changes
None.
Checklist
urgent,trivial,complex,documentation)AI-generated message.