Conversation
…irebirdSQL#47) The FB3 installer sets the generated SYSDBA password with 'gsec', which links against libtommath.so.0 and libncurses.so.5. Both were provisioned in RUN steps after install.sh, so gsec failed to load and the installer silently carried on. Images shipped an untouched security3.fdb (no Srp user, no PLG$SRP) with a SYSDBA.password that was never set, and every Srp login failed with "Install incomplete". Move the libtommath symlink and the libncurses5/libtinfo5 provisioning into the main RUN step, ahead of install.sh. Add tests covering the stock container's SYSDBA.password credentials. Record as D-019.
archive.ubuntu.com superseded 6.3-2ubuntu0.2 and the old .deb now returns 404, breaking the Firebird 3 Noble build.
This was referenced Sep 23, 2026
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #47.
Problem
In a Firebird 3 container started without
FIREBIRD_ROOT_PASSWORD, SYSDBA cannot log in with the password from/opt/firebird/SYSDBA.password. Every Srp login fails withInstall incomplete, please read the Compatibility chapter in the release notes for this version. This reproduces on every published FB3 image (all tags and distros). FB4 and FB5 are not affected.Root cause: the FB3 installer sets the SYSDBA password it generates with
gsec -add sysdba -pw <password>(setDBAPassword()ininstall.sh), and then writes that password toSYSDBA.password. FB3'sgsec,libfbclientandlibSrp.solink againstlibtommath.so.0andlibncurses.so.5/libtinfo.so.5, but our template only provided those in twoRUNsteps after./install.sh -silent. During the buildgsecfailed with:The installer's
runSilentwrapper prints the error and continues. The image then ships the tarball'ssecurity3.fdbunchanged: no Srp user and noPLG$SRPtable, since the Srp user manager only creates it when a user is first added through it.SYSDBA.passwordholds a password that was never set.This went unnoticed because
FIREBIRD_ROOT_PASSWORD(used in every README example) andFIREBIRD_USERboth add users through Srp at container start, which creates the missing structures. No test covered a stock container.Fix
src/Dockerfile.template: the FB3-onlylibtommath.so.0symlink and thelibncurses5/libtinfo5provisioning (D-017) now run inside the mainRUNstep, after the prerequisiteapt-get installand before./install.sh -silent. The installer's owngseccall then succeeds, soSYSDBA.passwordmatches the real SYSDBA password. The provisioning logic is unchanged. It now reuses the main step'scurland apt lists, which that step's final purge/clean already removes, so the separate install/purge/clean commands are gone. As a side effect, FB3 builds no longer logLooks like standalone server failed to start. For FB4+ the new block is skipped by theFIREBIRD_MAJOR = 3guard.src/image.tests.ps1:SYSDBA_password_file_allows_remote_login: a container with no environment variables must accept theSYSDBA.passwordcredentials overinet://(creating a database, then connecting to it), and reject a wrong password.FIREBIRD_USER_can_create_useralso checks that theSYSDBA.passwordcredentials still work when onlyFIREBIRD_USERis set.DECISIONS.md: D-019 records the ordering constraint (amends where D-017's step sits).generated/: regenerated withInvoke-Build Prepare.A separate commit bumps the Noble
libncurses5/libtinfo5pin from6.3-2ubuntu0.2to6.3-2ubuntu0.3.archive.ubuntu.comhas superseded0ubuntu0.2and it now returns 404, which breaks every FB3 Noble build (masterincluded). Same kind of fix as 3f7921c.Test plan
Invoke-Build Build+Invoke-Build Testfor3.0.14/noble: 27/27 green.firebirdsql/firebird:3.0.13(Install incomplete/Your user name and password are not defined), so they catch the regression.workflow_dispatchruns:3.0.14/bookworm: 35879244703 — success3.0.14/jammy: 35879453402 — success3.0.14/noble: 35879631667 — success (validates the pin bump)4.0.7/trixie: 35879822971 — success (regression check)5.0.4/trixie, amd64 + arm64: 35879991989 — success (regression check)publish-fork(all FB3 versions, trixie, build + full test suite before push): 35879036353 — success, full suite green for all six FB3 releases (3.0.9 → 3.0.14). Published asghcr.io/fdcastel/firebird:3.0.xfor the reporter to verify; the issue's exact repro (gsec -user sysdba -password "$PW" -di) now lists SYSDBA.Known unrelated CI failure: bullseye
The push-triggered fork CI run (35878518319) fails on bullseye in the prerequisite
apt-get install.deb.debian.org/debian-securityreturns 404 for thebullseye-securitypackages listed in its own index (curl,libcurl4,openssl,libicu67,libtommath1, …). A stockdebian:bullseye-slimreproduces it with justapt-get update && apt-get install curl, with no Firebird involved. Bullseye LTS ended on 2026-08-31, so this looks like the archive transition ofbullseye-security. It affectsmasterequally and needs a separate decision (repoint toarchive.debian.org, or drop/block bullseye). Because the fork CI'sBuildtask stops at the first failed image, I validated the other distros with the targeted dispatch runs above.