Skip to content

chore: upgrade AMX Mod X and shellcheck pins to latest - #38

Merged
KevinTCoughlin merged 3 commits into
mainfrom
claude/upgrade-mods-runtimes-6hye93
Jul 27, 2026
Merged

KevinTCoughlin merged 3 commits into
mainfrom
claude/upgrade-mods-runtimes-6hye93

Conversation

@KevinTCoughlin

@KevinTCoughlin KevinTCoughlin commented Jul 27, 2026 •

Copy link
Copy Markdown
Owner

Description

Upgrades the mod stack and build-tooling pins to their latest upstream versions. Every component was checked against upstream; only AMX Mod X and the shellcheck pin were actually behind.

Component Before After Status
ReHLDS 3.15.0.896 — already latest
ReGameDLL_CS 5.30.0.814 — already latest
Metamod-R 1.3.0.149 — already latest
ReAPI 5.29.0.358 — already latest
AMX Mod X build 5478 build 5479 bumped
shellcheck (ci.yml) v0.10.0 v0.11.0 bumped
debian:trixie (both stages) Debian 13 — current stable

Runtimes are already current: debian:trixie / trixie-slim is Debian 13, the present stable release. All GitHub Actions are pinned at their latest majors (checkout@v7, build-push-action@v7, metadata-action@v6, setup-buildx-action@v4, login-action@v4, trivy-action@v0.36.0, codeql-action@v4, sbom-action@v0.24.0, upload-artifact@v7, hadolint-action@v3.3.0, action-shellcheck@2.0.0) — Dependabot keeps those fresh. The shellcheck version: input is a plain string rather than an action ref, so Dependabot does not track it; that is why it had drifted a minor version behind.

Type of Change

  • Configuration change
  • Infrastructure/CI update
  • Documentation update

Related Issues

None.

Changes Made

  • Containerfile: ARG AMXMODX_BUILD 5478 → 5479
  • .github/workflows/ci.yml: shellcheck pin v0.10.0 → v0.11.0
  • .github/workflows/version-check.yml: replaced sort -nu | sort -r with a single sort -nru. The second sort re-ordered lexically and undid the numeric sort, so the workflow would pick the wrong "latest" once AMX Mod X builds reach 5 digits (ranking 9999 above 10000). Harmless at today's 4-digit builds, wrong later.
  • README.md: resynced the Stack list, which still advertised ReHLDS 3.14.0.857, ReGameDLL_CS 5.28.0.756, and ReAPI 5.26.0.338 rather than the versions the Containerfile actually pins; AMX Mod X now shows its build number
  • CHANGELOG.md: added entries for this bump, and removed two [Unreleased] claims that don't match the tree — base images pinned to OCI digests (added in Trixie migration, CI hardening, AMXX compiler modernization, and follow-up fixes #11, removed again in Optimize and modernize Debian slim runtime image #15, so the net diff has plain tags) and amxxpc invoked with -O2 (git log -S'-O2' -- Containerfile returns nothing, so it was never true). The fail-fast half of the -O2 line was kept; it is accurate.

Testing Performed

  • Container builds successfully: just build (via CI build-and-scan)
  • Lint checks pass: just check
  • Server starts and is joinable: just up
  • Manual testing performed (describe below)

Manual Testing:

  • hadolint 2.14.0 on the modified Containerfile: clean.
  • shellcheck 0.11.0 on entrypoint.sh and install.sh: clean, exit 0. Ran this before bumping the pin, to confirm 0.11.0's new checks (SC2327–SC2332, SC3062, SC2335) do not fire on either script. CI's Lint job then confirmed it on the runner. The version-check.yml run-block was extracted and shellchecked separately — also clean.
  • Sort fix verified two ways. On synthetic input (5478, 5479, 9999, 10000) the old pipeline's first candidate was 9999; the new one is 10000, with dedup preserved. Then version-check.yml was dispatched on this branch and passed — with the fix it resolved 5479 as the latest downloadable build and matched the Containerfile pin, exiting 0.
  • AMX Mod X build 5479 confirmed present and downloadable upstream (both the base-linux and cstrike-linux tarballs the Containerfile fetches).

CI status: all checks green on 6ceec26 (current head) — Lint ✅, build-and-scan ✅ (this is what exercises the AMXX 5479 fetch, the amxxpc compile over the eight .sma plugins, and the container smoke test), Trivy no blocking findings, Copilot re-review clean with no new comments.

Still not exercised anywhere: a live server start with players connecting. just up and in-game validation remain a manual step — no container runtime was available in the authoring environment, and CI's smoke test checks binary presence and executability rather than actual gameplay.

Checklist

  • I have performed a self-review of my own changes
  • I have tested that the server starts and accepts connections
  • I have updated documentation if needed
  • My changes generate no new warnings during build

Bump AMX Mod X from build 5478 to 5479 (latest downloadable build on
amxxdrop 1.10). ReHLDS 3.15.0.896, ReGameDLL_CS 5.30.0.814,
Metamod-R 1.3.0.149, and ReAPI 5.29.0.358 were verified against
upstream and are already the latest releases; debian:trixie is the
current Debian stable, so both build stages stay put.

Bump the shellcheck pin in ci.yml from v0.10.0 to v0.11.0. Verified
entrypoint.sh and install.sh are clean under 0.11.0's new checks
(SC2327-SC2332, SC3062, SC2335) before bumping.

Resync the README stack list, which still advertised ReHLDS
3.14.0.857 / ReGameDLL_CS 5.28.0.756 / ReAPI 5.26.0.338 rather than
the versions the Containerfile actually pins.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NAVdMb6TCFgkBdyh1Hdrme
Copilot AI review requested due to automatic review settings July 27, 2026 15:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the pinned versions for the AMX Mod X tooling bundle used in the container build and bumps the CI ShellCheck version, while also resyncing the README/CHANGELOG to reflect the actual pinned stack versions used by the Containerfile.

Changes:

  • Bumped AMX Mod X pin in the Containerfile from build 5478 to 5479.
  • Bumped ShellCheck pin in CI from v0.10.0 to v0.11.0.
  • Updated README stack versions and added corresponding CHANGELOG entries under [Unreleased].

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.

File Description
README.md Updates the displayed stack versions to match what the Containerfile actually pins (including AMX Mod X build number).
Containerfile Bumps ARG AMXMODX_BUILD to 5479 so the AMX Mod X tarball URLs resolve to the newer build.
CHANGELOG.md Adds [Unreleased] entries documenting the AMX Mod X and ShellCheck pin bumps and README resync.
.github/workflows/ci.yml Updates the ShellCheck version: input used by the shell lint job to v0.11.0.

@KevinTCoughlin
KevinTCoughlin marked this pull request as ready for review July 27, 2026 15:33
…HANGELOG claim

version-check.yml piped `sort -nu | sort -r`, so the second sort
re-ordered the build numbers lexically and undid the numeric sort.
Harmless at today's 4-digit AMX Mod X builds, but it would pick the
wrong "latest" once builds reach 5 digits (ranking 9999 above 10000).
Collapsed to a single `sort -nru`, which sorts numerically descending
and dedupes in one pass.

Removed the CHANGELOG line claiming base image FROM lines are pinned
to OCI manifest digests. The digests were added in #11 and removed
again in #15; both are still under [Unreleased], so the net diff has
plain debian:trixie / trixie-slim tags and the entry described a
change that no longer exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NAVdMb6TCFgkBdyh1Hdrme
Copilot AI review requested due to automatic review settings July 27, 2026 15:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Comment thread CHANGELOG.md Outdated
The entry stated `amxxpc` is invoked with an `-O2` optimisation flag,
but the Containerfile compile loop calls `./amxxpc "$sma"` with no
such flag, and `git log -S'-O2' -- Containerfile` shows it was never
there — the claim was never accurate rather than having regressed.

Kept the fail-fast half of the entry, which is correct: both the
compile and the mv carry `|| exit 1`. Left the build itself alone;
adding `-O2` would change compiler behaviour and is out of scope here.

Reported by Copilot review on #38.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NAVdMb6TCFgkBdyh1Hdrme
Copilot AI review requested due to automatic review settings July 27, 2026 15:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 5 changed files in this pull request and generated no new comments.

@KevinTCoughlin
KevinTCoughlin merged commit 9bc0e04 into main Jul 27, 2026
4 checks passed
@KevinTCoughlin
KevinTCoughlin deleted the claude/upgrade-mods-runtimes-6hye93 branch July 27, 2026 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants