Fix CI: unshadow the pinned Go, and add python3/protoc/go-md2man
Build Packages / Build .txz packages (push) Failing after 2m59s
Lint / ShellCheck (push) Successful in 12s
Lint / Validate .plg XML (push) Successful in 12s
Lint / EditorConfig (push) Successful in 5s

Task 84's log got further than any run so far — 4 of 8 packages
(aardvark-dns, passt, fuse-overlayfs, unraid-podman) built successfully
— and surfaced four distinct, genuine build-time issues for the rest:

1. podman: go.mod parsing failed with "invalid go version '1.25.6':
   must match format 1.23". Root cause: slackpkg's batch-mode
   `install gcc` (verified directly) pulls in every gcc-<lang> sibling
   package Slackware's gcc SlackBuild produces — including gcc-go, an
   ancient bundled go1.16.5. Our Go bootstrap only installed the pinned
   $GO_VERSION when `command -v go` found nothing, so gcc-go's go1.16.5
   silently won. Fixed by always installing/overwriting the pinned Go
   and prepending it to PATH, regardless of what else provides `go`.

2. crun: "no suitable Python interpreter found" — added python3.

3. netavark: build.rs (via prost-build) needs a `protoc` binary;
   Slackware packages no protobuf/protoc at all. Added the official
   prebuilt release binary, pinned + checksummed (no `unzip` on this
   image either, so extracted with `python3 -m zipfile` instead of
   adding yet another package).

4. conmon: `make install`'s docs target needs go-md2man, not packaged
   by Slackware and no prebuilt release exists upstream. `go install`
   it, pinned to a tagged release, now that our own Go is reliably on
   PATH.

All four verified directly against vbatts/slackware:15.0 on the actual
runner host before this commit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-11 21:32:27 +00:00
co-authored by Claude Sonnet 5
parent e912180e8d
commit 23a1ab22a6
2 changed files with 90 additions and 19 deletions
+12
View File
@@ -44,3 +44,15 @@ LIBSECCOMP_SRC_SHA256="f9a13e4c633d319a9240189760ca348caa0837c0ebe2a09b17061da8c
YAJL_VERSION="2.1.0" YAJL_VERSION="2.1.0"
YAJL_SRC_URL="https://github.com/lloyd/yajl/archive/refs/tags/${YAJL_VERSION}.tar.gz" YAJL_SRC_URL="https://github.com/lloyd/yajl/archive/refs/tags/${YAJL_VERSION}.tar.gz"
YAJL_SRC_SHA256="3fb73364a5a30efe615046d07e6db9d09fd2b41c763c5f7d3bfb121cd5c5ac5a" YAJL_SRC_SHA256="3fb73364a5a30efe615046d07e6db9d09fd2b41c763c5f7d3bfb121cd5c5ac5a"
# protoc (netavark's build.rs shells out to it via the prost-build crate) —
# Slackware ships no protobuf/protoc package at all, official prebuilt
# release binary used instead of a from-source C++ build.
PROTOC_VERSION="35.1"
PROTOC_SRC_URL="https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOC_VERSION}/protoc-${PROTOC_VERSION}-linux-x86_64.zip"
PROTOC_SRC_SHA256="6930ebf62bd4ea607b98fff052596c6ee564b9835b4ce172c75a3f53ae9d91b7"
# go-md2man (conmon's `make install` shells out to it to generate its man
# page) — installed via `go install`, pinned to a tagged release rather
# than @latest so this build stays reproducible.
GO_MD2MAN_VERSION="2.0.7"
+76 -17
View File
@@ -14,9 +14,10 @@
# below must name every package explicitly, including curl's HTTPS # below must name every package explicitly, including curl's HTTPS
# runtime libs (nghttp2, brotli, cyrus-sasl), or you get a shared-library # runtime libs (nghttp2, brotli, cyrus-sasl), or you get a shared-library
# error at the first invocation, not an install-time failure. What's left # error at the first invocation, not an install-time failure. What's left
# after this (libseccomp, yajl — neither ships in stock Slackware — plus # after this (libseccomp, yajl, protoc — none ship in stock Slackware —
# the Go and Rust toolchains, which no Slackware install ships) is # plus the Go/Rust toolchains and go-md2man, which no Slackware install
# bootstrapped from source, further down. This makes the script tolerant # ships) is bootstrapped from source or official upstream releases,
# further down. This makes the script tolerant
# of small differences between Slackware base image variants (it skips # of small differences between Slackware base image variants (it skips
# anything slackpkg reports as already installed) instead of assuming one # anything slackpkg reports as already installed) instead of assuming one
# exact image layout, while still failing loudly if something we cannot # exact image layout, while still failing loudly if something we cannot
@@ -76,7 +77,8 @@ if command -v slackpkg > /dev/null 2>&1; then
slackpkg -batch=on -default_answer=y install \ slackpkg -batch=on -default_answer=y install \
gcc gcc-g++ binutils make m4 perl autoconf automake libtool pkg-config \ gcc gcc-g++ binutils make m4 perl autoconf automake libtool pkg-config \
curl nghttp2 brotli cyrus-sasl ca-certificates glib2 libcap fuse3 \ curl nghttp2 brotli cyrus-sasl ca-certificates glib2 libcap fuse3 \
cmake libarchive lz4 libxml2 guile gc kernel-headers flex elfutils cmake libarchive lz4 libxml2 guile gc kernel-headers flex elfutils \
python3
else else
echo "==> slackpkg not found, assuming toolchain is already provided by the base image" echo "==> slackpkg not found, assuming toolchain is already provided by the base image"
fi fi
@@ -94,6 +96,7 @@ require_binary git "Needed to fetch crun's git submodules."
require_binary curl "Needed to fetch pinned source tarballs." require_binary curl "Needed to fetch pinned source tarballs."
require_binary makepkg "Slackware's own packaging tool (pkgtools); should always be present." require_binary makepkg "Slackware's own packaging tool (pkgtools); should always be present."
require_binary strip "Part of binutils; part of Slackware's 'D' series." require_binary strip "Part of binutils; part of Slackware's 'D' series."
require_binary python3 "Needed by crun's configure script (checks for Python >= 3)."
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
# 2. C library dependencies expected to already be present. # 2. C library dependencies expected to already be present.
@@ -147,27 +150,54 @@ fi
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
# 5. Go toolchain (podman) — official upstream tarball. # 5. Go toolchain (podman) — official upstream tarball.
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
if ! command -v go > /dev/null 2>&1; then # Always install our pinned Go, unconditionally — do NOT skip this just
echo "==> Go not found, installing $GO_VERSION" # because `command -v go` finds something. On this image, slackpkg's
curl -fL --retry 3 -o "$WORK/go.tar.gz" "$GO_SRC_URL" # batch-mode "install gcc" (step 0 above) pulls in every gcc-<lang>
actual=$(sha256sum "$WORK/go.tar.gz" | awk '{print $1}') # sibling package built from the same Slackware gcc SlackBuild, including
[ "$actual" = "$GO_SRC_SHA256" ] || { # gcc-go, which ships an ancient bundled Go (gccgo, go1.16.5) at
# /usr/bin/go — old enough that its go.mod parser rejects the 3-component
# "go 1.25.x" directive modern modules use, and would silently shadow our
# intended $GO_VERSION if we only installed when `go` was missing.
# Overwriting /usr/local/go and prepending it to PATH/GITHUB_PATH here
# guarantees the pinned toolchain wins regardless of what else provides a
# `go` binary.
echo "==> installing Go $GO_VERSION (unconditionally, see comment above)"
curl -fL --retry 3 -o "$WORK/go.tar.gz" "$GO_SRC_URL"
actual=$(sha256sum "$WORK/go.tar.gz" | awk '{print $1}')
[ "$actual" = "$GO_SRC_SHA256" ] || {
echo "!! Go toolchain checksum mismatch (expected $GO_SRC_SHA256, got $actual)" >&2 echo "!! Go toolchain checksum mismatch (expected $GO_SRC_SHA256, got $actual)" >&2
exit 1 exit 1
} }
rm -rf /usr/local/go rm -rf /usr/local/go
tar -C /usr/local -xf "$WORK/go.tar.gz" tar -C /usr/local -xf "$WORK/go.tar.gz"
export PATH="/usr/local/go/bin:$PATH" export PATH="/usr/local/go/bin:$PATH"
# Persist PATH for subsequent steps in the same GitHub Actions job. # Persist PATH for subsequent steps in the same GitHub Actions job.
if [ -n "${GITHUB_PATH:-}" ]; then if [ -n "${GITHUB_PATH:-}" ]; then
echo "/usr/local/go/bin" >> "$GITHUB_PATH" echo "/usr/local/go/bin" >> "$GITHUB_PATH"
fi
echo "==> using: $(go version)"
# -----------------------------------------------------------------------------
# 6. go-md2man (conmon) — its `make install` shells out to this to render
# docs/conmon.8.md into a man page; not packaged by Slackware, and no
# prebuilt binary release exists upstream, so `go install` it (now that
# our pinned Go from step 5 is on PATH). Pinned to a tagged release
# rather than @latest to keep this build reproducible.
# -----------------------------------------------------------------------------
if ! command -v go-md2man > /dev/null 2>&1; then
echo "==> installing go-md2man v$GO_MD2MAN_VERSION"
go install "github.com/cpuguy83/go-md2man/v2@v${GO_MD2MAN_VERSION}"
gobin="$(go env GOPATH)/bin"
export PATH="$gobin:$PATH"
if [ -n "${GITHUB_PATH:-}" ]; then
echo "$gobin" >> "$GITHUB_PATH"
fi fi
else else
echo "==> Go already present: $(go version)" echo "==> go-md2man already present: $(command -v go-md2man)"
fi fi
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
# 6. Rust toolchain (netavark, aardvark-dns) — via rustup. # 7. Rust toolchain (netavark, aardvark-dns) — via rustup.
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
if ! command -v cargo > /dev/null 2>&1; then if ! command -v cargo > /dev/null 2>&1; then
echo "==> Rust/cargo not found, installing via rustup ($RUST_CHANNEL channel)" echo "==> Rust/cargo not found, installing via rustup ($RUST_CHANNEL channel)"
@@ -182,5 +212,34 @@ else
echo "==> Rust already present: $(cargo --version)" echo "==> Rust already present: $(cargo --version)"
fi fi
# -----------------------------------------------------------------------------
# 8. protoc (netavark) — its build.rs (via the prost-build crate) shells
# out to a `protoc` binary to compile .proto files; Slackware packages no
# protobuf/protoc at all (checked: not in any of the main/extra/pasture/
# testing repos). Official prebuilt release binary used instead of a
# from-source C++ build. No `unzip` on this image either, so extract with
# `python3 -m zipfile` (python3 is already installed, see step 0/1, for
# crun's configure script) rather than adding yet another package.
# -----------------------------------------------------------------------------
if ! command -v protoc > /dev/null 2>&1; then
echo "==> installing protoc v$PROTOC_VERSION"
curl -fL --retry 3 -o "$WORK/protoc.zip" "$PROTOC_SRC_URL"
actual=$(sha256sum "$WORK/protoc.zip" | awk '{print $1}')
[ "$actual" = "$PROTOC_SRC_SHA256" ] || {
echo "!! protoc checksum mismatch (expected $PROTOC_SRC_SHA256, got $actual)" >&2
exit 1
}
rm -rf /usr/local/protoc
mkdir -p /usr/local/protoc
python3 -m zipfile -e "$WORK/protoc.zip" /usr/local/protoc
chmod +x /usr/local/protoc/bin/protoc
export PATH="/usr/local/protoc/bin:$PATH"
if [ -n "${GITHUB_PATH:-}" ]; then
echo "/usr/local/protoc/bin" >> "$GITHUB_PATH"
fi
else
echo "==> protoc already present: $(protoc --version)"
fi
echo echo
echo "==> Build environment ready." echo "==> Build environment ready."