Fix CI: bootstrap the full Slackware build toolchain via slackpkg
The build-packages.yml run was failing for two compounding reasons, found by testing directly against vbatts/slackware:15.0 on the actual runner host: 1. The image ships neither git nor its HTTPS runtime libs, so actions/checkout failed immediately. 2. It's a minimal rootfs with none of the 'D' (development) series — no gcc, make, autoconf, pkg-config, curl, glib2, libcap, or fuse3 — contrary to setup-slackware-buildenv.sh's assumption that a "full" Slackware install already provides these. An earlier fix attempt hand-pinned git + its deps (nghttp2, brotli, cyrus-sasl) by exact file + SHA256 from the base 15.0 release directory. That drifted out of sync with the newer, patched curl slackpkg installs later in the same container — same shared library, two different builds, causing a runtime symbol lookup error. Both steps now resolve every package through slackpkg's own prioritized mirror instead, keeping the whole toolchain on one mutually consistent version set. Verified end-to-end (git ls-remote and curl both succeed over HTTPS against the real Gitea instance, full toolchain present) in a fresh vbatts/slackware:15.0 container. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -47,26 +47,21 @@ on:
|
||||
# base image. See scripts/ci/setup-slackware-buildenv.sh for how missing
|
||||
# build dependencies are bootstrapped on top of whatever this image ships.
|
||||
#
|
||||
# vbatts/slackware:15.0 ships tar but NOT git (needed by actions/checkout)
|
||||
# or any of git's runtime dependencies. The "Install git" step below pulls
|
||||
# git and its missing shared libraries from Slackware's own official
|
||||
# package mirror, pinned by exact filename + verified SHA256, before
|
||||
# actions/checkout runs — see that step for the full dependency chain
|
||||
# (found by trial: git needs libnghttp2, which needs nothing extra, but
|
||||
# git also dlopens libbrotlidec and libsasl2 for HTTPS transport).
|
||||
# vbatts/slackware:15.0 ships tar but NOT git (needed by actions/checkout),
|
||||
# nor any of the shared libraries git's HTTPS transport needs. The
|
||||
# "Install git" step below uses slackpkg (already present and pre-
|
||||
# configured with a mirror in this image) rather than hand-picking package
|
||||
# files: git's HTTPS support pulls in nghttp2/brotli/cyrus-sasl, and
|
||||
# hand-pinning those separately from the base 15.0 release directory (as
|
||||
# an earlier version of this step did) silently drifted out of sync with
|
||||
# the newer, patched curl that scripts/ci/setup-slackware-buildenv.sh
|
||||
# installs later in the same container — same library, two different
|
||||
# builds, resulting in a symbol lookup error at runtime. Letting slackpkg
|
||||
# resolve everything from the same prioritized repo set (patches over
|
||||
# main, see /etc/slackpkg/slackpkg.conf's PRIORITY) keeps every package on
|
||||
# this image on a mutually consistent version set.
|
||||
env:
|
||||
SLACKWARE_IMAGE: "vbatts/slackware:15.0"
|
||||
SLACKWARE_MIRROR: "http://slackware.osuosl.org/slackware64-15.0/slackware64"
|
||||
GIT_PKG: "d/git-2.35.1-x86_64-1.txz"
|
||||
GIT_PKG_SHA256: "502a8e921c13a3e89fa121d26e6e376bd927b05e5a2d1039c1bf815ab6ec535d"
|
||||
CA_CERTIFICATES_PKG: "n/ca-certificates-20211216-noarch-1.txz"
|
||||
CA_CERTIFICATES_PKG_SHA256: "e26e8e1371dd5f4f53978cef0449542e7e56b26d1813dcbc546159b551939a91"
|
||||
NGHTTP2_PKG: "n/nghttp2-1.46.0-x86_64-1.txz"
|
||||
NGHTTP2_PKG_SHA256: "cad5c7b38ae424b3f44b707637623f740da45a1d1f9938933dc472f931d2bddc"
|
||||
BROTLI_PKG: "l/brotli-1.0.9-x86_64-7.txz"
|
||||
BROTLI_PKG_SHA256: "f20e995cce0cf5c4f2575f94e87978e6e5f7d3923e847e3bca814e7c324bd474"
|
||||
CYRUS_SASL_PKG: "n/cyrus-sasl-2.1.27-x86_64-7.txz"
|
||||
CYRUS_SASL_PKG_SHA256: "b613130758ec952b8585e03f5174c924bc8bfc6d90aa6c53e7e73a30c6801b68"
|
||||
|
||||
jobs:
|
||||
build:
|
||||
@@ -82,31 +77,28 @@ jobs:
|
||||
set -eu
|
||||
command -v tar > /dev/null || (echo "!! base image is missing tar — see SLACKWARE_IMAGE in this workflow" && exit 1)
|
||||
|
||||
cd /tmp
|
||||
for pkg in "$CA_CERTIFICATES_PKG" "$NGHTTP2_PKG" "$BROTLI_PKG" "$CYRUS_SASL_PKG" "$GIT_PKG"; do
|
||||
wget -q --tries=3 "$SLACKWARE_MIRROR/$pkg"
|
||||
done
|
||||
echo "${CA_CERTIFICATES_PKG_SHA256} $(basename "$CA_CERTIFICATES_PKG")" | sha256sum -c -
|
||||
echo "${NGHTTP2_PKG_SHA256} $(basename "$NGHTTP2_PKG")" | sha256sum -c -
|
||||
echo "${BROTLI_PKG_SHA256} $(basename "$BROTLI_PKG")" | sha256sum -c -
|
||||
echo "${CYRUS_SASL_PKG_SHA256} $(basename "$CYRUS_SASL_PKG")" | sha256sum -c -
|
||||
echo "${GIT_PKG_SHA256} $(basename "$GIT_PKG")" | sha256sum -c -
|
||||
|
||||
# installpkg has no dependency resolver (unlike slackpkg) — install
|
||||
# git's runtime libs first, then git itself.
|
||||
installpkg "$(basename "$CA_CERTIFICATES_PKG")"
|
||||
installpkg "$(basename "$NGHTTP2_PKG")"
|
||||
installpkg "$(basename "$BROTLI_PKG")"
|
||||
installpkg "$(basename "$CYRUS_SASL_PKG")"
|
||||
installpkg "$(basename "$GIT_PKG")"
|
||||
# CHECKGPG is turned off: slackpkg's default GPG-key bootstrap
|
||||
# fetches Slackware's signing key from www.slackware.com, which
|
||||
# is not reachable from every CI network (observed to hang on
|
||||
# this project's self-hosted Gitea Actions runner). CHECKMD5
|
||||
# (on by default) still verifies every package against the
|
||||
# mirror's own CHECKSUMS.md5 as a transit-integrity check.
|
||||
sed -i 's/^CHECKGPG=on/CHECKGPG=off/' /etc/slackpkg/slackpkg.conf
|
||||
slackpkg -batch=on -default_answer=y update
|
||||
# git and curl's HTTPS transport need nghttp2/brotli/cyrus-sasl at
|
||||
# runtime, but slackpkg does not resolve shared-library
|
||||
# dependencies (Slackware packages carry no such metadata) — list
|
||||
# them explicitly so they come from the same slackpkg pass (and
|
||||
# therefore the same mutually-consistent build) as git itself.
|
||||
slackpkg -batch=on -default_answer=y install \
|
||||
git ca-certificates nghttp2 brotli cyrus-sasl
|
||||
|
||||
# ca-certificates ships individual certs under
|
||||
# /usr/share/ca-certificates/ — this builds the combined bundle
|
||||
# git needs to actually trust HTTPS remotes (without it, cloning
|
||||
# from a Gitea instance over HTTPS fails cert verification even
|
||||
# though the certs are installed).
|
||||
# git (and later, curl) need to actually trust HTTPS remotes.
|
||||
update-ca-certificates
|
||||
echo "GIT_SSL_CAINFO=/etc/ssl/certs/ca-certificates.crt" >> "$GITHUB_ENV"
|
||||
echo "CURL_CA_BUNDLE=/etc/ssl/certs/ca-certificates.crt" >> "$GITHUB_ENV"
|
||||
|
||||
git --version
|
||||
|
||||
|
||||
Reference in New Issue
Block a user