Fix CI: bootstrap the full Slackware build toolchain via slackpkg
The build-packages.yml run was failing for two compounding reasons, found by testing directly against vbatts/slackware:15.0 on the actual runner host: 1. The image ships neither git nor its HTTPS runtime libs, so actions/checkout failed immediately. 2. It's a minimal rootfs with none of the 'D' (development) series — no gcc, make, autoconf, pkg-config, curl, glib2, libcap, or fuse3 — contrary to setup-slackware-buildenv.sh's assumption that a "full" Slackware install already provides these. An earlier fix attempt hand-pinned git + its deps (nghttp2, brotli, cyrus-sasl) by exact file + SHA256 from the base 15.0 release directory. That drifted out of sync with the newer, patched curl slackpkg installs later in the same container — same shared library, two different builds, causing a runtime symbol lookup error. Both steps now resolve every package through slackpkg's own prioritized mirror instead, keeping the whole toolchain on one mutually consistent version set. Verified end-to-end (git ls-remote and curl both succeed over HTTPS against the real Gitea instance, full toolchain present) in a fresh vbatts/slackware:15.0 container. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -5,14 +5,22 @@
|
||||
# Prepares a Slackware container (see .github/workflows/build-packages.yml)
|
||||
# to build all seven packages under packages/. Idempotent and safe to re-run.
|
||||
#
|
||||
# Strategy: detect what's already present (a stock "full" Slackware 15.0
|
||||
# install already provides gcc/make/autotools/glib2/libcap/fuse3) and only
|
||||
# bootstrap what's genuinely missing (libseccomp, yajl — neither ships in
|
||||
# stock Slackware — plus the Go and Rust toolchains, which no Slackware
|
||||
# install ships). This makes the script tolerant of small differences
|
||||
# between Slackware base image variants instead of assuming one exact image
|
||||
# layout, while still failing loudly if something we cannot self-provision
|
||||
# (a C compiler, basically) is missing.
|
||||
# Strategy: vbatts/slackware:15.0 (the image build-packages.yml runs this
|
||||
# in) is a minimal rootfs — it ships none of the 'D' (development) series,
|
||||
# nor glib2/libcap/fuse3/curl. Step 0 below uses slackpkg (already present
|
||||
# and pre-configured with a mirror in that image) to install the toolchain
|
||||
# packages by name. Slackware packages carry no dependency metadata at all
|
||||
# (unlike apt/dnf), so slackpkg does NOT resolve dependencies — the list
|
||||
# below must name every package explicitly, including curl's HTTPS
|
||||
# runtime libs (nghttp2, brotli, cyrus-sasl), or you get a shared-library
|
||||
# error at the first invocation, not an install-time failure. What's left
|
||||
# after this (libseccomp, yajl — neither ships in stock Slackware — plus
|
||||
# the Go and Rust toolchains, which no Slackware install ships) is
|
||||
# bootstrapped from source, further down. This makes the script tolerant
|
||||
# of small differences between Slackware base image variants (it skips
|
||||
# anything slackpkg reports as already installed) instead of assuming one
|
||||
# exact image layout, while still failing loudly if something we cannot
|
||||
# self-provision is missing.
|
||||
#
|
||||
# Exits non-zero with a clear message if a required tool cannot be found or
|
||||
# provisioned — this script is meant to run early in CI so failures surface
|
||||
@@ -49,6 +57,29 @@ require_pkgconfig() {
|
||||
return 0
|
||||
}
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# 0. Bootstrap the Slackware toolchain packages via slackpkg, if missing.
|
||||
#
|
||||
# CHECKGPG is turned off here: slackpkg's default GPG-key bootstrap fetches
|
||||
# Slackware's signing key from www.slackware.com, which is not reachable
|
||||
# from every CI network (observed to hang/fail on the self-hosted Gitea
|
||||
# Actions runner this project builds on). slackpkg's CHECKMD5 (on by
|
||||
# default) still verifies every package against the mirror's own
|
||||
# CHECKSUMS.md5 as a transit-integrity check. This is build-toolchain
|
||||
# provisioning, not the shipped artifacts — those are independently
|
||||
# checksummed by scripts/checksums.sh.
|
||||
# -----------------------------------------------------------------------------
|
||||
if command -v slackpkg > /dev/null 2>&1; then
|
||||
echo "==> bootstrapping build toolchain via slackpkg"
|
||||
sed -i 's/^CHECKGPG=on/CHECKGPG=off/' /etc/slackpkg/slackpkg.conf
|
||||
slackpkg -batch=on -default_answer=y update
|
||||
slackpkg -batch=on -default_answer=y install \
|
||||
gcc gcc-g++ binutils make m4 perl autoconf automake libtool pkg-config \
|
||||
curl nghttp2 brotli cyrus-sasl ca-certificates glib2 libcap fuse3
|
||||
else
|
||||
echo "==> slackpkg not found, assuming toolchain is already provided by the base image"
|
||||
fi
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# 1. Baseline toolchain expected to already be present in the base image.
|
||||
# -----------------------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user