From c3b8ae8ed95caac7a1d2c6b481f3fee73a06c876 Mon Sep 17 00:00:00 2001 From: magges Date: Sat, 11 Jul 2026 22:17:02 +0000 Subject: [PATCH] Fix CI: json-c for crun, and fetch crun's git submodules as pinned tarballs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Verified end-to-end with a full local build of all 8 packages on the actual runner host (docker exec against vbatts/slackware:15.0, bind- mounted repo on the cache pool) instead of round-tripping through Gitea Actions for each fix — much faster for a chain of issues this deep. All 8 packages now build successfully from a clean checkout. Three fixes, all in crun (the last package still failing): 1. "Package requirements (json-c >= 0.14) were not met" — added json-c to the toolchain bootstrap. 2. crun depends on the libocispec git submodule, which in turn depends on the image-spec and runtime-spec git submodules. GitHub's source archive tarball never includes submodule content (no .git directory for `git submodule update` to work against — the existing `|| true` masked this failing silently). Fetched all three as their own pinned tarballs instead, at the exact commits crun 1.28 references (cross-checked via the GitHub contents API), matching how every other dependency in this project is already pinned. 3. crun.c unconditionally #includes git-version.h, which crun's own Makefile only generates via `git describe` (again, no .git) or from a pre-existing .tarball-git-version.h — the file crun's own `make dist` would have written, which we never run. Write that file ourselves in the exact format the Makefile already expects; this is the documented fallback path bundled release tarballs rely on, not a workaround around it. Also includes the podman go-md2man pre-seed fix and setup-slackware- buildenv.sh python3 addition from the previous commit's follow-up testing (both already verified working in this same local build run). Co-Authored-By: Claude Sonnet 5 --- packages/crun/crun.SlackBuild | 42 +++++++++++++++++++++----- packages/podman/podman.SlackBuild | 12 ++++++++ scripts/ci/setup-slackware-buildenv.sh | 3 +- versions.env | 25 +++++++++++++++ 4 files changed, 74 insertions(+), 8 deletions(-) diff --git a/packages/crun/crun.SlackBuild b/packages/crun/crun.SlackBuild index 879f845..b7c54f7 100755 --- a/packages/crun/crun.SlackBuild +++ b/packages/crun/crun.SlackBuild @@ -37,13 +37,41 @@ done cd "$srcdir" -# GitHub's source archive does not include vendored git submodules -# (libocispec) that crun's release tarballs normally bundle; init/update -# them explicitly. -if [ -f .gitmodules ]; then - echo "==> [crun] fetching submodules" - git -c protocol.file.allow=always submodule update --init --recursive || true -fi +# GitHub's source archive has no .git directory, so `git submodule +# update` can never work against it (it needs an actual git repo to +# resolve against) — it silently fails and leaves libocispec/ empty, +# which only surfaces much later as a confusing "No rule to make target +# 'all'" in that subdirectory. Fetch libocispec as its own pinned source +# instead, matching every other dependency in this project, and unpack it +# directly over the empty submodule directory. +echo "==> [crun] fetching libocispec (git submodule, pinned separately — see versions.env)" +libocispec_tarball=$(sb_fetch_and_verify "$LIBOCISPEC_SRC_URL" "$LIBOCISPEC_SRC_SHA256" "libocispec-$LIBOCISPEC_COMMIT.tar.gz") +rm -rf "$srcdir/libocispec" +mkdir -p "$srcdir/libocispec" +tar -xf "$libocispec_tarball" -C "$srcdir/libocispec" --strip-components=1 + +# libocispec has its own two git submodules (image-spec, runtime-spec) — +# same problem, one level deeper. Same fix, same reasoning. +echo "==> [crun] fetching libocispec's image-spec/runtime-spec submodules" +imagespec_tarball=$(sb_fetch_and_verify "$IMAGE_SPEC_SRC_URL" "$IMAGE_SPEC_SRC_SHA256" "image-spec-$IMAGE_SPEC_COMMIT.tar.gz") +rm -rf "$srcdir/libocispec/image-spec" +mkdir -p "$srcdir/libocispec/image-spec" +tar -xf "$imagespec_tarball" -C "$srcdir/libocispec/image-spec" --strip-components=1 + +runtimespec_tarball=$(sb_fetch_and_verify "$RUNTIME_SPEC_SRC_URL" "$RUNTIME_SPEC_SRC_SHA256" "runtime-spec-$RUNTIME_SPEC_COMMIT.tar.gz") +rm -rf "$srcdir/libocispec/runtime-spec" +mkdir -p "$srcdir/libocispec/runtime-spec" +tar -xf "$runtimespec_tarball" -C "$srcdir/libocispec/runtime-spec" --strip-components=1 + +# crun.c unconditionally #includes git-version.h. Its own Makefile only +# generates that file from `git describe` (needs .git, which a plain +# tarball checkout never has) or, failing that, from a pre-existing +# .tarball-git-version.h — the file crun's own `make dist` would have +# written. We're not running `make dist`, so write it ourselves in the +# exact format that Makefile target expects; this is the documented +# fallback path, not a workaround around it. +printf '/* autogenerated. */\n#ifndef GIT_VERSION\n# define GIT_VERSION "%s"\n#endif\n' "$VERSION" \ + > .tarball-git-version.h echo "==> [crun] autogen + configure" ./autogen.sh diff --git a/packages/podman/podman.SlackBuild b/packages/podman/podman.SlackBuild index 8d8f388..2e8dfdd 100755 --- a/packages/podman/podman.SlackBuild +++ b/packages/podman/podman.SlackBuild @@ -50,6 +50,18 @@ export BUILDTAGS="seccomp exclude_graphdriver_btrfs exclude_graphdriver_devicema export CGO_ENABLED=1 export GOFLAGS="${GOFLAGS:--mod=mod}" +# podman's own Makefile wants to build ITS bundled copy of go-md2man from +# test/tools/vendor/ for doc generation, but that vendor tree isn't +# consistent enough to build standalone outside podman's own module scope +# ("without -mod=vendor, directory ... has no package path"). Its Makefile +# only attempts that build if test/tools/build/go-md2man doesn't already +# exist — pre-seed it with our own system go-md2man (installed in +# scripts/ci/setup-slackware-buildenv.sh) to skip the broken vendor build +# entirely; it's the same tool doing the same job. +mkdir -p test/tools/build +cp "$(command -v go-md2man)" test/tools/build/go-md2man +chmod +x test/tools/build/go-md2man + echo "==> [podman] make (BUILDTAGS=$BUILDTAGS)" make BUILDTAGS="$BUILDTAGS" GO_BUILD_FLAGS="-ldflags -s" diff --git a/scripts/ci/setup-slackware-buildenv.sh b/scripts/ci/setup-slackware-buildenv.sh index 894b9ee..98464eb 100755 --- a/scripts/ci/setup-slackware-buildenv.sh +++ b/scripts/ci/setup-slackware-buildenv.sh @@ -78,7 +78,7 @@ if command -v slackpkg > /dev/null 2>&1; then gcc gcc-g++ binutils make m4 perl autoconf automake libtool pkg-config \ curl nghttp2 brotli cyrus-sasl ca-certificates glib2 libcap fuse3 \ cmake libarchive lz4 libxml2 guile gc kernel-headers flex elfutils \ - python3 + python3 json-c else echo "==> slackpkg not found, assuming toolchain is already provided by the base image" fi @@ -104,6 +104,7 @@ require_binary python3 "Needed by crun's configure script (checks for Python >= require_pkgconfig glib-2.0 "Install Slackware's glib2 package (needed by conmon)." require_pkgconfig libcap "Install Slackware's libcap package (needed by crun)." || true require_pkgconfig fuse3 "Install Slackware's fuse3 package (needed by fuse-overlayfs)." || true +require_pkgconfig json-c "Install Slackware's json-c package (needed by crun, >= 0.14)." || true # ----------------------------------------------------------------------------- # 3. libseccomp — not part of stock Slackware, build from source if missing. diff --git a/versions.env b/versions.env index 862c000..08b41cf 100644 --- a/versions.env +++ b/versions.env @@ -37,6 +37,31 @@ CRUN_VERSION="1.28" CRUN_SRC_URL="https://github.com/containers/crun/archive/refs/tags/${CRUN_VERSION}.tar.gz" CRUN_SRC_SHA256="90284c7f097f8ee72a6447978c263e1b1355727c2f2ca0ac667e6d57788f46f5" +# crun's build depends on the libocispec git submodule, which GitHub's +# source archive (fetched above) never includes — a plain tarball has no +# .git directory for `git submodule update` to work against, so that has +# to be fetched as its own separate pinned source instead. Commit pinned +# to exactly what crun 1.28 references (verified via +# `curl https://api.github.com/repos/containers/crun/contents/libocispec?ref=1.28`); +# re-derive it the same way whenever CRUN_VERSION changes. +LIBOCISPEC_COMMIT="8034d0ecd27f646ba3ffae5ff24db234ce062825" +LIBOCISPEC_SRC_URL="https://github.com/containers/libocispec/archive/${LIBOCISPEC_COMMIT}.tar.gz" +LIBOCISPEC_SRC_SHA256="3e9170e54ddf487dc087ff1b88d0722e134a206cf36bba87cc946819ccf036ab" + +# libocispec itself has two more git submodules (same problem, one level +# deeper) — its own generate.py needs both schema trees present at build +# time. Commits pinned to exactly what the LIBOCISPEC_COMMIT above +# references (verified the same way, via +# `curl https://api.github.com/repos/containers/libocispec/contents/image-spec?ref=$LIBOCISPEC_COMMIT` +# and .../runtime-spec?ref=...). +IMAGE_SPEC_COMMIT="26647a49f642c7d22a1cd3aa0a48e4650a542269" +IMAGE_SPEC_SRC_URL="https://github.com/opencontainers/image-spec/archive/${IMAGE_SPEC_COMMIT}.tar.gz" +IMAGE_SPEC_SRC_SHA256="8668357de6a1162220b2d1fb654a4182a55844b90ad2774c3b99640eec7e2f54" + +RUNTIME_SPEC_COMMIT="d64c1d945da7cf6970061c7c9ff4391fafdf2a15" +RUNTIME_SPEC_SRC_URL="https://github.com/opencontainers/runtime-spec/archive/${RUNTIME_SPEC_COMMIT}.tar.gz" +RUNTIME_SPEC_SRC_SHA256="1698ebaa7ff07f8409c084fe9539d0391820e71b7a6e6d877aa1ce8b383a4b50" + # --- netavark -------------------------------------------------------------- # https://github.com/containers/netavark NETAVARK_VERSION="2.0.0"