From f56704a7fb7147136a0ab10532e0a65bf5651681 Mon Sep 17 00:00:00 2001 From: magges Date: Sat, 11 Jul 2026 13:57:19 +0000 Subject: [PATCH] Fix CI: install git in the Slackware build container before checkout vbatts/slackware:15.0 ships neither git nor its runtime shared libs (nghttp2, brotli, cyrus-sasl) or ca-certificates, so actions/checkout was failing immediately with "base image is missing git/tar". Install git and its dependencies from Slackware's own official mirror, pinned by exact filename and verified SHA256, and build the CA bundle so git can trust HTTPS remotes. Verified end-to-end against the real Gitea instance (git ls-remote succeeds) in a fresh vbatts/slackware:15.0 container. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/build-packages.yml | 53 ++++++++++++++++++++++++++-- 1 file changed, 50 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build-packages.yml b/.github/workflows/build-packages.yml index 0f73237..9f223c3 100644 --- a/.github/workflows/build-packages.yml +++ b/.github/workflows/build-packages.yml @@ -46,8 +46,27 @@ on: # pin by digest) if the project standardizes on a different/self-hosted # base image. See scripts/ci/setup-slackware-buildenv.sh for how missing # build dependencies are bootstrapped on top of whatever this image ships. +# +# vbatts/slackware:15.0 ships tar but NOT git (needed by actions/checkout) +# or any of git's runtime dependencies. The "Install git" step below pulls +# git and its missing shared libraries from Slackware's own official +# package mirror, pinned by exact filename + verified SHA256, before +# actions/checkout runs — see that step for the full dependency chain +# (found by trial: git needs libnghttp2, which needs nothing extra, but +# git also dlopens libbrotlidec and libsasl2 for HTTPS transport). env: SLACKWARE_IMAGE: "vbatts/slackware:15.0" + SLACKWARE_MIRROR: "http://slackware.osuosl.org/slackware64-15.0/slackware64" + GIT_PKG: "d/git-2.35.1-x86_64-1.txz" + GIT_PKG_SHA256: "502a8e921c13a3e89fa121d26e6e376bd927b05e5a2d1039c1bf815ab6ec535d" + CA_CERTIFICATES_PKG: "n/ca-certificates-20211216-noarch-1.txz" + CA_CERTIFICATES_PKG_SHA256: "e26e8e1371dd5f4f53978cef0449542e7e56b26d1813dcbc546159b551939a91" + NGHTTP2_PKG: "n/nghttp2-1.46.0-x86_64-1.txz" + NGHTTP2_PKG_SHA256: "cad5c7b38ae424b3f44b707637623f740da45a1d1f9938933dc472f931d2bddc" + BROTLI_PKG: "l/brotli-1.0.9-x86_64-7.txz" + BROTLI_PKG_SHA256: "f20e995cce0cf5c4f2575f94e87978e6e5f7d3923e847e3bca814e7c324bd474" + CYRUS_SASL_PKG: "n/cyrus-sasl-2.1.27-x86_64-7.txz" + CYRUS_SASL_PKG_SHA256: "b613130758ec952b8585e03f5174c924bc8bfc6d90aa6c53e7e73a30c6801b68" jobs: build: @@ -58,10 +77,38 @@ jobs: outputs: artifact-name: ${{ steps.artifact-name.outputs.value }} steps: - - name: Install git and tar (needed before actions/checkout can run) + - name: Install git (needed before actions/checkout can run) run: | - (command -v git && command -v tar) || \ - (echo "!! base image is missing git/tar — see SLACKWARE_IMAGE in this workflow" && exit 1) + set -eu + command -v tar > /dev/null || (echo "!! base image is missing tar — see SLACKWARE_IMAGE in this workflow" && exit 1) + + cd /tmp + for pkg in "$CA_CERTIFICATES_PKG" "$NGHTTP2_PKG" "$BROTLI_PKG" "$CYRUS_SASL_PKG" "$GIT_PKG"; do + wget -q --tries=3 "$SLACKWARE_MIRROR/$pkg" + done + echo "${CA_CERTIFICATES_PKG_SHA256} $(basename "$CA_CERTIFICATES_PKG")" | sha256sum -c - + echo "${NGHTTP2_PKG_SHA256} $(basename "$NGHTTP2_PKG")" | sha256sum -c - + echo "${BROTLI_PKG_SHA256} $(basename "$BROTLI_PKG")" | sha256sum -c - + echo "${CYRUS_SASL_PKG_SHA256} $(basename "$CYRUS_SASL_PKG")" | sha256sum -c - + echo "${GIT_PKG_SHA256} $(basename "$GIT_PKG")" | sha256sum -c - + + # installpkg has no dependency resolver (unlike slackpkg) — install + # git's runtime libs first, then git itself. + installpkg "$(basename "$CA_CERTIFICATES_PKG")" + installpkg "$(basename "$NGHTTP2_PKG")" + installpkg "$(basename "$BROTLI_PKG")" + installpkg "$(basename "$CYRUS_SASL_PKG")" + installpkg "$(basename "$GIT_PKG")" + + # ca-certificates ships individual certs under + # /usr/share/ca-certificates/ — this builds the combined bundle + # git needs to actually trust HTTPS remotes (without it, cloning + # from a Gitea instance over HTTPS fails cert verification even + # though the certs are installed). + update-ca-certificates + echo "GIT_SSL_CAINFO=/etc/ssl/certs/ca-certificates.crt" >> "$GITHUB_ENV" + + git --version - uses: actions/checkout@v4