diff --git a/deploy/bootstrap.sh b/deploy/bootstrap.sh index cf599e2..ce94f9d 100644 --- a/deploy/bootstrap.sh +++ b/deploy/bootstrap.sh @@ -200,7 +200,9 @@ PANEL_TLS_CERT="${STATE_DIR}/panel-tls.crt" PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key" SRC_DIR="/opt/felis/src" HOST_BIN="/usr/local/bin/felis" -GOROOT_DIR="/usr/local/go" +# Felis's own build toolchain, not /usr/local/go: install_go_toolchain replaces whatever +# version sits here, and an operator's Go at the conventional path is not ours to swap. +GOROOT_DIR="/opt/felis/go" NANO_SERVICE="/etc/systemd/system/felis-nano.service" VELOCITY_DIR="/opt/felis/velocity" VELOCITY_USER="felis-velocity" @@ -2321,6 +2323,7 @@ install_go_toolchain() { have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)" [ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}" rm -rf "$GOROOT_DIR" + mkdir -p "$(dirname "$GOROOT_DIR")" tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}" ok "go toolchain at ${GOROOT_DIR}/bin/go" } diff --git a/deploy/bootstrap_test.sh b/deploy/bootstrap_test.sh index 8a727e2..a3fe0b4 100644 --- a/deploy/bootstrap_test.sh +++ b/deploy/bootstrap_test.sh @@ -473,8 +473,15 @@ else fi # --- install_go_toolchain checks the tarball before it replaces anything ---------------- -# The tarball is unpacked into /usr/local and run as root, so a download that does not hash -# to the pin is refused -- and refused before the working toolchain is removed. +# The tarball is unpacked and run as root, so a download that does not hash to the pin is +# refused -- and refused before the working toolchain is removed. + +# The function replaces whatever version sits at GOROOT_DIR, so that has to be a directory +# Felis owns, never an operator's /usr/local/go. +case "$(grep '^GOROOT_DIR=' "$BS")" in + 'GOROOT_DIR="/opt/felis/'*) echo "PASS the Go toolchain lives under /opt/felis" ;; + *) echo "FAIL the Go toolchain must live under /opt/felis, got: $(grep '^GOROOT_DIR=' "$BS")"; fails=$((fails + 1)) ;; +esac gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")" [ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; }