Unverified Commit 7b5b28c5 authored by Minseong Choi's avatar Minseong Choi 💬
Browse files

fix(bootstrap): keep the nano build toolchain under /opt/felis

The source build of the nano binary installed Go at /usr/local/go and
replaced whatever version was already there. On a host that also
builds other things, the operator's own toolchain was removed and
swapped for Felis's pinned version without a word.

GOROOT_DIR is now /opt/felis/go, next to the source, the Velocity
install and the JRE Felis already keeps under /opt/felis, and
install_go_toolchain creates the parent before unpacking. A host where
an earlier run put Go at /usr/local/go downloads it once more on the
next re-run and keeps the old tree untouched; removing it is the
operator's call. The harness now requires the toolchain directory to
be under /opt/felis.
parent 0faec2b0
Loading
Loading
Loading
Loading
+4 −1
Changes for deploy/bootstrap.sh: 4 added lines, 1 removed line.
Original line number Diff line number Diff line
@@ -200,7 +200,9 @@ PANEL_TLS_CERT="${STATE_DIR}/panel-tls.crt"
PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key"
SRC_DIR="/opt/felis/src"
HOST_BIN="/usr/local/bin/felis"
GOROOT_DIR="/usr/local/go"
# Felis's own build toolchain, not /usr/local/go: install_go_toolchain replaces whatever
# version sits here, and an operator's Go at the conventional path is not ours to swap.
GOROOT_DIR="/opt/felis/go"
NANO_SERVICE="/etc/systemd/system/felis-nano.service"
VELOCITY_DIR="/opt/felis/velocity"
VELOCITY_USER="felis-velocity"
@@ -2321,6 +2323,7 @@ install_go_toolchain() {
  have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)"
  [ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}"
  rm -rf "$GOROOT_DIR"
  mkdir -p "$(dirname "$GOROOT_DIR")"
  tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}"
  ok "go toolchain at ${GOROOT_DIR}/bin/go"
}
+9 −2
Changes for deploy/bootstrap_test.sh: 9 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -473,8 +473,15 @@ else
fi

# --- install_go_toolchain checks the tarball before it replaces anything ----------------
# The tarball is unpacked into /usr/local and run as root, so a download that does not hash
# to the pin is refused -- and refused before the working toolchain is removed.
# The tarball is unpacked and run as root, so a download that does not hash to the pin is
# refused -- and refused before the working toolchain is removed.

# The function replaces whatever version sits at GOROOT_DIR, so that has to be a directory
# Felis owns, never an operator's /usr/local/go.
case "$(grep '^GOROOT_DIR=' "$BS")" in
  'GOROOT_DIR="/opt/felis/'*) echo "PASS the Go toolchain lives under /opt/felis" ;;
  *) echo "FAIL the Go toolchain must live under /opt/felis, got: $(grep '^GOROOT_DIR=' "$BS")"; fails=$((fails + 1)) ;;
esac

gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")"
[ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; }