fix(bootstrap): keep the nano build toolchain under /opt/felis

The source build of the nano binary installed Go at /usr/local/go and
replaced whatever version was already there. On a host that also
builds other things, the operator's own toolchain was removed and
swapped for Felis's pinned version without a word.

GOROOT_DIR is now /opt/felis/go, next to the source, the Velocity
install and the JRE Felis already keeps under /opt/felis, and
install_go_toolchain creates the parent before unpacking. A host where
an earlier run put Go at /usr/local/go downloads it once more on the
next re-run and keeps the old tree untouched; removing it is the
operator's call. The harness now requires the toolchain directory to
be under /opt/felis.
This commit is contained in:
flyemoji committed 2026-09-22 14:59:39 +09:00
1 parent 0faec2b02a
commit 7b5b28c587
2 files changed
+13 -3

No files matched your search

+4 -1
View File
@@ -200,7 +200,9 @@ PANEL_TLS_CERT="${STATE_DIR}/panel-tls.crt"
PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key" PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key"
SRC_DIR="/opt/felis/src" SRC_DIR="/opt/felis/src"
HOST_BIN="/usr/local/bin/felis" HOST_BIN="/usr/local/bin/felis"
GOROOT_DIR="/usr/local/go" # Felis's own build toolchain, not /usr/local/go: install_go_toolchain replaces whatever
# version sits here, and an operator's Go at the conventional path is not ours to swap.
GOROOT_DIR="/opt/felis/go"
NANO_SERVICE="/etc/systemd/system/felis-nano.service" NANO_SERVICE="/etc/systemd/system/felis-nano.service"
VELOCITY_DIR="/opt/felis/velocity" VELOCITY_DIR="/opt/felis/velocity"
VELOCITY_USER="felis-velocity" VELOCITY_USER="felis-velocity"
@@ -2321,6 +2323,7 @@ install_go_toolchain() {
have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)" have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)"
[ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}" [ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}"
rm -rf "$GOROOT_DIR" rm -rf "$GOROOT_DIR"
mkdir -p "$(dirname "$GOROOT_DIR")"
tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}" tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}"
ok "go toolchain at ${GOROOT_DIR}/bin/go" ok "go toolchain at ${GOROOT_DIR}/bin/go"
} }
+9 -2
View File
@@ -473,8 +473,15 @@ else
fi fi
# --- install_go_toolchain checks the tarball before it replaces anything ---------------- # --- install_go_toolchain checks the tarball before it replaces anything ----------------
# The tarball is unpacked into /usr/local and run as root, so a download that does not hash # The tarball is unpacked and run as root, so a download that does not hash to the pin is
# to the pin is refused -- and refused before the working toolchain is removed. # refused -- and refused before the working toolchain is removed.
# The function replaces whatever version sits at GOROOT_DIR, so that has to be a directory
# Felis owns, never an operator's /usr/local/go.
case "$(grep '^GOROOT_DIR=' "$BS")" in
'GOROOT_DIR="/opt/felis/'*) echo "PASS the Go toolchain lives under /opt/felis" ;;
*) echo "FAIL the Go toolchain must live under /opt/felis, got: $(grep '^GOROOT_DIR=' "$BS")"; fails=$((fails + 1)) ;;
esac
gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")" gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")"
[ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; } [ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; }