fix(bootstrap): keep the nano build toolchain under /opt/felis
The source build of the nano binary installed Go at /usr/local/go and replaced whatever version was already there. On a host that also builds other things, the operator's own toolchain was removed and swapped for Felis's pinned version without a word. GOROOT_DIR is now /opt/felis/go, next to the source, the Velocity install and the JRE Felis already keeps under /opt/felis, and install_go_toolchain creates the parent before unpacking. A host where an earlier run put Go at /usr/local/go downloads it once more on the next re-run and keeps the old tree untouched; removing it is the operator's call. The harness now requires the toolchain directory to be under /opt/felis.
This commit is contained in:
2 files changed
+13
-3
No files matched your search
+4
-1
@@ -200,7 +200,9 @@ PANEL_TLS_CERT="${STATE_DIR}/panel-tls.crt"
|
|||||||
PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key"
|
PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key"
|
||||||
SRC_DIR="/opt/felis/src"
|
SRC_DIR="/opt/felis/src"
|
||||||
HOST_BIN="/usr/local/bin/felis"
|
HOST_BIN="/usr/local/bin/felis"
|
||||||
GOROOT_DIR="/usr/local/go"
|
# Felis's own build toolchain, not /usr/local/go: install_go_toolchain replaces whatever
|
||||||
|
# version sits here, and an operator's Go at the conventional path is not ours to swap.
|
||||||
|
GOROOT_DIR="/opt/felis/go"
|
||||||
NANO_SERVICE="/etc/systemd/system/felis-nano.service"
|
NANO_SERVICE="/etc/systemd/system/felis-nano.service"
|
||||||
VELOCITY_DIR="/opt/felis/velocity"
|
VELOCITY_DIR="/opt/felis/velocity"
|
||||||
VELOCITY_USER="felis-velocity"
|
VELOCITY_USER="felis-velocity"
|
||||||
@@ -2321,6 +2323,7 @@ install_go_toolchain() {
|
|||||||
have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)"
|
have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)"
|
||||||
[ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}"
|
[ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}"
|
||||||
rm -rf "$GOROOT_DIR"
|
rm -rf "$GOROOT_DIR"
|
||||||
|
mkdir -p "$(dirname "$GOROOT_DIR")"
|
||||||
tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}"
|
tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}"
|
||||||
ok "go toolchain at ${GOROOT_DIR}/bin/go"
|
ok "go toolchain at ${GOROOT_DIR}/bin/go"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -473,8 +473,15 @@ else
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# --- install_go_toolchain checks the tarball before it replaces anything ----------------
|
# --- install_go_toolchain checks the tarball before it replaces anything ----------------
|
||||||
# The tarball is unpacked into /usr/local and run as root, so a download that does not hash
|
# The tarball is unpacked and run as root, so a download that does not hash to the pin is
|
||||||
# to the pin is refused -- and refused before the working toolchain is removed.
|
# refused -- and refused before the working toolchain is removed.
|
||||||
|
|
||||||
|
# The function replaces whatever version sits at GOROOT_DIR, so that has to be a directory
|
||||||
|
# Felis owns, never an operator's /usr/local/go.
|
||||||
|
case "$(grep '^GOROOT_DIR=' "$BS")" in
|
||||||
|
'GOROOT_DIR="/opt/felis/'*) echo "PASS the Go toolchain lives under /opt/felis" ;;
|
||||||
|
*) echo "FAIL the Go toolchain must live under /opt/felis, got: $(grep '^GOROOT_DIR=' "$BS")"; fails=$((fails + 1)) ;;
|
||||||
|
esac
|
||||||
|
|
||||||
gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")"
|
gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")"
|
||||||
[ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; }
|
[ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; }
|
||||||
|
|||||||
Reference in new issue
Block a user