fix(bootstrap): keep the nano build toolchain under /opt/felis
The source build of the nano binary installed Go at /usr/local/go and replaced whatever version was already there. On a host that also builds other things, the operator's own toolchain was removed and swapped for Felis's pinned version without a word. GOROOT_DIR is now /opt/felis/go, next to the source, the Velocity install and the JRE Felis already keeps under /opt/felis, and install_go_toolchain creates the parent before unpacking. A host where an earlier run put Go at /usr/local/go downloads it once more on the next re-run and keeps the old tree untouched; removing it is the operator's call. The harness now requires the toolchain directory to be under /opt/felis.
This commit is contained in:
2 files changed
+13
-3
No files matched your search
+4
-1
@@ -200,7 +200,9 @@ PANEL_TLS_CERT="${STATE_DIR}/panel-tls.crt"
|
||||
PANEL_TLS_KEY="${STATE_DIR}/panel-tls.key"
|
||||
SRC_DIR="/opt/felis/src"
|
||||
HOST_BIN="/usr/local/bin/felis"
|
||||
GOROOT_DIR="/usr/local/go"
|
||||
# Felis's own build toolchain, not /usr/local/go: install_go_toolchain replaces whatever
|
||||
# version sits here, and an operator's Go at the conventional path is not ours to swap.
|
||||
GOROOT_DIR="/opt/felis/go"
|
||||
NANO_SERVICE="/etc/systemd/system/felis-nano.service"
|
||||
VELOCITY_DIR="/opt/felis/velocity"
|
||||
VELOCITY_USER="felis-velocity"
|
||||
@@ -2321,6 +2323,7 @@ install_go_toolchain() {
|
||||
have="$(sha256sum <"${tmp}/${tarball}" | cut -d' ' -f1)"
|
||||
[ "$have" = "$want" ] || die "Go ${FELIS_GO_VERSION} (${arch}) checksum mismatch: got ${have}, expected ${want}"
|
||||
rm -rf "$GOROOT_DIR"
|
||||
mkdir -p "$(dirname "$GOROOT_DIR")"
|
||||
tar -C "$(dirname "$GOROOT_DIR")" -xzf "${tmp}/${tarball}" || die "failed to unpack ${tarball}"
|
||||
ok "go toolchain at ${GOROOT_DIR}/bin/go"
|
||||
}
|
||||
|
||||
@@ -473,8 +473,15 @@ else
|
||||
fi
|
||||
|
||||
# --- install_go_toolchain checks the tarball before it replaces anything ----------------
|
||||
# The tarball is unpacked into /usr/local and run as root, so a download that does not hash
|
||||
# to the pin is refused -- and refused before the working toolchain is removed.
|
||||
# The tarball is unpacked and run as root, so a download that does not hash to the pin is
|
||||
# refused -- and refused before the working toolchain is removed.
|
||||
|
||||
# The function replaces whatever version sits at GOROOT_DIR, so that has to be a directory
|
||||
# Felis owns, never an operator's /usr/local/go.
|
||||
case "$(grep '^GOROOT_DIR=' "$BS")" in
|
||||
'GOROOT_DIR="/opt/felis/'*) echo "PASS the Go toolchain lives under /opt/felis" ;;
|
||||
*) echo "FAIL the Go toolchain must live under /opt/felis, got: $(grep '^GOROOT_DIR=' "$BS")"; fails=$((fails + 1)) ;;
|
||||
esac
|
||||
|
||||
gblock="$(awk '/^install_go_toolchain\(\) \{/,/^}/' "$BS")"
|
||||
[ -n "$gblock" ] || { echo "FAIL: no install_go_toolchain found in $BS"; exit 1; }
|
||||
|
||||
Reference in new issue
Block a user