| Age | Commit message (Collapse) | Author | Files | Lines |
|
Binary-repack packages (metasploit-framework-bin) need a post-install step on
the host: install the package, then regenerate artifacts that require a live
install (msfvenom bash-completion, man pages). This repo is deliberately outside
the buildsystem workflow, so producing that package meant a manual root build
here. --keep instead copies the built target .txz out to <data>/kept/ (path
printed) so it can be installed on the host directly from a normal test run. The
build is otherwise throwaway; deps are unaffected.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
The dep cache was keyed on image digest alone, so a nightly image rebuild
orphaned the old digest's cache dir forever (disk creep). Namespace it as
<variant>-<digest> and, on each run, prune superseded digests of the SAME
variant. Scoping to the variant means a --current run does not wipe the 15.0
cache, so testing both trees back-to-back still reuses built deps (e.g.
google-go-lang). Correctness was already fine (digest self-invalidates); this
just stops the accumulation, matching sbo-batch-test's invalidate-on-base-update.
Add three prune self-checks.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
The main loop runs build_variant in an `if ! (...)` condition, which
suppresses set -e inside the subshell, so a failed docker build fell through
to push a nonexistent tag and log "Done" (seen live: a transient containerd
export lock reported success). Add explicit exit checks on docker build and
docker push in all three scripts; return non-zero so the variant is marked
failed.
Also prune the build cache before a --force full-image build: --force already
implies --no-cache, so the stale cache is dead weight that still loads the
snapshotter's lock bookkeeping and has raced the layer export. Best-effort,
never fails the build.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
The tool resolved the target package from the SBo tree, so it tested the
already-published version, not the local edit under test. Useless for the
maintenance workflow, where the point is to verify an edited SlackBuild while
its deps come from the tree.
resolve_target_dir now takes the target from where you are:
- a path (absolute, ./x, or containing /): that dir
- a bare name: ./<name>/ under CWD, else CWD itself if it IS <name>/
Repo-agnostic; deps still resolve from the configured SBo tree via
find_slackbuild_dir. Add four target-resolution self-checks.
Also source /etc/profile.d/*.sh in the build container before running the
SlackBuild: the heredoc is a non-login shell, so a bare `go build` picked the
system gccgo 1.18 instead of the installed google-go-lang; sourcing profile.d
activates dep-provided env (GOROOT/PATH, cargo, ...) as a real login build would.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Tree syncs moved earlier (01:00, 02:00), so the image chain runs earlier too
and both variants are ready well before the ~09:00 work start: -current
03:00/03:20/04:30 (ready ~04:35), 15.0 05:00/05:20/06:30 (ready ~06:35).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
All three scripts self-gate (ChangeLog hash, base digest, full digest + .txz
hash), so --force was forcing needless full rebuilds. Drop it: unchanged
nights are now cheap no-ops. Add the 15.0 variant (09:00/09:20/11:00), which
on frozen stable rebuilds only when the 15.0 repo actually changes. -current
stays at 06:00/06:20/08:00.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
The nightly chain on docker.noland.dnx runs after the NAS repo syncs (04:00,
05:00): bootstrap 06:00, full-image 06:20 (~55 min), testbuild 08:00. Also add
the --version current --force flags the deployed crontab actually uses.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
require_image now docker-pulls ACTIVE_IMAGE (a fully-qualified registry ref)
if it is not already local, instead of erroring out and telling the user to
pull by hand. Only errors if the pull itself fails. Pull-if-missing only: a
stale local tag is not refreshed (noted for a future --pull flag).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Two bugs surfaced by the first real end-to-end run:
1. docker run lacked -i, so bash -s got no stdin and the heredoc build script
was silently discarded (0s BUILD-FAILED, empty log). Add -i.
2. sbopkglint ran host-side, where it shells out to sudo to installpkg the
package for inspection; Slackware has no configured sudo, so lint errored
(lxsudo not found / password required). Move the lint into the build
container (target only, gated on IS_TARGET), where it runs as root with the
baked-in tool and needs no sudo. The host now just reads the LINT-CLEAN /
LINT-FINDINGS marker from the log for its summary. Drop the dead host-side
lint_pkg function.
Verified: feroxbuster builds and lints clean end-to-end against
sbo-testbuild:current in 72s.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Previously drop: only filtered the resolved build order, so an external dep
with no dir in the tree (a 15.0-only SBo package like rust-opt) was flagged
UNMET before the order filter ran, and drop: could never rescue it. Move the
OV_DROP check into _resolve_visit: a dropped token is now skipped entirely
(no recurse, no UNMET, no order entry), satisfying 15.0-only deps that the
-current base already provides. Still inert on 15.0. Add self-check coverage
and clarify overrides.example.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Replace the stub with a lazy load of the active image's /var/log/packages:
strip each entry's -<ver>-<arch>-<build> tail to the bare package name and
match REQUIRES tokens against that set, so a dep the full-install image
already provides resolves as met instead of UNMET. Loaded once per run via
docker run --rm; TB_BASE_PKGS/TB_BASE_LOADED are test-seedable to bypass
docker. Add logic-check coverage.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
The full-image build pulled the entire Slackware tree from slackware.nl over
WAN: slow (40+ min), flaky (truncated .asc downloads), and it wedged the
legacy builder. The identical tree is on LAN NFS, so serve it to the build
container instead.
- config: add HTTP_MIRROR_HOST/PORT (docker0 bridge gateway + ephemeral port).
- bootstrap.sh: bake the LAN HTTP mirror URL into the base image instead of
slackware.nl, so the full build inherits it.
- build-full-image.sh: start an ephemeral python3 http.server rooted at the
variant NFS tree on the bridge for the build duration, killed via the EXIT
trap; require_mount so an unmounted NAS fails loud; wait for the server
before building.
Also fix a silent-failure bug: without importing the Slackware GPG key against
the mirror first, slackpkg cannot verify CHECKSUMS.md5 and installs almost
nothing (94 packages instead of ~1788). Add "slackpkg update gpg" as the first
Dockerfile step; verified the package count jumps 94 -> 1788 with it.
Fetch is incremental (slackpkg downloads only installed packages), unlike the
buildkit --build-context path which eagerly copies the whole multi-GB tree.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
bootstrap fed slackpkg update gpg with "yes YES |". When slackpkg exits
first (key already valid), yes takes SIGPIPE and, under set -e/pipefail,
the pipeline reports non-zero even though the key import succeeded, firing
a bogus "slackpkg GPG update failed" warning on every run.
Read slackpkg own status via PIPESTATUS[1] instead of the pipeline status,
inside an if so set -e/pipefail does not abort on the SIGPIPE; capture
PIPESTATUS as the first command in each branch so no intervening command
resets it. Verified: warning gone on re-run, key still imports.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Upstream sbopkg ships as .tgz, not .txz. The require_pkgs guard, txz_hash
find, cp staging, and Dockerfile COPY all hard-coded *.txz, so a .tgz
package failed the presence check and was excluded from the rebuild hash.
Widen every glob to *.t?z (matches .txz/.tgz/.tbz/.tlz); stage the whole
pkgs dir into the image and installpkg the lot, dropping the in-image
extension coupling entirely.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
|
|
|
|
Add nvchecker stanzas for the seven packages moved from pentesting-suite
(SecLists, ffuf, gobuster, exploitdb, nuclei, feroxbuster,
metasploit-framework-bin) and a Build Strategies section covering Go/Rust
source builds, .deb repacks, and data packages, plus the metasploit
msfvenom-completion and man-page regeneration procedures.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
SBo-official packages maintained by danix, split out of my-slackbuilds.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|