From e887d1ed0f99fdace6f746699078f6188551ca68 Mon Sep 17 00:00:00 2001 From: "Danilo M." Date: Mon, 13 Jul 2026 18:06:16 +0200 Subject: image-builder: feed full build from LAN NFS mirror over HTTP, fix GPG verify The full-image build pulled the entire Slackware tree from slackware.nl over WAN: slow (40+ min), flaky (truncated .asc downloads), and it wedged the legacy builder. The identical tree is on LAN NFS, so serve it to the build container instead. - config: add HTTP_MIRROR_HOST/PORT (docker0 bridge gateway + ephemeral port). - bootstrap.sh: bake the LAN HTTP mirror URL into the base image instead of slackware.nl, so the full build inherits it. - build-full-image.sh: start an ephemeral python3 http.server rooted at the variant NFS tree on the bridge for the build duration, killed via the EXIT trap; require_mount so an unmounted NAS fails loud; wait for the server before building. Also fix a silent-failure bug: without importing the Slackware GPG key against the mirror first, slackpkg cannot verify CHECKSUMS.md5 and installs almost nothing (94 packages instead of ~1788). Add "slackpkg update gpg" as the first Dockerfile step; verified the package count jumps 94 -> 1788 with it. Fetch is incremental (slackpkg downloads only installed packages), unlike the buildkit --build-context path which eagerly copies the whole multi-GB tree. Co-Authored-By: Claude Opus 4.8 --- .extras/image-builder/build-full-image.sh | 27 ++++++++++++++++++++++++++- 1 file changed, 26 insertions(+), 1 deletion(-) (limited to '.extras/image-builder/build-full-image.sh') diff --git a/.extras/image-builder/build-full-image.sh b/.extras/image-builder/build-full-image.sh index 8c4476e..c5f1c36 100755 --- a/.extras/image-builder/build-full-image.sh +++ b/.extras/image-builder/build-full-image.sh @@ -91,6 +91,8 @@ needs_rebuild() { build_variant() { local VERSION="$1" + local REPO_KEY="slackware64-${VERSION}" + require_mount "${VERSION}" # NFS must be up: we serve it over HTTP below derive_tags "${VERSION}" _log "=== ${FULL_TAG} ===" @@ -110,14 +112,37 @@ build_variant() { local WORKDIR WORKDIR="$(mktemp -d /tmp/slackware-full.XXXXXX)" + + # Serve the NFS mirror over HTTP on the docker bridge for the duration of + # the build, so slackpkg in the build container fetches packages from LAN + # instead of the internet. Killed (with WORKDIR cleanup) on any exit. + local MIRROR_ROOT; MIRROR_ROOT="$(strip_scheme "$(mirror_path "${MIRROR}" "${REPO_KEY}")")" + [[ -f "${MIRROR_ROOT}/PACKAGES.TXT" ]] \ + || _err "mirror root has no PACKAGES.TXT: ${MIRROR_ROOT}" + python3 -m http.server "${HTTP_MIRROR_PORT}" \ + --bind "${HTTP_MIRROR_HOST}" --directory "${MIRROR_ROOT}" \ + >/dev/null 2>&1 & + local HTTP_PID=$! # shellcheck disable=SC2064 - trap "rm -rf '${WORKDIR}'" EXIT + trap "kill ${HTTP_PID} 2>/dev/null; rm -rf '${WORKDIR}'" EXIT + # Wait for the server to accept connections before building. + local i + for i in 1 2 3 4 5 6 7 8 9 10; do + curl -sf -o /dev/null "http://${HTTP_MIRROR_HOST}:${HTTP_MIRROR_PORT}/PACKAGES.TXT" && break + [[ $i -eq 10 ]] && _err "HTTP mirror did not come up on ${HTTP_MIRROR_HOST}:${HTTP_MIRROR_PORT}" + sleep 0.5 + done # Generate the Dockerfile for this variant cat > "${WORKDIR}/Dockerfile" <