Skip to content

tkldev-setup: build the bootstrap locally when it cannot be downloaded, verify the right file - #1

Merged
marcos-mendez merged 9 commits into
masterfrom
fix/build-missing-bootstrap
Sep 26, 2026
Merged

marcos-mendez merged 9 commits into
masterfrom
fix/build-missing-bootstrap

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Problem: on a fresh TKLDev 19.0 the 40tkldev first-boot hook (tkldev-setup core) died with a 404 because bootstrap-trixie-amd64.tar.gz was never published on the mirror, and nothing could be built; with a mirror that has the tarball (bookworm) the download aborted on signature-verify because it was pointed at the bootstrap directory instead of the tarball.

Diagnosis: the closing bracket of a dirname call had moved (78e7142 upstream), so signature-verify received /turnkey/fab/bootstraps/- and its .hash, which do not exist; and the script had no fallback when the tarball or its .hash cannot be downloaded.

Fix: verify the tarball, not its directory; when the download fails, clone or update turnkeylinux/bootstrap next to FAB_PATH and 'make install' it, as bt-bootstrap does (default: warn and build; --strict: fail as before; --transition: warn and skip, without verifying files that were never downloaded). The script now defines its functions first, returns early when sourced, and takes TKLBAM_PATH like BT_PATH and FAB_PATH so a run can be pointed at a scratch tree. The last commit makes tests/coverage.sh read COVERAGE_THRESHOLD, the variable the reusable workflow exports.

Tests: 63 bats with git, wget, apt-get, make, lsb_release, turnkey-version, dpkg, id and signature-verify stubbed on PATH; tests/coverage.sh under kcov: tkldev-setup 185/186 lines (99.46 percent; the missing line is the continuation of a two-line warning call). On a TKLDev 19.0 VM with the trixie bootstrap removed: default builds and installs it in 81 s, --strict exits 1, --transition skips; a bookworm download verifies and unpacks.

Serves BRIEF section 8 (the build host must build from the organization) and the M0 gate of docs/m0-gate.md.

marcos-mendez and others added 9 commits September 22, 2026 15:44
… dir

78e7142 moved the closing bracket to the end of the path, so
$(dirname "$BOOTSTRAP_PATH/$bootstrap_tar") returns $BOOTSTRAP_PATH itself
and signature-verify is called on /turnkey/fab/bootstraps/<codename>-<arch>
(and .hash), which do not exist. With bash -e this aborts tkldev-setup on
every bootstrap download:

    FATAL [signature-verify]: file &/or hashfile not found
    (/turnkey/fab/bootstraps/bookworm-amd64 / .../bookworm-amd64.hash)

Tested with RELEASE=debian/bookworm: GPG and checksum verification pass and
the bootstrap is unpacked.
19.0 shipped without bootstrap-trixie-amd64.tar.gz on the mirror, so on a
fresh TKLDev 19.0 the 40tkldev firstboot hook (tkldev-setup core) dies with
a 404 and leaves no bootstrap, and nothing can be built.

When the tarball (or its .hash) can't be downloaded, build it with the
bootstrap repo instead, the same way bt-bootstrap does: clone or update
turnkeylinux/bootstrap next to FAB_PATH and run 'make install'.

- default: warn and build locally
- --strict: fail, as before
- --transition: warn and skip, as before; it no longer goes on to verify
  files that were never downloaded

Tested on a TKLDev 19.0 VM with the trixie bootstrap removed: default builds
and installs it (81s), --strict exits 1, --transition skips; a bookworm
download still verifies and unpacks.
No behaviour change: the block that downloads (or builds) the bootstrap
now lives in setup_bootstrap(), called from the same place.
Pure move plus a guard: all functions now come first, and the file
returns early when sourced instead of executed, so a test can load the
functions without running the setup. Executed directly, the order of
operations is unchanged.
TKLBAM_PATH (default /turnkey/tklbam-profiles) joins BT_PATH and
FAB_PATH, so a run can be pointed at a scratch tree end to end.
63 tests under tests/: option parsing and the main body run the whole
script, resolve_ref, update_repo, clone_or_update, setup_bootstrap and
build_bootstrap are sourced and called one at a time. git, wget,
apt-get, make, lsb_release, turnkey-version, dpkg, id and
signature-verify are stubs in tests/stubs that record their arguments;
FAB_PATH, BT_PATH and TKLBAM_PATH point at a scratch directory.

Run with: bats tests/
Runs the bats suite under kcov and fails below the threshold for
tkldev-setup. Measured on a TKLDev 19 host: 99.46 percent (185 of 186
lines); the remaining line is the continuation of a two-line warning
call, which bash reports on its first line only.
The reusable workflow test-shell.yml exports the caller's threshold as
COVERAGE_THRESHOLD and runs the script without arguments, so the script
enforced its own default (95) whatever the workflow said. The positional
argument still wins, the environment variable comes next, 95 remains the
fallback.
@marcos-mendez
marcos-mendez merged commit 994ecf4 into master Sep 26, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant