Skip to content

Commit aa8e062

Browse files
framefilterclaude
andcommitted
ci(image): patch upstream OpenWRT 25.12 Image Builder rootfs.mk bug
Run 25749740914 failed in Image Builder's prepare_rootfs step with a bash syntax error in code we didn't write. Root-caused upstream: in include/rootfs.mk on openwrt-25.12 and main both, the recipe wraps opkg-only fixups in `if [ -z "$(CONFIG_USE_APK)" ]; then ... fi`, where the body is two `$(if ...)` substitutions. Under apk builds (CONFIG_USE_APK=y) the `then` branch is never executed at runtime, but bash still has to *parse* it. In Image Builder context (IB=y) the awk substitution collapses to empty, and bash sees the rendered recipe as: if [ -z "y" ]; then ; sed -i "..." ; fi — an empty `then` body before `;` is a syntax error. Same broken recipe in openwrt-25.12 and main; no upstream issue or PR reported. Affects any 25.12.x Image Builder consumer with SOURCE_DATE_EPOCH set (Image Builder appears to set it automatically). Verified our side is clean: the apk install reported "OK: 67.4 MiB in 171 packages", which means our DEPENDS:= against the 25.12.3 feed resolves correctly. The crash is downstream of every line of our code. Workaround: new `Patch Image Builder rootfs.mk` step inserts a `: ;` no-op so the `then` block has at least one parseable statement regardless of which Make substitutions collapse. Patch is local to this CI run's Image Builder copy; nothing leaves the runner; no fork of openwrt/openwrt. A grep-after-sed fails the build if upstream ever changes the recipe shape so we notice instead of silently doing nothing. Also drops `yubikey-personalization` from the dep-list comment in the prior staging step, in line with the WebAuthn-only auth model that landed in 6cc71b7. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 1bdd6d8 commit aa8e062

1 file changed

Lines changed: 35 additions & 3 deletions

File tree

‎.github/workflows/package.yml‎

Lines changed: 35 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -246,13 +246,45 @@ jobs:
246246
# picked up as a local repo; `make image` indexes them before
247247
# resolving PACKAGES. Transitive deps of bubbleui (nginx-ssl,
248248
# nftables, wireguard-tools, dnsmasq-full, https-dns-proxy,
249-
# yubikey-personalization, ca-bundle, px5g-mbedtls — see
250-
# package/bubbleui/Makefile) come from the upstream 25.12.3
251-
# feed, also indexed automatically by Image Builder.
249+
# ca-bundle, px5g-mbedtls — see package/bubbleui/Makefile)
250+
# come from the upstream 25.12.3 feed, also indexed
251+
# automatically by Image Builder.
252252
mkdir -p "$IB/packages"
253253
cp bubbleui-pkg/bubbleui-*.apk "$IB/packages/"
254254
ls -la "$IB/packages/"
255255
256+
- name: Patch Image Builder rootfs.mk (upstream OpenWRT 25.12 bug)
257+
env:
258+
IB: ${{ steps.ib.outputs.ib_dir }}
259+
run: |
260+
set -e
261+
# OpenWRT 25.12.x Image Builder's prepare_rootfs recipe in
262+
# include/rootfs.mk wraps opkg-only fixups inside:
263+
#
264+
# if [ -z "$(CONFIG_USE_APK)" ]; then \
265+
# $(if $(IB),,awk -i inplace ...) ; \
266+
# $(if $(SOURCE_DATE_EPOCH),sed -i ... ;) \
267+
# fi;
268+
#
269+
# Under apk builds (CONFIG_USE_APK=y) the `then` branch is
270+
# never executed at runtime, but bash still has to *parse* it.
271+
# In Image Builder context (IB=y) the awk substitution
272+
# collapses to empty, leaving `then ; sed ... ; fi` — bash
273+
# refuses an empty body before the `;` and the whole rootfs
274+
# prepare step dies with a syntax error. Same recipe on
275+
# `openwrt-25.12` and `main` of openwrt/openwrt as of
276+
# 2026-05-12; no upstream fix.
277+
#
278+
# Workaround: insert a `: ;` no-op so the `then` block parses
279+
# regardless of which Make substitutions are empty. Patch is
280+
# local to this CI run's Image Builder copy. The grep below
281+
# fails the build if upstream ever changes the recipe shape,
282+
# so we notice instead of silently doing nothing.
283+
target="$IB/include/rootfs.mk"
284+
test -f "$target"
285+
sed -i 's#if \[ -z "$(CONFIG_USE_APK)" \]; then \\#if [ -z "$(CONFIG_USE_APK)" ]; then : ; \\#' "$target"
286+
grep -F 'if [ -z "$(CONFIG_USE_APK)" ]; then : ;' "$target" >/dev/null
287+
256288
- name: Build firmware image
257289
env:
258290
IB: ${{ steps.ib.outputs.ib_dir }}

0 commit comments

Comments
 (0)