diff --git a/patches/pkgbuild/gcc.sh b/patches/pkgbuild/gcc.sh index 42aad10..f2b77f6 100755 --- a/patches/pkgbuild/gcc.sh +++ b/patches/pkgbuild/gcc.sh @@ -259,6 +259,20 @@ grep -A1 '^build() {' PKGBUILD | head -2 | sed 's/^/ /' # is not depended on, and the check below asserts it rather than trusting it. # Adding a name to that set is now enough, in one place. # +# libisl.so is in the same list for a DIFFERENT reason, and the difference is +# worth a sentence. The others are components this PKGBUILD stops building. +# isl is an outside library that gcc simply never linked: the host has no isl, +# so configure recorded ISLLIBS='' and ISLINC='', and the artefact agrees -- +# +# $ readelf -d usr/bin/gcc usr/lib/libgcc_s.so.1 | grep -c libisl +# 0 +# +# The remedy is the same, so the list is the same. Building isl instead was +# the first plan and it does not work: the Arch packaging repo for isl was +# last touched in 2017 and its only source URL is isl.gforge.inria.fr, which +# died with INRIA's GForge. What this costs is Graphite -- the -floop-* +# optimisations -- and TODO.md records it. +# # Both spellings occur: a bare name in a sub-package's depends, and the # versioned "libhwasan=$pkgver-$pkgrel" form in gcc's own. The unused # package_libhwasan() function can stay -- makepkg never calls a function @@ -266,7 +280,10 @@ grep -A1 '^build() {' PKGBUILD | head -2 | sed 's/^/ /' python3 - <<'PY' import io, re drop = ["libhwasan", "libquadmath", "lib32-gcc-libs", - "libgm2", "libgo", "libgphobos", "libgcobol"] + "libgm2", "libgo", "libgphobos", "libgcobol", + # Not a component we dropped -- an EXTERNAL library gcc was never + # configured against. See the note above the list. + "libisl.so"] s = io.open("PKGBUILD", encoding="utf-8").read() def prune(block): diff --git a/patches/pkgbuild/gnutls.sh b/patches/pkgbuild/gnutls.sh new file mode 100755 index 0000000..d5a7334 --- /dev/null +++ b/patches/pkgbuild/gnutls.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash +# gnutls: leancrypto is asked for, and Ubuntu has no such library. +# +# configure: error: leancrypto support was requested but the required +# libraries were not found. +# +# Arch packages leancrypto -- a post-quantum crypto library -- and gnutls +# links it for ML-KEM and ML-DSA. Nothing about s390x prevents it; the build +# host simply cannot supply it, and building leancrypto first would add a +# package to the closure for algorithms pacman does not use. It signs with +# OpenPGP through gpgme, and TLS to the mirrors needs none of this. +# +# TWO PLACES, and the second is the one that bites silently. The configure +# flag is what stops the build, so it is what gets noticed. But 'leancrypto' +# is ALSO in depends=, and --nodeps means makepkg never checks it: gnutls +# would build, pass, and enter the repository asking for a package this port +# will never contain. Same shape as gcc-libs declaring libhwasan, and as make +# declaring guile -- the third instance of it in this port, which is why the +# audit that finds them is now part of the routine rather than an afterthought. +set -euo pipefail +python3 - <<'PY' +import io +s = io.open("PKGBUILD", encoding="utf-8").read() + +# (a) the flag that stops configure. It is the LAST option on the line, with +# no trailing backslash, so the preceding backslash goes with it. +old = " \\\n --with-leancrypto" +assert s.count(old) == 1, "gnutls: expected exactly one --with-leancrypto" +s = s.replace(old, "", 1) + +# (b) the declaration nobody checks +old = "'leancrypto' " +assert s.count(old) == 1, "gnutls: expected exactly one leancrypto in depends" +s = s.replace(old, "", 1) + +io.open("PKGBUILD", "w", encoding="utf-8").write(s) +PY +grep -q 'leancrypto' PKGBUILD && { + echo "gnutls: leancrypto still referenced" >&2; exit 1; } +echo "gnutls: leancrypto dropped from configure AND from depends" diff --git a/patches/pkgbuild/make.sh b/patches/pkgbuild/make.sh new file mode 100755 index 0000000..cfa33e1 --- /dev/null +++ b/patches/pkgbuild/make.sh @@ -0,0 +1,38 @@ +#!/usr/bin/env bash +# make: it declares guile, and our make has no guile in it. +# +# depends=('glibc' 'guile') +# +# GNU make's configure AUTO-DETECTS guile -- the PKGBUILD passes a bare +# `./configure --prefix=/usr` and says nothing about it. This build host has +# no guile at all, so the $(guile ...) function was never compiled in, and the +# artefact says so plainly: +# +# $ readelf -d usr/bin/make | grep NEEDED +# (NEEDED) Shared library: [libc.so.6] +# +# One library. Nothing else. +# +# THE TRAP is that nothing fails. --nodeps means makepkg never checks the +# declaration, so make built, passed, and entered the repository asking for a +# package this port does not have and does not need. It is the same class as +# gcc-libs declaring libhwasan: a dependency that is real in Arch's build +# environment and false in ours, and the only thing that ever notices is +# pacman, at install time, long after the cause. +# +# It is worth the entry it costs. guile drags in bdw-gc and libffi behind it, +# so this single false line was three packages of closure for a feature the +# binary does not contain. +# +# WHY REMOVE RATHER THAN BUILD. Because the declaration should describe THIS +# artefact. Building guile and rebuilding make would be the other honest +# answer and would match Arch exactly -- TODO.md records it as deferred, with +# the cost, so the choice stays visible. What is not defensible is shipping a +# make that claims a feature it lacks. +set -euo pipefail +grep -q "^depends=('glibc' 'guile')$" PKGBUILD || { + echo "make: depends line is not the expected ('glibc' 'guile')" >&2; exit 1; } +sed -i "s/^depends=('glibc' 'guile')$/depends=('glibc')/" PKGBUILD +grep -q "^depends=('glibc')$" PKGBUILD || { + echo "make: guile not removed from depends" >&2; exit 1; } +echo "make: guile dropped from depends (the binary links libc only)"