[FIX] declared, never linked: guile, libisl.so, leancrypto

An audit of every missing dependency spelled as a soname, asking the ARTEFACT
whether the package that declares it actually links it. It contradicted my
guesses: curl's krb5, ssh2 and idn2 are all real. Two were not.

  make      readelf -d usr/bin/make -> libc.so.6, and nothing else
  gcc       configure recorded ISLLIBS='' ISLINC=''; zero libisl in the tree

Both are false in our build environment and true in Arch's. --nodeps means
makepkg never checks, so each shipped a package asking for something this
port will never contain -- and only pacman ever notices, at install time.

Building isl was the first plan. Its Arch packaging repo was last touched in
2017 and its only source URL is isl.gforge.inria.fr, dead with INRIA's
GForge. There is nothing to build; the declaration goes instead, and Graphite
goes with it.

gnutls found the same shape from the other direction: --with-leancrypto
stopped configure, and 'leancrypto' sat in depends= where nothing checks it.

--- FR ---

Un audit de chaque dépendance manquante écrite en soname, demandant à
l'ARTEFACT si le paquet qui la déclare la lie vraiment. Il a contredit mes
suppositions : les krb5, ssh2 et idn2 de curl sont bien réels. Deux ne
l'étaient pas.

  make      readelf -d usr/bin/make -> libc.so.6, et rien d'autre
  gcc       configure a noté ISLLIBS='' ISLINC='' ; aucun libisl dans l'arbre

Les deux sont fausses dans notre environnement et vraies dans celui d'Arch.
--nodeps veut dire que makepkg ne vérifie jamais : chacun livrait donc un
paquet réclamant ce que ce portage ne contiendra jamais — et seul pacman s'en
aperçoit, à l'installation.

Bâtir isl était le premier plan. Son dépôt de packaging Arch n'a pas bougé
depuis 2017 et sa seule source pointe isl.gforge.inria.fr, morte avec le
GForge d'INRIA. Il n'y a rien à bâtir : c'est la déclaration qui part, et
Graphite avec elle.

gnutls a montré la même forme par l'autre bout : --with-leancrypto arrêtait
configure, et 'leancrypto' figurait dans depends= où rien ne le vérifie.

Assisted-by: Claude Opus 5
This commit is contained in:
Mathieu Benoit 2026-08-19 05:28:32 -04:00
parent 2a1997e06d
commit 3c926f10a9
3 changed files with 96 additions and 1 deletions

View file

@ -259,6 +259,20 @@ grep -A1 '^build() {' PKGBUILD | head -2 | sed 's/^/ /'
# is not depended on, and the check below asserts it rather than trusting it. # is not depended on, and the check below asserts it rather than trusting it.
# Adding a name to that set is now enough, in one place. # Adding a name to that set is now enough, in one place.
# #
# libisl.so is in the same list for a DIFFERENT reason, and the difference is
# worth a sentence. The others are components this PKGBUILD stops building.
# isl is an outside library that gcc simply never linked: the host has no isl,
# so configure recorded ISLLIBS='' and ISLINC='', and the artefact agrees --
#
# $ readelf -d usr/bin/gcc usr/lib/libgcc_s.so.1 | grep -c libisl
# 0
#
# The remedy is the same, so the list is the same. Building isl instead was
# the first plan and it does not work: the Arch packaging repo for isl was
# last touched in 2017 and its only source URL is isl.gforge.inria.fr, which
# died with INRIA's GForge. What this costs is Graphite -- the -floop-*
# optimisations -- and TODO.md records it.
#
# Both spellings occur: a bare name in a sub-package's depends, and the # Both spellings occur: a bare name in a sub-package's depends, and the
# versioned "libhwasan=$pkgver-$pkgrel" form in gcc's own. The unused # versioned "libhwasan=$pkgver-$pkgrel" form in gcc's own. The unused
# package_libhwasan() function can stay -- makepkg never calls a function # package_libhwasan() function can stay -- makepkg never calls a function
@ -266,7 +280,10 @@ grep -A1 '^build() {' PKGBUILD | head -2 | sed 's/^/ /'
python3 - <<'PY' python3 - <<'PY'
import io, re import io, re
drop = ["libhwasan", "libquadmath", "lib32-gcc-libs", drop = ["libhwasan", "libquadmath", "lib32-gcc-libs",
"libgm2", "libgo", "libgphobos", "libgcobol"] "libgm2", "libgo", "libgphobos", "libgcobol",
# Not a component we dropped -- an EXTERNAL library gcc was never
# configured against. See the note above the list.
"libisl.so"]
s = io.open("PKGBUILD", encoding="utf-8").read() s = io.open("PKGBUILD", encoding="utf-8").read()
def prune(block): def prune(block):

40
patches/pkgbuild/gnutls.sh Executable file
View file

@ -0,0 +1,40 @@
#!/usr/bin/env bash
# gnutls: leancrypto is asked for, and Ubuntu has no such library.
#
# configure: error: leancrypto support was requested but the required
# libraries were not found.
#
# Arch packages leancrypto -- a post-quantum crypto library -- and gnutls
# links it for ML-KEM and ML-DSA. Nothing about s390x prevents it; the build
# host simply cannot supply it, and building leancrypto first would add a
# package to the closure for algorithms pacman does not use. It signs with
# OpenPGP through gpgme, and TLS to the mirrors needs none of this.
#
# TWO PLACES, and the second is the one that bites silently. The configure
# flag is what stops the build, so it is what gets noticed. But 'leancrypto'
# is ALSO in depends=, and --nodeps means makepkg never checks it: gnutls
# would build, pass, and enter the repository asking for a package this port
# will never contain. Same shape as gcc-libs declaring libhwasan, and as make
# declaring guile -- the third instance of it in this port, which is why the
# audit that finds them is now part of the routine rather than an afterthought.
set -euo pipefail
python3 - <<'PY'
import io
s = io.open("PKGBUILD", encoding="utf-8").read()
# (a) the flag that stops configure. It is the LAST option on the line, with
# no trailing backslash, so the preceding backslash goes with it.
old = " \\\n --with-leancrypto"
assert s.count(old) == 1, "gnutls: expected exactly one --with-leancrypto"
s = s.replace(old, "", 1)
# (b) the declaration nobody checks
old = "'leancrypto' "
assert s.count(old) == 1, "gnutls: expected exactly one leancrypto in depends"
s = s.replace(old, "", 1)
io.open("PKGBUILD", "w", encoding="utf-8").write(s)
PY
grep -q 'leancrypto' PKGBUILD && {
echo "gnutls: leancrypto still referenced" >&2; exit 1; }
echo "gnutls: leancrypto dropped from configure AND from depends"

38
patches/pkgbuild/make.sh Executable file
View file

@ -0,0 +1,38 @@
#!/usr/bin/env bash
# make: it declares guile, and our make has no guile in it.
#
# depends=('glibc' 'guile')
#
# GNU make's configure AUTO-DETECTS guile -- the PKGBUILD passes a bare
# `./configure --prefix=/usr` and says nothing about it. This build host has
# no guile at all, so the $(guile ...) function was never compiled in, and the
# artefact says so plainly:
#
# $ readelf -d usr/bin/make | grep NEEDED
# (NEEDED) Shared library: [libc.so.6]
#
# One library. Nothing else.
#
# THE TRAP is that nothing fails. --nodeps means makepkg never checks the
# declaration, so make built, passed, and entered the repository asking for a
# package this port does not have and does not need. It is the same class as
# gcc-libs declaring libhwasan: a dependency that is real in Arch's build
# environment and false in ours, and the only thing that ever notices is
# pacman, at install time, long after the cause.
#
# It is worth the entry it costs. guile drags in bdw-gc and libffi behind it,
# so this single false line was three packages of closure for a feature the
# binary does not contain.
#
# WHY REMOVE RATHER THAN BUILD. Because the declaration should describe THIS
# artefact. Building guile and rebuilding make would be the other honest
# answer and would match Arch exactly -- TODO.md records it as deferred, with
# the cost, so the choice stays visible. What is not defensible is shipping a
# make that claims a feature it lacks.
set -euo pipefail
grep -q "^depends=('glibc' 'guile')$" PKGBUILD || {
echo "make: depends line is not the expected ('glibc' 'guile')" >&2; exit 1; }
sed -i "s/^depends=('glibc' 'guile')$/depends=('glibc')/" PKGBUILD
grep -q "^depends=('glibc')$" PKGBUILD || {
echo "make: guile not removed from depends" >&2; exit 1; }
echo "make: guile dropped from depends (the binary links libc only)"