[FIX] declared, never linked: guile, libisl.so, leancrypto
An audit of every missing dependency spelled as a soname, asking the ARTEFACT whether the package that declares it actually links it. It contradicted my guesses: curl's krb5, ssh2 and idn2 are all real. Two were not. make readelf -d usr/bin/make -> libc.so.6, and nothing else gcc configure recorded ISLLIBS='' ISLINC=''; zero libisl in the tree Both are false in our build environment and true in Arch's. --nodeps means makepkg never checks, so each shipped a package asking for something this port will never contain -- and only pacman ever notices, at install time. Building isl was the first plan. Its Arch packaging repo was last touched in 2017 and its only source URL is isl.gforge.inria.fr, dead with INRIA's GForge. There is nothing to build; the declaration goes instead, and Graphite goes with it. gnutls found the same shape from the other direction: --with-leancrypto stopped configure, and 'leancrypto' sat in depends= where nothing checks it. --- FR --- Un audit de chaque dépendance manquante écrite en soname, demandant à l'ARTEFACT si le paquet qui la déclare la lie vraiment. Il a contredit mes suppositions : les krb5, ssh2 et idn2 de curl sont bien réels. Deux ne l'étaient pas. make readelf -d usr/bin/make -> libc.so.6, et rien d'autre gcc configure a noté ISLLIBS='' ISLINC='' ; aucun libisl dans l'arbre Les deux sont fausses dans notre environnement et vraies dans celui d'Arch. --nodeps veut dire que makepkg ne vérifie jamais : chacun livrait donc un paquet réclamant ce que ce portage ne contiendra jamais — et seul pacman s'en aperçoit, à l'installation. Bâtir isl était le premier plan. Son dépôt de packaging Arch n'a pas bougé depuis 2017 et sa seule source pointe isl.gforge.inria.fr, morte avec le GForge d'INRIA. Il n'y a rien à bâtir : c'est la déclaration qui part, et Graphite avec elle. gnutls a montré la même forme par l'autre bout : --with-leancrypto arrêtait configure, et 'leancrypto' figurait dans depends= où rien ne le vérifie. Assisted-by: Claude Opus 5
This commit is contained in:
parent
2a1997e06d
commit
3c926f10a9
3 changed files with 96 additions and 1 deletions
|
|
@ -259,6 +259,20 @@ grep -A1 '^build() {' PKGBUILD | head -2 | sed 's/^/ /'
|
|||
# is not depended on, and the check below asserts it rather than trusting it.
|
||||
# Adding a name to that set is now enough, in one place.
|
||||
#
|
||||
# libisl.so is in the same list for a DIFFERENT reason, and the difference is
|
||||
# worth a sentence. The others are components this PKGBUILD stops building.
|
||||
# isl is an outside library that gcc simply never linked: the host has no isl,
|
||||
# so configure recorded ISLLIBS='' and ISLINC='', and the artefact agrees --
|
||||
#
|
||||
# $ readelf -d usr/bin/gcc usr/lib/libgcc_s.so.1 | grep -c libisl
|
||||
# 0
|
||||
#
|
||||
# The remedy is the same, so the list is the same. Building isl instead was
|
||||
# the first plan and it does not work: the Arch packaging repo for isl was
|
||||
# last touched in 2017 and its only source URL is isl.gforge.inria.fr, which
|
||||
# died with INRIA's GForge. What this costs is Graphite -- the -floop-*
|
||||
# optimisations -- and TODO.md records it.
|
||||
#
|
||||
# Both spellings occur: a bare name in a sub-package's depends, and the
|
||||
# versioned "libhwasan=$pkgver-$pkgrel" form in gcc's own. The unused
|
||||
# package_libhwasan() function can stay -- makepkg never calls a function
|
||||
|
|
@ -266,7 +280,10 @@ grep -A1 '^build() {' PKGBUILD | head -2 | sed 's/^/ /'
|
|||
python3 - <<'PY'
|
||||
import io, re
|
||||
drop = ["libhwasan", "libquadmath", "lib32-gcc-libs",
|
||||
"libgm2", "libgo", "libgphobos", "libgcobol"]
|
||||
"libgm2", "libgo", "libgphobos", "libgcobol",
|
||||
# Not a component we dropped -- an EXTERNAL library gcc was never
|
||||
# configured against. See the note above the list.
|
||||
"libisl.so"]
|
||||
s = io.open("PKGBUILD", encoding="utf-8").read()
|
||||
|
||||
def prune(block):
|
||||
|
|
|
|||
40
patches/pkgbuild/gnutls.sh
Executable file
40
patches/pkgbuild/gnutls.sh
Executable file
|
|
@ -0,0 +1,40 @@
|
|||
#!/usr/bin/env bash
|
||||
# gnutls: leancrypto is asked for, and Ubuntu has no such library.
|
||||
#
|
||||
# configure: error: leancrypto support was requested but the required
|
||||
# libraries were not found.
|
||||
#
|
||||
# Arch packages leancrypto -- a post-quantum crypto library -- and gnutls
|
||||
# links it for ML-KEM and ML-DSA. Nothing about s390x prevents it; the build
|
||||
# host simply cannot supply it, and building leancrypto first would add a
|
||||
# package to the closure for algorithms pacman does not use. It signs with
|
||||
# OpenPGP through gpgme, and TLS to the mirrors needs none of this.
|
||||
#
|
||||
# TWO PLACES, and the second is the one that bites silently. The configure
|
||||
# flag is what stops the build, so it is what gets noticed. But 'leancrypto'
|
||||
# is ALSO in depends=, and --nodeps means makepkg never checks it: gnutls
|
||||
# would build, pass, and enter the repository asking for a package this port
|
||||
# will never contain. Same shape as gcc-libs declaring libhwasan, and as make
|
||||
# declaring guile -- the third instance of it in this port, which is why the
|
||||
# audit that finds them is now part of the routine rather than an afterthought.
|
||||
set -euo pipefail
|
||||
python3 - <<'PY'
|
||||
import io
|
||||
s = io.open("PKGBUILD", encoding="utf-8").read()
|
||||
|
||||
# (a) the flag that stops configure. It is the LAST option on the line, with
|
||||
# no trailing backslash, so the preceding backslash goes with it.
|
||||
old = " \\\n --with-leancrypto"
|
||||
assert s.count(old) == 1, "gnutls: expected exactly one --with-leancrypto"
|
||||
s = s.replace(old, "", 1)
|
||||
|
||||
# (b) the declaration nobody checks
|
||||
old = "'leancrypto' "
|
||||
assert s.count(old) == 1, "gnutls: expected exactly one leancrypto in depends"
|
||||
s = s.replace(old, "", 1)
|
||||
|
||||
io.open("PKGBUILD", "w", encoding="utf-8").write(s)
|
||||
PY
|
||||
grep -q 'leancrypto' PKGBUILD && {
|
||||
echo "gnutls: leancrypto still referenced" >&2; exit 1; }
|
||||
echo "gnutls: leancrypto dropped from configure AND from depends"
|
||||
38
patches/pkgbuild/make.sh
Executable file
38
patches/pkgbuild/make.sh
Executable file
|
|
@ -0,0 +1,38 @@
|
|||
#!/usr/bin/env bash
|
||||
# make: it declares guile, and our make has no guile in it.
|
||||
#
|
||||
# depends=('glibc' 'guile')
|
||||
#
|
||||
# GNU make's configure AUTO-DETECTS guile -- the PKGBUILD passes a bare
|
||||
# `./configure --prefix=/usr` and says nothing about it. This build host has
|
||||
# no guile at all, so the $(guile ...) function was never compiled in, and the
|
||||
# artefact says so plainly:
|
||||
#
|
||||
# $ readelf -d usr/bin/make | grep NEEDED
|
||||
# (NEEDED) Shared library: [libc.so.6]
|
||||
#
|
||||
# One library. Nothing else.
|
||||
#
|
||||
# THE TRAP is that nothing fails. --nodeps means makepkg never checks the
|
||||
# declaration, so make built, passed, and entered the repository asking for a
|
||||
# package this port does not have and does not need. It is the same class as
|
||||
# gcc-libs declaring libhwasan: a dependency that is real in Arch's build
|
||||
# environment and false in ours, and the only thing that ever notices is
|
||||
# pacman, at install time, long after the cause.
|
||||
#
|
||||
# It is worth the entry it costs. guile drags in bdw-gc and libffi behind it,
|
||||
# so this single false line was three packages of closure for a feature the
|
||||
# binary does not contain.
|
||||
#
|
||||
# WHY REMOVE RATHER THAN BUILD. Because the declaration should describe THIS
|
||||
# artefact. Building guile and rebuilding make would be the other honest
|
||||
# answer and would match Arch exactly -- TODO.md records it as deferred, with
|
||||
# the cost, so the choice stays visible. What is not defensible is shipping a
|
||||
# make that claims a feature it lacks.
|
||||
set -euo pipefail
|
||||
grep -q "^depends=('glibc' 'guile')$" PKGBUILD || {
|
||||
echo "make: depends line is not the expected ('glibc' 'guile')" >&2; exit 1; }
|
||||
sed -i "s/^depends=('glibc' 'guile')$/depends=('glibc')/" PKGBUILD
|
||||
grep -q "^depends=('glibc')$" PKGBUILD || {
|
||||
echo "make: guile not removed from depends" >&2; exit 1; }
|
||||
echo "make: guile dropped from depends (the binary links libc only)"
|
||||
Loading…
Reference in a new issue