[ADD] upstream.lock, and keep the machine out of the repository

Until now the honest description of this port was: it worked once, on one
machine. Every PKGBUILD comes from a `git clone --depth 1` of
gitlab.archlinux.org, and the 63 hooks assert exact strings -- deliberately, and
several have caught their own mistakes that way. But it means the port is written
against a moving target: someone starting over today gets what Arch has today,
not what these hooks were written against.

What closes that is not the 18 GB of build output -- regenerable packages, a
chroot wiped on every run, state files derived from the repository by design. It
is one commit per checkout: 155 lines. build_package now pins a fresh clone to
the locked commit, and says so when a package is NOT in the lock, because that is
how a lock quietly stops covering what it claims to.

RELAIS.md joins the repository, written without the build machine's alias,
address or account -- a successor needs the shape of the access, not its
coordinates. check-private.sh keeps it that way, and .env.example loses its
literal account name. Three of its patterns had to go on their first runs: they
flagged a systemd unit template, upstream maintainer headers, the localhost lines
of a generated /etc/hosts, and its own explanatory comment. A check that fails on
correct files is one somebody stops running.

--- FR ---

Jusqu'ici la description honnête de ce portage était : il a fonctionné une fois,
sur une machine. Chaque PKGBUILD vient d'un `git clone --depth 1` de
gitlab.archlinux.org, et les 63 hooks affirment des chaînes exactes — à dessein,
et plusieurs y ont attrapé leurs propres erreurs. Mais le portage est donc écrit
contre une cible mouvante : qui recommence aujourd'hui obtient l'Arch du jour.

Ce qui comble ce trou n'est pas les 18 Go de production — paquets régénérables,
chroot effacé à chaque passage, registres dérivés du dépôt par conception. C'est
un commit par arbre : 155 lignes. build_package épingle un nouveau clone sur le
commit verrouillé, et le DIT quand un paquet n'y figure pas, car c'est ainsi qu'un
verrou cesse discrètement de couvrir ce qu'il prétend.

RELAIS.md entre dans le dépôt, écrit sans l'alias, l'adresse ni le compte de la
machine — un successeur a besoin de la forme de l'accès, pas de ses coordonnées.
check-private.sh l'y maintient, et .env.example perd son nom de compte littéral.
Trois de ses motifs ont dû partir dès les premiers passages : ils signalaient un
gabarit d'unité systemd, des en-têtes de mainteneurs amont, les lignes localhost
d'un /etc/hosts généré, et son propre commentaire explicatif. Un contrôle qui
échoue sur des fichiers justes est un contrôle qu'on cesse de lancer.

Assisted-by: Claude Opus 5
This commit is contained in:
Mathieu Benoit 2026-08-22 22:52:04 -04:00
parent ff65121058
commit 4101d18f72
6 changed files with 558 additions and 4 deletions

View file

@ -3,8 +3,8 @@
# Add the entire .env file content as ZVM_CONFIG secret in GitHub Actions
# z/VM Connection Details
ZVM_HOST=192.0.0.0
ZVM_USER=linux1
ZVM_HOST=zvm.example.com
ZVM_USER=your-zvm-user
ZVM_PORT=22
# SSH Key Configuration
@ -14,9 +14,11 @@ ZVM_SSH_KEY="-----BEGIN OPENSSH PRIVATE KEY-----
-----END OPENSSH PRIVATE KEY-----"
# Build Configuration
# Note: the two SYSTEMD_* paths below are not read by anything in this
# repository at present. They describe directories on the z/VM guest.
BUILD_TIMEOUT_MINUTES=30
SYSTEMD_BUILD_DIR="/home/linux1/systemd-build"
SYSTEMD_OUTPUT_DIR="/home/linux1/systemd-minimal"
SYSTEMD_BUILD_DIR="/home/$ZVM_USER/systemd-build"
SYSTEMD_OUTPUT_DIR="/home/$ZVM_USER/systemd-minimal"
# Connection Settings
SSH_CONNECT_TIMEOUT=10

127
RELAIS.md Normal file
View file

@ -0,0 +1,127 @@
# Arch Linux sur s390x — état du portage
Objectif : **ERPLibre tourne sur Arch Linux s390x.** Terminé quand ERPLibre
fonctionne, pas quand les paquets compilent.
## Où est quoi
| | |
|---|---|
| Machine | la VM de developpement s390x, Ubuntu, joignable par un rebond ssh |
| Dépôt du portage | `~/git/archlinux-s390x` — **72 commits, aucun distant** |
| Espace de travail | `~/work/arch-s390x` |
| Dépôt étage 1 | `~/work/arch-s390x/repo/s390x` |
| Dépôt étage 2 | `~/work/arch-s390x/repo2/s390x` |
| Chroot étage 2 | `~/work/arch-s390x/rootfs-stage2` |
| Registres | `stage1.state`, `stage2.state` |
**Ne pas toucher** : `/var/lib/libvirt` (VM d'autres travaux). Le `/tmp` de
cette machine est partagé **et** en tmpfs — utiliser un sous-répertoire à soi.
## Comment on lance
```bash
cd ~/git/archlinux-s390x
bash scripts/build-stage1.sh # toute la liste
bash scripts/build-stage1.sh gperf rsync # à la demande, écrase le registre
EL_NOCHECK=1 bash scripts/build-stage2.sh --all
bash scripts/build-stage2.sh libxml2 # un paquet
bash scripts/test-chroot.sh # RESOLVE / ARTEFACT / SONAME / RUN
```
Toujours en arrière-plan, la sortie dans un fichier :
```bash
setsid nohup bash scripts/build-stage2.sh --all > ~/work/arch-s390x/out.txt 2>&1 < /dev/null &
```
`EL_STALL_MIN` (défaut 45) tue une construction muette ; `EL_NOCHECK=1` saute
les suites de tests, à réserver à la première passe.
## Où on en est
- **Étage 1 : 180 paquets**, `RESOLVE ok` — la fermeture du chroot résout à
**148 paquets** avec `--nodeps` éteint. `ARTEFACT ok`, `RUN ok`.
- **Étage 2** : `glibc`, `texinfo`, `libxml2`, `linux-api-headers`, `pkgconf` et
~75 autres reconstruits dans le chroot. Passe complète en cours.
- Test de fumée du chroot : **11 ok, 0 échec, 0 dérive connue**.
- **Étage 3 : pas commencé.** Auto-hébergement quand l'étage 3 reproduit
l'étage 2.
- **ERPLibre : pas commencé.** 18 paquets et leur fermeture, puis ERPLibre.
## Les décisions à connaître
**Base processeur : z13, tune z16.** Arch ne nomme aucune base s390x, donc GCC
retombait sur `arch5` = z900, l'an 2000, et tout paquet à intrinsèques
vectoriels échouait. Posée à deux endroits qui répondent à deux questions :
`makepkg.conf` du chroot (comment on compile) et `--with-arch` de gcc (ce que
suppose le compilateur livré). z13 est ce qu'Ubuntu s390x exige déjà.
**`filesystem` livre les liens lib64 sur s390x.** Arch ne les crée que pour
x86_64 ; sans eux, la chaîne s390x crée un **vrai** `/usr/lib64`, ce qui
retourne le libdir par défaut de meson et casse tout pkg-config.
**Documentation : elle cède.** L'`arch-meson` du chroot est enveloppé avec
`--auto-features auto`. Neuf outils de documentation manquent et chacun coûte un
moteur de langage entier (doxygen → LLVM, asciidoctor → Ruby, a2x → Python).
À restaurer à l'étage 3.
**L'étage 2 est reprenable.** Le chroot est reconstruit à chaque passage, donc sa
production y est réinstallée au démarrage — mais **seulement ce que
`stage2.state` déclare encore de confiance**. Retirer un nom du registre est la
façon de dire « ne restaure pas cet artefact ».
## Les trois formes d'échec
1. **Contamination** — un chemin de l'hôte dans un paquet (multiarch Debian,
`/usr/local`, `usr/lib64`). Le test ARTEFACT les compte.
2. **Trou de fermeture** — l'étage 1 bâtit sous `--nodeps`, donc un paquet peut
se construire et rester ininstallable. `help2man` a bloqué une passe entière
ainsi. Le test RESOLVE est là pour ça.
3. **L'hôte est en retard** — libxslt exige libxml2 ≥ 2.15.1, Ubuntu livre
2.14.5. Ni contamination ni manque : la mauvaise machine. Ces paquets se
bâtissent **par** l'étage 2, pas dans l'étage 1, et sont hissés dans
`STAGE2_FIRST`. Une passe d'étage 1 doit les déclarer en échec.
## Pièges qui ont coûté du temps
- **Un garde qui vérifie une chose voisine de ce qu'il veut dire** — cinq fois.
`test -L` qui échoue ne dit pas « vrai répertoire » : il échoue aussi sur un
chemin absent. Un `grep -A1 --enable-languages=ada` vérifiait une ancre qu'une
section antérieure du même hook avait supprimée.
- **La première erreur d'un journal n'est pas la cause.** makepkg poursuit après
un `.BUILDINFO` manqué : cinq échecs ont été attribués à gpgme alors que la
ligne fatale, plus bas, était toujours la même.
- **`\s` en Python englobe les retours de ligne.** Une indentation capturée
contenait un saut de ligne et a inséré un drapeau dans le vide. Travailler sur
les **lignes**, pas sur les décalages.
- **Un échec ssh n'est pas la preuve qu'un travail distant est fini.** Le lien du
rebond tombe. Faire imprimer la réponse par la commande distante et la faire
sortir en 0, exiger plusieurs absences consécutives, ne jamais conclure depuis
un hôte injoignable.
- **Ne jamais `sed -i` un script qu'un bash est en train de lire.** Un fichier
de guetteur par lancement.
- **Cinq endroits pour retirer un composant** : tableau `pkgname`, bloc de
construction, lignes `_pick`, cibles make explicites, et le silencieux — le
tableau `depends` d'un **autre** sous-paquet, plus les `depends+=` dans
`package()`.
## Commits
Identité git : reprendre celle des commits existants (`git log -1 --format='%an <%ae>'`),
passée en `-c user.name=... -c user.email=...`. `TZ='America/Montreal'`, message écrit dans un fichier puis `git commit -F`.
Sujet `[TYPE] portée : sujet`, 72 caractères au plus. Corps bilingue : anglais,
`--- FR ---`, français, ~10 lignes par langue. Trailer
`Assisted-by: Claude Opus 5`. **Jamais** d'IA dans `Co-authored-by:`.
Lister les fichiers explicitement — **jamais `git add -A`**.
## Ce qui reste
1. Finir la passe d'étage 2 ; les échecs restants sont à classer par la
**dernière** erreur de chaque journal.
2. Rebâtir `pacman` à l'étage 2 : celui de l'étage 1 réclame `libgpgme.so.11`
(hôte 1.x) quand notre gpgme livre `.45`. Inoffensif pendant la
construction, fatal sur la cible.
3. Passe d'étage 2 **avec** les suites de tests, sans `EL_NOCHECK`.
4. Étage 3, puis comparaison étage 3 / étage 2.
5. Les 18 paquets d'ERPLibre et leur fermeture. Puis ERPLibre.

View file

@ -366,6 +366,34 @@ build_package() {
return 1
}
fi
# Land on the commit this port was written against, not on today's.
#
# The clone above is --depth 1 of whatever HEAD happens to be. Every hook
# under patches/pkgbuild/ asserts exact strings, so a version bump upstream
# breaks them -- which is the hooks working as intended, and also the reason
# a rebuild months from now would not reproduce this one.
#
# scripts/upstream.lock records one commit per checkout. When it names this
# package, the checkout is put on that commit; when it does not, the build
# proceeds on HEAD and SAYS SO, because an unlocked package is how the lock
# quietly stops covering the port.
if [ -f "$HERE_DIR/upstream.lock" ]; then
local _sha
_sha=$(awk -v n="$name" '$1 == n {print $2}' "$HERE_DIR/upstream.lock")
if [ -n "$_sha" ]; then
if [ "$(git -C "$WORK/pkg/$name" rev-parse HEAD 2>/dev/null)" != "$_sha" ]; then
if git -C "$WORK/pkg/$name" fetch -q --depth 1 origin "$_sha" 2>/dev/null &&
git -C "$WORK/pkg/$name" checkout -q --detach FETCH_HEAD 2>/dev/null; then
echo " pinned to ${_sha:0:9} (upstream.lock)"
else
echo " WARNING: cannot reach locked commit ${_sha:0:9}; using HEAD" >&2
fi
fi
else
echo " NOTE: $name is not in upstream.lock; building against HEAD" >&2
fi
fi
cd "$WORK/pkg/$name" || return 1
# Port patches. Upstream PKGBUILDs are written for x86_64 and some carry
# flags no other architecture accepts -- glibc's --enable-sframe is the

100
scripts/check-private.sh Executable file
View file

@ -0,0 +1,100 @@
#!/usr/bin/env bash
# Refuse to carry the developer's machine in the repository.
#
# WHY THIS EXISTS. RELAIS.md was written with the build machine's ssh alias, the
# guest's IP address, and the author's name and e-mail in the body of the text.
# None of it was needed: a successor needs the SHAPE of the access, not its
# coordinates, and the commit identity is already in the author field of every
# commit.
#
# It is a check rather than a one-time cleanup because the leak arrives by
# accident. Every path in this port gets pasted from a terminal at some point --
# error messages carry absolute paths, and absolute paths carry usernames.
#
# Run over the TRACKED files only. Build output under work/ is nobody's business
# here and is not versioned; see scripts/upstream-lock.sh for what is.
set -uo pipefail
cd "$(dirname "${BASH_SOURCE[0]}")/.." || exit 2
# Deliberately narrow. A pattern that fires on ordinary prose gets disabled, and
# a disabled check is worse than none.
#
# - RFC1918 addresses and any dotted quad
# - /home/<name>, which is how a username travels
# - an e-mail address
declare -a PATTERNS=(
'\b10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\b'
'\b192\.168\.[0-9]{1,3}\.[0-9]{1,3}\b'
'\b172\.(1[6-9]|2[0-9]|3[01])\.[0-9]{1,3}\.[0-9]{1,3}\b'
'/home/[a-z][a-z0-9_-]*'
)
# 127.0.0.0/8 is NOT here. It was, and it flagged
#
# scripts/create-rootfs.sh:152 127.0.0.1 localhost
# scripts/create-rootfs.sh:154 127.0.1.1 archlinux-s390x.localdomain
#
# which is the content an /etc/hosts is supposed to have. Loopback says nothing
# about whose machine this is -- that is the whole point of loopback -- and a
# check that fails on a correct file is a check somebody will stop running.
declare -a NAMES=(
'address'
'private address'
'private address'
'home directory with a username'
)
# NO GENERIC E-MAIL PATTERN. There was one, and it had to go on its first run:
#
# scripts/create-rootfs.sh:302 .../etc/systemd/system/getty@tty1.service
# CODEOWNERS:4 * @Morganamilo morganamilo@archlinux.org
# arch-kernel/PKGBUILD-s390x:1 # Maintainer: ... <heftig@archlinux.org>
#
# A systemd unit template contains an @, and upstream maintainer headers are
# supposed to carry addresses -- they are Arch's, publicly published, and a
# PKGBUILD without them would be the anomaly. Six of nine findings were noise,
# which is how a check gets switched off and stops protecting anything.
#
# The author's own address is not covered here either, deliberately: it is in the
# author field of all 89 commits by the project's own convention, so calling it a
# leak in prose while requiring it in metadata would be incoherent. What this
# checks is the machine -- addresses and usernames -- which nothing needs.
# Files that are examples ON PURPOSE. Named one by one, with the reason, because
# a wildcard exclusion is how a real leak gets waved through.
#
# EMPTY, and that is the intended state. .env.example was listed here, exempted
# for carrying a home directory with a literal account name -- then its values
# were made neutral and the exemption had nothing left to excuse. An exemption
# that outlives its reason is how a file stops being checked without anyone
# deciding that it should.
#
# And the first version of this very comment quoted the path it was describing,
# so the check flagged its own source. A redaction tool must not spell out what
# it redacts; there is no reason to name the account to explain why it is gone.
declare -a ALLOW=()
hits=0
for i in "${!PATTERNS[@]}"; do
while IFS=: read -r file line rest; do
[ -n "$file" ] || continue
skip=0
for a in "${ALLOW[@]}"; do [ "$file" = "$a" ] && skip=1; done
[ "$skip" -eq 1 ] && continue
printf ' %-28s %s:%s %s\n' "${NAMES[$i]}" "$file" "$line" \
"$(printf '%s' "$rest" | cut -c1-60)"
hits=$((hits + 1))
done < <(git grep -nIE "${PATTERNS[$i]}" -- . 2>/dev/null)
done
# Commit messages too. The working tree can be cleaned with an edit; a message
# needs history rewritten, so it is worth knowing early rather than late.
msg=$(git log --all --format='%B' 2>/dev/null |
grep -cE '\b(192\.168|10|172\.(1[6-9]|2[0-9]|3[01]))\.[0-9]{1,3}\.[0-9]{1,3}\b|/home/[a-z]' || true)
if [ "$hits" -eq 0 ] && [ "${msg:-0}" -eq 0 ]; then
echo "no machine identity, address or username in the tracked files"
exit 0
fi
[ "${msg:-0}" -gt 0 ] && printf ' %s line(s) in COMMIT MESSAGES -- needs history rewriting\n' "$msg"
printf '%s finding(s)\n' "$((hits + ${msg:-0}))"
exit 1

137
scripts/upstream-lock.sh Executable file
View file

@ -0,0 +1,137 @@
#!/usr/bin/env bash
# The upstream commit of every package checkout, recorded and enforced.
#
# WHY THIS EXISTS. Every PKGBUILD in this port comes from a fresh
# `git clone --depth 1` of gitlab.archlinux.org, and the 63 hooks under
# patches/pkgbuild/ assert EXACT strings:
#
# assert s.count(old) == 1, "binutils: expected one --enable-pgo-build ..."
#
# That strictness is deliberate and it works -- several hooks have caught their
# own mistakes that way. But it means the port is written against a moving
# target. The day Arch bumps a version, a hook fails; and someone starting over
# today does not get what this port was written against, they get whatever Arch
# has today.
#
# So before this file, the honest description was: the port worked once, on one
# machine. What was missing to change that is not the 18 GB of build output --
# all of it regenerable -- but the one number per checkout that says which
# upstream commit it was.
#
# write record the current HEAD of every checkout under $WORK/pkg
# verify report checkouts that have moved away from the lock (default)
# restore put every checkout back on its locked commit
#
# NOT versioned alongside this: repo/s390x and repo2/s390x (800 MB of binaries a
# script can rebuild), rootfs-stage2 (wiped every run by design), stage1.state
# and stage2.state (derived from what is really in repo/s390x -- versioning them
# would invite them to disagree with it), and the build logs.
set -uo pipefail
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK="${WORK:-$HOME/work/arch-s390x}"
LOCK="${LOCK:-$HERE/upstream.lock}"
usage() { printf 'usage: %s [write|verify|restore]\n' "${0##*/}" >&2; exit 2; }
# The remote is READ from each checkout, not rebuilt from a base URL. Most come
# from archlinux/packaging/packages, pacman does not, and guessing would put a
# wrong URL in a file whose whole purpose is to be trusted later.
_scan() {
local d name sha url
for d in "$WORK"/pkg/*/; do
[ -d "$d/.git" ] || continue
name=$(basename "$d")
sha=$(git -C "$d" rev-parse HEAD 2>/dev/null) || continue
url=$(git -C "$d" remote get-url origin 2>/dev/null) || continue
printf '%s %s %s\n' "$name" "$sha" "$url"
done | sort
}
cmd_write() {
local tmp
tmp=$(mktemp)
{
printf '# Upstream commit of every package checkout in this port.\n'
printf '# Regenerate with: bash scripts/upstream-lock.sh write\n'
printf '# Verify with: bash scripts/upstream-lock.sh verify\n'
printf '#\n'
printf '# <package> <commit> <url>\n'
_scan
} > "$tmp"
mv "$tmp" "$LOCK"
printf 'wrote %s entries to %s\n' "$(grep -vc '^#' "$LOCK")" "$LOCK"
}
cmd_verify() {
[ -f "$LOCK" ] || { echo "no lock file at $LOCK" >&2; return 2; }
local n=0 moved=0 missing=0 name sha url cur
while read -r name sha url; do
case "$name" in ''|'#'*) continue ;; esac
n=$((n + 1))
if [ ! -d "$WORK/pkg/$name/.git" ]; then
printf ' ABSENT %s\n' "$name"; missing=$((missing + 1)); continue
fi
cur=$(git -C "$WORK/pkg/$name" rev-parse HEAD 2>/dev/null)
if [ "$cur" != "$sha" ]; then
printf ' MOVED %-24s %s -> %s\n' "$name" "${sha:0:9}" "${cur:0:9}"
moved=$((moved + 1))
fi
done < "$LOCK"
# THE OTHER DIRECTION, which is the one that goes wrong silently. Above
# answers "has a locked checkout moved?"; this answers "is the lock still
# covering the port?" A package added to packages.sh and never locked builds
# against whatever upstream has that day, and nothing about the lock file
# looks wrong -- it is complete for everything it mentions.
local unlocked=0 p
if [ -f "$HERE/packages.sh" ]; then
# shellcheck disable=SC1090
HERE="$HERE" source "$HERE/packages.sh"
for p in "${STAGE1_PACKAGES[@]}"; do
grep -q "^$p " "$LOCK" || { printf ' UNLOCKED %s\n' "$p"; unlocked=$((unlocked + 1)); }
done
fi
printf '%s locked, %s moved, %s absent, %s unlocked\n' \
"$n" "$moved" "$missing" "$unlocked"
# A checkout that is absent is not a failure: it has simply not been cloned
# on this machine yet. One that MOVED is, because a hook was written against
# the other commit. UNLOCKED is reported but not fatal -- a package added to
# the list and not yet built has nothing to lock, and `write` covers it once
# it does.
[ "$moved" -eq 0 ]
}
cmd_restore() {
[ -f "$LOCK" ] || { echo "no lock file at $LOCK" >&2; return 2; }
local ok=0 fail=0 name sha url
while read -r name sha url; do
case "$name" in ''|'#'*) continue ;; esac
local d="$WORK/pkg/$name"
if [ ! -d "$d/.git" ]; then
mkdir -p "$d"
git -C "$d" init -q 2>/dev/null
git -C "$d" remote add origin "$url" 2>/dev/null
fi
# --depth 1 of a specific commit, because that is how these were cloned
# and a full history of 155 repositories is not wanted. It needs
# uploadpack.allowReachableSHA1InWant on the server; when that is
# refused the failure is reported rather than skipped, since a checkout
# left on the wrong commit is exactly what this file exists to prevent.
if git -C "$d" fetch -q --depth 1 origin "$sha" 2>/dev/null &&
git -C "$d" checkout -q --detach FETCH_HEAD 2>/dev/null; then
ok=$((ok + 1))
else
printf ' FAILED %-24s %s\n' "$name" "${sha:0:9}"
fail=$((fail + 1))
fi
done < "$LOCK"
printf '%s restored, %s failed\n' "$ok" "$fail"
[ "$fail" -eq 0 ]
}
case "${1:-verify}" in
write) cmd_write ;;
verify) cmd_verify ;;
restore) cmd_restore ;;
*) usage ;;
esac

160
scripts/upstream.lock Normal file
View file

@ -0,0 +1,160 @@
# Upstream commit of every package checkout in this port.
# Regenerate with: bash scripts/upstream-lock.sh write
# Verify with: bash scripts/upstream-lock.sh verify
#
# <package> <commit> <url>
acl c51beb032d03a50cbd8dae96de23986d21558875 https://gitlab.archlinux.org/archlinux/packaging/packages/acl.git
attr 13964f8a55dde2d7e407267eb8fbc5ec44bdb585 https://gitlab.archlinux.org/archlinux/packaging/packages/attr.git
audit 8db272a0138b530ab71f98763c808a5713f859a4 https://gitlab.archlinux.org/archlinux/packaging/packages/audit.git
autoconf c69f433ef07dc732887e22cd5d5a7501cd944fef https://gitlab.archlinux.org/archlinux/packaging/packages/autoconf.git
automake 9697f63e766a66b5da9ccba3fc1a46a798875154 https://gitlab.archlinux.org/archlinux/packaging/packages/automake.git
bash ac765bd0cb9b4c27f75c94bc320bf3c8b57304c4 https://gitlab.archlinux.org/archlinux/packaging/packages/bash.git
binutils 5b5ba27ac801a1e7d11819e02a80605ea33434dd https://gitlab.archlinux.org/archlinux/packaging/packages/binutils.git
bison 891a7b237b41cb44109510b25afeb85ffef71b8a https://gitlab.archlinux.org/archlinux/packaging/packages/bison.git
brotli 6ed940ad7ae3399fd7f84045703849a1a3a58914 https://gitlab.archlinux.org/archlinux/packaging/packages/brotli.git
bzip2 655c806171fcb62300d8a056536360615f99be3e https://gitlab.archlinux.org/archlinux/packaging/packages/bzip2.git
ca-certificates d343b61653fb3cfe7a2bdad8a66c0d122ff11a78 https://gitlab.archlinux.org/archlinux/packaging/packages/ca-certificates.git
cmake 34717d0847e2be15bc3b6a66f3a4ab2e430bff2a https://gitlab.archlinux.org/archlinux/packaging/packages/cmake.git
coreutils f33db1312f616064d4730f92e793d6a761a69e5a https://gitlab.archlinux.org/archlinux/packaging/packages/coreutils.git
cppdap 4a8ba28125a5fcaf5870b47177bbd6b7949ed59d https://gitlab.archlinux.org/archlinux/packaging/packages/cppdap.git
cryptsetup 5fd56afd0d44fad6129716d89103a48d29aa7ef1 https://gitlab.archlinux.org/archlinux/packaging/packages/cryptsetup.git
curl 45e9c1b535b60dd96c05f0c5dc7c07a8ea5947ac https://gitlab.archlinux.org/archlinux/packaging/packages/curl.git
db5.3 ef842314637f28c5ae1a5e803ad3799965c0f27e https://gitlab.archlinux.org/archlinux/packaging/packages/db5.3.git
dbus f9960c26b0014b2b0b750425010feacda1b42be8 https://gitlab.archlinux.org/archlinux/packaging/packages/dbus.git
diffutils 63d25ebd4b3fc2850529955960643c07221bc233 https://gitlab.archlinux.org/archlinux/packaging/packages/diffutils.git
e2fsprogs 82fb4498152e7cd1ae41d604eff56b72acbab4f6 https://gitlab.archlinux.org/archlinux/packaging/packages/e2fsprogs.git
elfutils 841f42b00b1efc00cda023493d1615d821c8b6ff https://gitlab.archlinux.org/archlinux/packaging/packages/elfutils.git
expat fbde2ec58055670e3f02fb23e2fc76fbbbcdd994 https://gitlab.archlinux.org/archlinux/packaging/packages/expat.git
fakeroot 6018258ff15e848b084e622eb26c6b8deae715fc https://gitlab.archlinux.org/archlinux/packaging/packages/fakeroot.git
file 6135bd0a6dd827ebbdc64f26064c5fd502a9d7ba https://gitlab.archlinux.org/archlinux/packaging/packages/file.git
filesystem a0dee6ef8fcbdfee5cc4305e7256175ca4c90458 https://gitlab.archlinux.org/archlinux/packaging/packages/filesystem.git
findutils ba133ab22ff7e31094dd167693c6dc897b387182 https://gitlab.archlinux.org/archlinux/packaging/packages/findutils.git
flex d81507d185287886cc2d3e8d1fc37dbb0f4bc482 https://gitlab.archlinux.org/archlinux/packaging/packages/flex.git
gawk 81baf7293a940a3b21f5becbb22e6b7c2d0b2bbc https://gitlab.archlinux.org/archlinux/packaging/packages/gawk.git
gcc 938c83e423b3624dc28eb4b8034802e1b879d9e1 https://gitlab.archlinux.org/archlinux/packaging/packages/gcc.git
gdbm 6ef1719fa6a07eda8a64de8c1cfa943670736857 https://gitlab.archlinux.org/archlinux/packaging/packages/gdbm.git
gettext 8005dbbd5fdeaa9a79cc93275283c6e0ee2f58a9 https://gitlab.archlinux.org/archlinux/packaging/packages/gettext.git
git 3f116bf577be55e74bdf29a6dc2ee2431bb99a64 https://gitlab.archlinux.org/archlinux/packaging/packages/git.git
glibc 7a444d10dd6b85918b891bf386f03c68c548de3b https://gitlab.archlinux.org/archlinux/packaging/packages/glibc.git
gmp edbb271e660845ac77d6421237fcffb50e101389 https://gitlab.archlinux.org/archlinux/packaging/packages/gmp.git
gnulib-l10n 8ab4b0bbd4a2529955be4dd6b7824a34d7199894 https://gitlab.archlinux.org/archlinux/packaging/packages/gnulib-l10n.git
gnupg e1e1349727faf0073cf38f4895223130f28627d3 https://gitlab.archlinux.org/archlinux/packaging/packages/gnupg.git
gnutls e3c0b5810fb046635df0d7b1a1b6d0b1813d152c https://gitlab.archlinux.org/archlinux/packaging/packages/gnutls.git
gperf 1ad3213d13d12c8507fab53ec15ec0559be99ffc https://gitlab.archlinux.org/archlinux/packaging/packages/gperf.git
gpgme ce68a023c3cd8e348f87c83666e0a2713cfca47b https://gitlab.archlinux.org/archlinux/packaging/packages/gpgme.git
grep b6557325ffa4abe40e4785823939a42093218acd https://gitlab.archlinux.org/archlinux/packaging/packages/grep.git
groff f84578039481409d2c880adc5bd5dcc4b3285dbb https://gitlab.archlinux.org/archlinux/packaging/packages/groff.git
gzip 4b347e7230151d6980db3251f1c65a7b27956c10 https://gitlab.archlinux.org/archlinux/packaging/packages/gzip.git
help2man e2c0cff5c9566eb76b322950e8ad85b6dd15e9cb https://gitlab.archlinux.org/archlinux/packaging/packages/help2man.git
hicolor-icon-theme 671ceecae2fa1f55a7fef9ead1d4cecfb3010d62 https://gitlab.archlinux.org/archlinux/packaging/packages/hicolor-icon-theme.git
hwdata 51d93b3b4d53801ef687ef80c9c114eb243e50d2 https://gitlab.archlinux.org/archlinux/packaging/packages/hwdata.git
iana-etc c5484926af06c592cd97bdf4e486b210fb6265f5 https://gitlab.archlinux.org/archlinux/packaging/packages/iana-etc.git
icu 30c818dc5a32b217d738ba9a8d942f202dfd44c6 https://gitlab.archlinux.org/archlinux/packaging/packages/icu.git
inetutils d8410cb37b77eafde97a741fa255bd270bef3ccf https://gitlab.archlinux.org/archlinux/packaging/packages/inetutils.git
isl 254dad53bc342a04c8b5d288989edf0d64fe84d4 https://gitlab.archlinux.org/archlinux/packaging/packages/isl.git
jansson 7099734a6d46580fd37fe1773afd38b05275cb97 https://gitlab.archlinux.org/archlinux/packaging/packages/jansson.git
json-c 8a1daf8921e589e429e5534fe08a0c4a9c8d5a78 https://gitlab.archlinux.org/archlinux/packaging/packages/json-c.git
jsoncpp dae598b1ac3fbd69e97cfcf085fc690b514a778e https://gitlab.archlinux.org/archlinux/packaging/packages/jsoncpp.git
kbd 106bbe3fb6bdbff8c021aa4bcd2dede08d566b68 https://gitlab.archlinux.org/archlinux/packaging/packages/kbd.git
keyutils ed23150cb9c757e41c6fc279a2ab3a104f013f4a https://gitlab.archlinux.org/archlinux/packaging/packages/keyutils.git
kmod 8870cb609b63050aafc7943cff0c8c931bf04ed1 https://gitlab.archlinux.org/archlinux/packaging/packages/kmod.git
krb5 32b702e4c0d55856cbdf5c9264d37fc628879712 https://gitlab.archlinux.org/archlinux/packaging/packages/krb5.git
libaio 461eeac270aa5d3174677c3061f1a870f93de6cc https://gitlab.archlinux.org/archlinux/packaging/packages/libaio.git
libarchive 1cfaa8a6f9ba012b482e9544c4e5b662ef3ae911 https://gitlab.archlinux.org/archlinux/packaging/packages/libarchive.git
libassuan 87e42f5b5fde977ec98cc72c7f5ef5ad1f257d8c https://gitlab.archlinux.org/archlinux/packaging/packages/libassuan.git
libcap 1af5a8bd3ca74002d3422c1dfe0710d3f567502b https://gitlab.archlinux.org/archlinux/packaging/packages/libcap.git
libcap-ng 6fb7f460cee1dd2c99bd7aea2a69b86bf122ab7c https://gitlab.archlinux.org/archlinux/packaging/packages/libcap-ng.git
libevent 914033d8ac6b2c684de7ad43612eed464768f41f https://gitlab.archlinux.org/archlinux/packaging/packages/libevent.git
libffi 1aa204da4e1541bdcec3e80ae8f274fc01f0ab29 https://gitlab.archlinux.org/archlinux/packaging/packages/libffi.git
libgcrypt cc1f0a9d4a2ba80102d6df75389a908f38c773f3 https://gitlab.archlinux.org/archlinux/packaging/packages/libgcrypt.git
libgpg-error 7b4fcfe31a3922de885b60c4eccd915c2173a0ea https://gitlab.archlinux.org/archlinux/packaging/packages/libgpg-error.git
libidn2 7254392fe9adbba2842442e66bafca2fe9cd761c https://gitlab.archlinux.org/archlinux/packaging/packages/libidn2.git
libksba 0cb32bfe33f9164d6a442f0a01f44eab7c9cc711 https://gitlab.archlinux.org/archlinux/packaging/packages/libksba.git
libmakepkg-dropins 7ed7cbb353a988d994b3cb6d1f84f1846c4a1569 https://gitlab.archlinux.org/archlinux/packaging/packages/libmakepkg-dropins.git
libmicrohttpd 664d951bda570500fb90cfa7c09c6cf9e9a6ff40 https://gitlab.archlinux.org/archlinux/packaging/packages/libmicrohttpd.git
libmpc 6e8d5f209c5dfb2d2baee32acc85b79124c63362 https://gitlab.archlinux.org/archlinux/packaging/packages/libmpc.git
libnghttp2 40f0611c83a4b35926b181318365699f0c5a5530 https://gitlab.archlinux.org/archlinux/packaging/packages/libnghttp2.git
libnsl dbea5e4a59907a7f968cbc7af3ee9bc06cb8fef5 https://gitlab.archlinux.org/archlinux/packaging/packages/libnsl.git
libpsl fab5ebccddcf0368fe1912b617b4ad6d0e228237 https://gitlab.archlinux.org/archlinux/packaging/packages/libpsl.git
libsasl fe194d6f4952a9d4f242b7bad516ceb4474e0d1b https://gitlab.archlinux.org/archlinux/packaging/packages/libsasl.git
libseccomp 95a18e64bdd767620a8d8f06ad95eb6c55e49340 https://gitlab.archlinux.org/archlinux/packaging/packages/libseccomp.git
libsodium 64aa1ac49189236f7f1f73c0f6666c56fc1c3f0c https://gitlab.archlinux.org/archlinux/packaging/packages/libsodium.git
libssh2 bc15a4596376406c291657780461fa73dece1532 https://gitlab.archlinux.org/archlinux/packaging/packages/libssh2.git
libtasn1 6938a3e5e83ad01b59cdc79177d1534fb2d99b41 https://gitlab.archlinux.org/archlinux/packaging/packages/libtasn1.git
libtirpc aed070e8147f8131b41a145a41dc2d60ae8a7fbd https://gitlab.archlinux.org/archlinux/packaging/packages/libtirpc.git
libtool 15aa493fd752474832140a0e7ebfa85316c3b0a4 https://gitlab.archlinux.org/archlinux/packaging/packages/libtool.git
libunistring 42ca409302e9f0b4adeb5a813101fabb87a3950a https://gitlab.archlinux.org/archlinux/packaging/packages/libunistring.git
libusb 51dbbbfd2746111908f9ac8b7440f39353e3d705 https://gitlab.archlinux.org/archlinux/packaging/packages/libusb.git
libuv 518c5d9f877da479df875629555b55311b878151 https://gitlab.archlinux.org/archlinux/packaging/packages/libuv.git
libverto 863a2e0e0b079d9d215da38e40e1a675202d9eba https://gitlab.archlinux.org/archlinux/packaging/packages/libverto.git
libxcrypt 678cc689bd7336d2487965a9018a214426cb27c2 https://gitlab.archlinux.org/archlinux/packaging/packages/libxcrypt.git
libxml2 68bb2c304fb0220e791a60eb326bb8baf3d0b813 https://gitlab.archlinux.org/archlinux/packaging/packages/libxml2.git
libxslt ae2998e51f2c294a8b697b53669df27479c96494 https://gitlab.archlinux.org/archlinux/packaging/packages/libxslt.git
licenses f350b4965ef8c70408945fe14f063d58cf3ffd65 https://gitlab.archlinux.org/archlinux/packaging/packages/licenses.git
linux-api-headers 61a5b4eec7dc4d0f65c2480a7fa5f3f92fcfdeb2 https://gitlab.archlinux.org/archlinux/packaging/packages/linux-api-headers.git
lmdb 3d944072132a24afc5e1b5e4ad5bd8c594b39146 https://gitlab.archlinux.org/archlinux/packaging/packages/lmdb.git
lvm2 41d043868d89148475f6b35049d0cf915346a309 https://gitlab.archlinux.org/archlinux/packaging/packages/lvm2.git
lz4 076c161de8c991f45091bf62a0cc39ddc5a45445 https://gitlab.archlinux.org/archlinux/packaging/packages/lz4.git
m4 8d427e7ad898cf68d466d24663445319e50c0438 https://gitlab.archlinux.org/archlinux/packaging/packages/m4.git
make 4d865385b09185093589a83352c10b81c56f0624 https://gitlab.archlinux.org/archlinux/packaging/packages/make.git
meson ff8fdbf2ebc0b792940ddfefdcf51fcba180535a https://gitlab.archlinux.org/archlinux/packaging/packages/meson.git
mpdecimal 97bd21a0ac8a8268e0ed8b2c73addf307c7e3be5 https://gitlab.archlinux.org/archlinux/packaging/packages/mpdecimal.git
mpfr e27b6c97553f1975c5aed9214421c3f804cd9cc6 https://gitlab.archlinux.org/archlinux/packaging/packages/mpfr.git
ncurses d4793eded7e1af898845a294ea9e7df7617346fa https://gitlab.archlinux.org/archlinux/packaging/packages/ncurses.git
nettle 2ff22835ddfdfbb161468c050aad4b81b1897ae4 https://gitlab.archlinux.org/archlinux/packaging/packages/nettle.git
ninja 90b1fa92ba7de92d6adeddef54e3547f9936d490 https://gitlab.archlinux.org/archlinux/packaging/packages/ninja.git
nlohmann-json 0fd1e698245e0175842c5da5df802bbb3b300afa https://gitlab.archlinux.org/archlinux/packaging/packages/nlohmann-json.git
npth 1b2368b8edfe8b8c8d247776f1836157ba2daabc https://gitlab.archlinux.org/archlinux/packaging/packages/npth.git
nspr 342de75dc3fa9529664070f60367e134d54f7e08 https://gitlab.archlinux.org/archlinux/packaging/packages/nspr.git
nss d2bfe1eaed93ae02efe69baa0ffb393687bcccd3 https://gitlab.archlinux.org/archlinux/packaging/packages/nss.git
openldap 5aa84bc5167fb8ad392136496e7cd518415ff430 https://gitlab.archlinux.org/archlinux/packaging/packages/openldap.git
openssl 7ccf1c694a2b13124db1867a83354419d61155f1 https://gitlab.archlinux.org/archlinux/packaging/packages/openssl.git
p11-kit 88d86284cb6640d38872f49b0ae40885901083ec https://gitlab.archlinux.org/archlinux/packaging/packages/p11-kit.git
pacman abdc0dfedf3ca553a02dde8551e972fe745535b7 https://gitlab.archlinux.org/archlinux/packaging/packages/pacman.git
pacman-mirrorlist cdd43159511061a3705873ea9356f99f0abea832 https://gitlab.archlinux.org/archlinux/packaging/packages/pacman-mirrorlist.git
pam b37ce90d5b3ecbc83f9ca1c0644a5c055f51b89f https://gitlab.archlinux.org/archlinux/packaging/packages/pam.git
pambase 18ff110e2b4181d8b84bccdf86525cf2a50ad20d https://gitlab.archlinux.org/archlinux/packaging/packages/pambase.git
patch 1510b48e7c483c2b2390da6db729bae2bc224c31 https://gitlab.archlinux.org/archlinux/packaging/packages/patch.git
patchelf 613753346ac32d150a8d194b09b9800fc402f2fe https://gitlab.archlinux.org/archlinux/packaging/packages/patchelf.git
pcre2 8bc00874943fc29b4fd51fc3cd7f844f77540849 https://gitlab.archlinux.org/archlinux/packaging/packages/pcre2.git
perl 082f5d4956953eddd296f6d7e28f2f4d8f02e67f https://gitlab.archlinux.org/archlinux/packaging/packages/perl.git
perl-error 74aef3ceb2bf6df06740b7be607dfe5a21d325cb https://gitlab.archlinux.org/archlinux/packaging/packages/perl-error.git
perl-locale-gettext 8420cef9ab4b27eec812de91755e80128c25e01f https://gitlab.archlinux.org/archlinux/packaging/packages/perl-locale-gettext.git
perl-mailtools bd80e1bc526deae831ace860455d2519fe6a1295 https://gitlab.archlinux.org/archlinux/packaging/packages/perl-mailtools.git
perl-timedate 0c4bac17183489ece9370298f45faf8fef586cb4 https://gitlab.archlinux.org/archlinux/packaging/packages/perl-timedate.git
pinentry 960a245f317f34fce281246f46d66f0d9b9d5eae https://gitlab.archlinux.org/archlinux/packaging/packages/pinentry.git
pkgconf fd5cdd4c656e1d7db763518d55a95f085e80a6f1 https://gitlab.archlinux.org/archlinux/packaging/packages/pkgconf.git
popt a40d1ac24230f1aab1034cf67423694fcbe3be4c https://gitlab.archlinux.org/archlinux/packaging/packages/popt.git
python 3254b074f643d1fe29c72516f4ccb5dc4eeba2ac https://gitlab.archlinux.org/archlinux/packaging/packages/python.git
python-build 4d3e49b21fdb9e3648ca89bae4f27cb9a3681b78 https://gitlab.archlinux.org/archlinux/packaging/packages/python-build.git
python-flit-core 85b6eb1e07f482cd748b30e6feee8b3d09c443d1 https://gitlab.archlinux.org/archlinux/packaging/packages/python-flit-core.git
python-installer eac45dc1cca1a3e08192ded2f206b9882ba62559 https://gitlab.archlinux.org/archlinux/packaging/packages/python-installer.git
python-packaging a61fb6392a3d58655c46d6fba09f8edb978bb562 https://gitlab.archlinux.org/archlinux/packaging/packages/python-packaging.git
python-pyproject-hooks 3f43005e004dd15d6aa2dde0cd3f34886f954b2c https://gitlab.archlinux.org/archlinux/packaging/packages/python-pyproject-hooks.git
python-setuptools 8b56f5626b15d6b62ea6653e34e93d3a7e6dbb3e https://gitlab.archlinux.org/archlinux/packaging/packages/python-setuptools.git
python-tqdm e0b7ec5522cc742812ba067fab0c0db660333063 https://gitlab.archlinux.org/archlinux/packaging/packages/python-tqdm.git
python-wheel fa134ae45e7a48fc26dbb5c7aa4a78c16f9f61dd https://gitlab.archlinux.org/archlinux/packaging/packages/python-wheel.git
readline 562fc3dc105d29b06ad9bfae84e27387d1d50b6a https://gitlab.archlinux.org/archlinux/packaging/packages/readline.git
rhash 61d85647a7448bab282f716abed0cdfb7709cdce https://gitlab.archlinux.org/archlinux/packaging/packages/rhash.git
rsync a39d75c48e9ad042c9f1911ea9051cdfc0095d7e https://gitlab.archlinux.org/archlinux/packaging/packages/rsync.git
scdoc b64728f57c4dc9ea783ad8784244892cba6b514d https://gitlab.archlinux.org/archlinux/packaging/packages/scdoc.git
sed 780ca8fdf9c24e621892422449f81258c1bc557b https://gitlab.archlinux.org/archlinux/packaging/packages/sed.git
shadow b9fd1505550d16a29861b4a0f6ac2de9a6d51a5a https://gitlab.archlinux.org/archlinux/packaging/packages/shadow.git
sqlite 214bd51b91465641e9e4d9a7e4a6e0b008ccb5b6 https://gitlab.archlinux.org/archlinux/packaging/packages/sqlite.git
swig f0a3306021a19081736d55fa70c406d933ecdd9e https://gitlab.archlinux.org/archlinux/packaging/packages/swig.git
systemd c308648aad46596b85bed9ca75c2b0148c9ee0f2 https://gitlab.archlinux.org/archlinux/packaging/packages/systemd.git
tar 5a387a9a4b6c783d80f406b26ddf079c435ffced https://gitlab.archlinux.org/archlinux/packaging/packages/tar.git
tcl 3d1fb2cdd9faf93c8fee65f3b298b146667091cb https://gitlab.archlinux.org/archlinux/packaging/packages/tcl.git
texinfo 9782313fb801fbb2ed9d2e748c1e37e86db40f96 https://gitlab.archlinux.org/archlinux/packaging/packages/texinfo.git
thin-provisioning-tools 7fab7c19d42dcfdde7525353ffbd4d13c851220e https://gitlab.archlinux.org/archlinux/packaging/packages/thin-provisioning-tools.git
tpm2-tss 608d3ed4aa216f1ae9e76ccde010a4ca995b05ca https://gitlab.archlinux.org/archlinux/packaging/packages/tpm2-tss.git
tzdata b4310c9e1ed8dc4db77df94064e0e34b253476f7 https://gitlab.archlinux.org/archlinux/packaging/packages/tzdata.git
unixodbc c815df040bb9090643cf7fcbd3553053bc21e895 https://gitlab.archlinux.org/archlinux/packaging/packages/unixodbc.git
util-linux fdd37ea8813a904217449ec3dd4a484289bf36d5 https://gitlab.archlinux.org/archlinux/packaging/packages/util-linux.git
wget 1f6bebfe16b4aa0dfdc0508ed9ccd6dac3ac5d4c https://gitlab.archlinux.org/archlinux/packaging/packages/wget.git
which 571f8d0043f15de2b95214447ccc3fdc353bfa3e https://gitlab.archlinux.org/archlinux/packaging/packages/which.git
xxhash 894683581bbd1394bc3ab53033206bc96c9bafe2 https://gitlab.archlinux.org/archlinux/packaging/packages/xxhash.git
xz f4f6ad564c6bfdbdb759e89a20695f7c984795f4 https://gitlab.archlinux.org/archlinux/packaging/packages/xz.git
zlib ba441e639f2382b1a53dd46933629ee49c69aefb https://gitlab.archlinux.org/archlinux/packaging/packages/zlib.git
zlib-ng 7fbfaedb20d80b1722fb344d204487f0e4cf58d4 https://gitlab.archlinux.org/archlinux/packaging/packages/zlib-ng.git
zstd 954700db664044388cabc818d703bcfae97bfa1c https://gitlab.archlinux.org/archlinux/packaging/packages/zstd.git