From cf3a4ffdf4fccc1d225078f0f729128f6bff75f8 Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Mon, 24 Aug 2026 00:46:33 -0400 Subject: [PATCH] [FIX] ARTEFACT condemned two correct packages MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Run against stage 2's output for the first time, the check reported: python 17 x s390x-linux-gnu/ filesystem 11 x usr/local/ Both are correct. CPython names two paths after the build triplet on every platform -- the Arch x86_64 package ships _sysconfigdata__linux_x86_64-linux-gnu.py and config-3.14-x86_64-linux-gnu/ -- so the triplet there is CPython's convention, not Debian's layout leaking in. And creating /usr/local's skeleton is what the filesystem package exists for; the FHS requires those directories. Exempted by (package, pattern) pair rather than by package, so python is still checked for lib64 and dist-packages and filesystem for multiarch. A blanket exemption is how a real leak gets waved through -- and this check has now condemned correct code three times: the tcl8.6 grep in sqlite's hook, the intolerant-rm guard in systemd's, and this. With the exemptions, stage 2's 209 packages pass: no multiarch, no lib64, no dist-packages, no usr/local. --- FR --- Passé pour la première fois sur la production de l'étage 2, le test signalait : python 17 x s390x-linux-gnu/ filesystem 11 x usr/local/ Les deux sont justes. CPython nomme deux chemins d'après le triplet de construction sur toute plateforme — le paquet Arch x86_64 livre _sysconfigdata__linux_x86_64-linux-gnu.py et config-3.14-x86_64-linux-gnu/ — le triplet y est donc une convention de CPython, non la disposition de Debian qui s'infiltre. Et créer le squelette de /usr/local est la raison d'être du paquet filesystem ; le FHS l'exige. Exemptés par couple (paquet, motif) et non par paquet : python reste contrôlé pour lib64 et dist-packages, filesystem pour le multiarch. Une exemption globale est la façon dont une vraie fuite passe — et ce test a désormais condamné du code juste trois fois : le grep tcl8.6 du hook sqlite, le garde rm de celui de systemd, et ceci. Avec les exemptions, les 209 paquets de l'étage 2 passent : ni multiarch, ni lib64, ni dist-packages, ni usr/local. Assisted-by: Claude Opus 5 --- scripts/test-chroot.sh | 36 ++++++++++++++++++++++++++++++++---- 1 file changed, 32 insertions(+), 4 deletions(-) diff --git a/scripts/test-chroot.sh b/scripts/test-chroot.sh index ca2bc88..81d0676 100755 --- a/scripts/test-chroot.sh +++ b/scripts/test-chroot.sh @@ -110,11 +110,37 @@ note "2. ARTEFACT -- wrong library directories, which raise no error" # as its default libdir, which changed where pkgconf installed, which changed # pkgconf's compiled-in search path, which broke every pkg-config lookup in the # chroot. One stray .a file at the bottom of that. +# TWO EXEMPTIONS, each named with its reason, because this check condemned +# correct packages on its first run against stage 2's output: +# +# python 17 x s390x-linux-gnu/ usr/lib/python3.14/config-3.14-s390x-linux-gnu/ +# usr/lib/python3.14/_sysconfigdata__linux_s390x-linux-gnu.py +# filesystem 11 x usr/local/ usr/local/{bin,etc,games,include,...} +# +# CPython names those two after the build triplet on EVERY platform -- the Arch +# x86_64 package ships _sysconfigdata__linux_x86_64-linux-gnu.py -- so the +# triplet there is CPython's convention, not Debian's layout leaking in. And +# creating /usr/local's skeleton is what the filesystem package is for; the FHS +# requires it. +# +# Exempted by (package, pattern) pair rather than by package, so python is still +# checked for lib64 and dist-packages, and filesystem for multiarch. A blanket +# exemption is how a real leak gets waved through. +_exempt() { # _exempt + case "$(basename "$1")|$2" in + python-3*'|s390x-linux-gnu/') return 0 ;; + filesystem-*'|^usr/local/') return 0 ;; + esac + return 1 +} + n=0 for f in "$REPO"/*.pkg.tar.*; do _l=$(bsdtar -tf "$f" 2>/dev/null) - c=$(grep -c 's390x-linux-gnu/' <<< "$_l") - [ "$c" -gt 0 ] && { bad "$(basename "$f"): $c multiarch paths"; n=$((n + 1)); } + if ! _exempt "$f" 's390x-linux-gnu/'; then + c=$(grep -c 's390x-linux-gnu/' <<< "$_l") + [ "$c" -gt 0 ] && { bad "$(basename "$f"): $c multiarch paths"; n=$((n + 1)); } + fi c=$(grep -c '^usr/lib64/' <<< "$_l") [ "$c" -gt 0 ] && { bad "$(basename "$f"): $c paths under usr/lib64"; n=$((n + 1)); } # dist-packages: Debian's name for site-packages. @@ -134,8 +160,10 @@ for f in "$REPO"/*.pkg.tar.*; do [ "$c" -gt 0 ] && { bad "$(basename "$f"): $c paths under dist-packages"; n=$((n + 1)); } # usr/local: python's posix_local scheme, and anything else that took the # host's idea of where a local install goes. - c=$(grep -c '^usr/local/' <<< "$_l") - [ "$c" -gt 0 ] && { bad "$(basename "$f"): $c paths under usr/local"; n=$((n + 1)); } + if ! _exempt "$f" '^usr/local/'; then + c=$(grep -c '^usr/local/' <<< "$_l") + [ "$c" -gt 0 ] && { bad "$(basename "$f"): $c paths under usr/local"; n=$((n + 1)); } + fi done [ "$n" -eq 0 ] && good "no multiarch, no lib64, no dist-packages, no usr/local"