[ADD] closure rounds two and three, and the CA bundle

Thirty-five packages pulled in nineteen more, and those two. The resolver
named each round as precisely as the first, and it now reports satisfied:
101 packages, --nodeps off.

THE MEASUREMENT THAT CHANGED ITS ANSWER. Four of round two were going to be
avoided by dropping sub-packages -- sqlite-tcl, sqlite-analyzer, the openldap
server, debuginfod -- reasoning that had been right for python-brotli.
Measured instead: tcl, unixodbc and libmicrohttpd each cost ZERO new
packages, because the closure had filled in around them. Building them beats
four hooks, and it does not leave sqlite shipping an sqltclsh that cannot
start. The arithmetic that was right at forty packages was wrong at a hundred
and thirty.

ca-certificates-mozilla is the only entry here that is not a library: it is
the root certificate list itself, and ca-certificates is only the machinery
around it. Without it the target trusts nothing and every HTTPS verification
fails. It has no packaging repo -- nss produces it -- so nss and nspr came
too, measured first: nspr free, nss needing only mercurial on the host, and
hg.mozilla.org answering in 0.3s. 172 certificates shipped.

--- FR ---

Trente-cinq paquets en ont tiré dix-neuf autres, puis ces deux-là. Le
résolveur a nommé chaque tour aussi précisément que le premier, et il se
déclare maintenant satisfait : 101 paquets, --nodeps désactivé.

LA MESURE QUI A CHANGÉ SA RÉPONSE. Quatre paquets du deuxième tour allaient
être évités en écartant des sous-paquets — sqlite-tcl, sqlite-analyzer, le
serveur openldap, debuginfod — par un raisonnement juste pour python-brotli.
Mesuré plutôt que supposé : tcl, unixodbc et libmicrohttpd coûtent ZÉRO
paquet nouveau, la fermeture s'étant refermée autour d'eux. Les bâtir vaut
mieux que quatre crochets, et évite de livrer un sqlite contenant un sqltclsh
incapable de démarrer. L'arithmétique juste à quarante paquets était fausse à
cent trente.

ca-certificates-mozilla est la seule entrée ici qui ne soit pas une
bibliothèque : c'est la liste des certificats racine elle-même, et
ca-certificates n'en est que la mécanique. Sans lui la cible ne fait
confiance à rien et toute vérification HTTPS échoue. Il n'a pas de dépôt de
packaging — nss le produit — donc nss et nspr ont suivi, mesurés d'abord :
nspr gratuit, nss ne réclamant que mercurial sur l'hôte, et hg.mozilla.org
répondant en 0,3 s. 172 certificats livrés.

Assisted-by: Claude Opus 5
This commit is contained in:
Mathieu Benoit 2026-08-19 06:24:11 -04:00
parent cb13d98b2b
commit de7a4c70a2
2 changed files with 74 additions and 1 deletions

View file

@ -90,6 +90,30 @@ install_host_deps() {
# qhelpgenerator -- and the third needs Qt, so the chain had no end. Its
# doc features are pinned off in a hook instead. A single missing library
# is a host dep; a queue of them is a feature that should be disabled.
#
# The closure's second round wanted three more, and each named a program
# rather than a library: asn1Parser by p11-kit (libtasn1-bin -- we build
# the libtasn1 PACKAGE, but the host needs the TOOL), libevent by
# libverto, libaio by lvm2.
#
# libsasl asked for a fourth and did not get it. Its error said
# "libpq-fe.h: No such file or directory" while the header sat in
# /usr/include/postgresql, and mysql.h sat in /usr/include/mariadb -- two
# files that exist, on paths configure does not try. By the rule above,
# that is a queue, so the SQL auxprop plugin is disabled in a hook
# instead. Arch declares depends=(glibc) for libsasl and says why: the
# plugins are dlopened, so nothing is lost.
#
# mercurial is for nss, whose only source is an hg clone of Mozilla's NSS
# repository. gyp, perl and python were already here.
#
# libnspr4-dev is nss's other half: its build hardcodes -I/usr/include/nspr
# and stops on `plarena.h: No such file or directory`. We DO build an nspr
# package -- 4.40, newer than the host's 4.36 -- but this is an ABSENCE on
# the host, not an age, so the ordinary stage-1 rule applies and the host
# package is the answer. The libgcrypt hook exists precisely because that
# rule did not apply there: 1.51 against a floor of 1.56 cannot be fixed
# by installing anything.
sudo apt-get -o DPkg::Lock::Timeout=600 install -y -qq \
meson ninja-build pkg-config gettext \
libarchive-dev libcurl4-openssl-dev libgpgme-dev libssl-dev \
@ -114,7 +138,8 @@ install_host_deps() {
libcryptsetup-dev libgcrypt20-dev libgnutls28-dev libpam0g-dev \
libpopt-dev scdoc libgpg-error-dev cython3 tcl-dev libsodium-dev \
autoconf-archive ducktype \
yelp-tools liblmdb-dev libcmocka-dev libverto-dev uthash-dev
yelp-tools liblmdb-dev libcmocka-dev libverto-dev uthash-dev \
libtasn1-bin libevent-dev libaio-dev mercurial libnspr4-dev
install_host_shims
}

View file

@ -93,6 +93,54 @@ STAGE1_PACKAGES=(
icu jansson kbd kmod krb5 libcap-ng libgcrypt libidn2 libksba
libmpc libnsl libseccomp libssh2 libtirpc libunistring libusb libxcrypt
nettle npth openldap pambase pcre2 perl pinentry sqlite tpm2-tss
# Closure, second round. The first thirty-five pulled these in, exactly as
# the comment above predicted, and the resolver named them just as
# precisely.
#
# THE MEASUREMENT THAT MATTERS HERE IS THE ONE THAT CHANGED ITS ANSWER.
# Four of these were going to be avoided by dropping a sub-package --
# sqlite-tcl, sqlite-analyzer, the openldap server, debuginfod -- on the
# reasoning that had removed python-brotli earlier. Measured instead of
# assumed, tcl, unixodbc and libmicrohttpd each cost ZERO new packages:
# the closure had filled in around them. Building them is cheaper than
# four hooks, and it does not leave sqlite shipping an sqltclsh that
# cannot start.
#
# python still costs three (libffi, mpdecimal, gdbm) and is still avoided
# -- but for the ABI reason, not the cost one: python-audit and
# python-capng are cp313 wheels and Arch ships 3.14. Their hooks say so.
#
db5.3 gdbm e2fsprogs gnulib-l10n json-c keyutils p11-kit libsasl
libsodium libtasn1 libverto lmdb popt lvm2 tcl unixodbc libmicrohttpd
# ca-certificates-mozilla, which is the only thing here that is not a
# library. It is the LIST OF ROOT CERTIFICATES -- ca-certificates itself
# is only the trust machinery around it, so without this the target has a
# trust store containing nothing, and every HTTPS verification fails.
# curl declares ca-certificates, and pacman fetches through curl.
#
# It has no packaging repo of its own: the clone 404s, which
# gitlab.archlinux.org reports by asking for a login -- the same
# misleading shape that made libselinux look like a network problem. nss
# produces it as a sub-package, so nss is what gets built, and nspr comes
# with it.
#
# Measured before committing to it rather than estimated: nspr costs
# nothing new, nss needs only nspr plus mercurial on the host, and
# hg.mozilla.org answers from this build host (HTTP 302 in 0.3s -- worth
# checking, since dev.gnupg.org does not answer at all and libassuan
# needed a source change because of it).
nspr nss
# Closure, third round, and it is two packages. Both were pulled in by
# what the second round added, and both cost nothing further: libffi by
# libp11-kit, libevent by libverto.
#
# They are worth a line because of what they unblocked. p11-kit builds
# into three packages, and libp11-kit's dependency on libffi was holding
# up the whole chain ca-certificates -> ca-certificates-utils -> p11-kit
# -> libp11-kit. The resolver reported it as "ca-certificates required by
# curl" -- four links away from the missing name, and nothing in that
# message points at libffi.
libffi libevent
# And finally the package manager itself, built as an Arch package.
pacman
)