diff --git a/scripts/bootstrap-pacman.sh b/scripts/bootstrap-pacman.sh index 0e8c7fe..3b4e035 100755 --- a/scripts/bootstrap-pacman.sh +++ b/scripts/bootstrap-pacman.sh @@ -90,6 +90,30 @@ install_host_deps() { # qhelpgenerator -- and the third needs Qt, so the chain had no end. Its # doc features are pinned off in a hook instead. A single missing library # is a host dep; a queue of them is a feature that should be disabled. + # + # The closure's second round wanted three more, and each named a program + # rather than a library: asn1Parser by p11-kit (libtasn1-bin -- we build + # the libtasn1 PACKAGE, but the host needs the TOOL), libevent by + # libverto, libaio by lvm2. + # + # libsasl asked for a fourth and did not get it. Its error said + # "libpq-fe.h: No such file or directory" while the header sat in + # /usr/include/postgresql, and mysql.h sat in /usr/include/mariadb -- two + # files that exist, on paths configure does not try. By the rule above, + # that is a queue, so the SQL auxprop plugin is disabled in a hook + # instead. Arch declares depends=(glibc) for libsasl and says why: the + # plugins are dlopened, so nothing is lost. + # + # mercurial is for nss, whose only source is an hg clone of Mozilla's NSS + # repository. gyp, perl and python were already here. + # + # libnspr4-dev is nss's other half: its build hardcodes -I/usr/include/nspr + # and stops on `plarena.h: No such file or directory`. We DO build an nspr + # package -- 4.40, newer than the host's 4.36 -- but this is an ABSENCE on + # the host, not an age, so the ordinary stage-1 rule applies and the host + # package is the answer. The libgcrypt hook exists precisely because that + # rule did not apply there: 1.51 against a floor of 1.56 cannot be fixed + # by installing anything. sudo apt-get -o DPkg::Lock::Timeout=600 install -y -qq \ meson ninja-build pkg-config gettext \ libarchive-dev libcurl4-openssl-dev libgpgme-dev libssl-dev \ @@ -114,7 +138,8 @@ install_host_deps() { libcryptsetup-dev libgcrypt20-dev libgnutls28-dev libpam0g-dev \ libpopt-dev scdoc libgpg-error-dev cython3 tcl-dev libsodium-dev \ autoconf-archive ducktype \ - yelp-tools liblmdb-dev libcmocka-dev libverto-dev uthash-dev + yelp-tools liblmdb-dev libcmocka-dev libverto-dev uthash-dev \ + libtasn1-bin libevent-dev libaio-dev mercurial libnspr4-dev install_host_shims } diff --git a/scripts/build-stage1.sh b/scripts/build-stage1.sh index 6adc48b..247cf7d 100755 --- a/scripts/build-stage1.sh +++ b/scripts/build-stage1.sh @@ -93,6 +93,54 @@ STAGE1_PACKAGES=( icu jansson kbd kmod krb5 libcap-ng libgcrypt libidn2 libksba libmpc libnsl libseccomp libssh2 libtirpc libunistring libusb libxcrypt nettle npth openldap pambase pcre2 perl pinentry sqlite tpm2-tss + # Closure, second round. The first thirty-five pulled these in, exactly as + # the comment above predicted, and the resolver named them just as + # precisely. + # + # THE MEASUREMENT THAT MATTERS HERE IS THE ONE THAT CHANGED ITS ANSWER. + # Four of these were going to be avoided by dropping a sub-package -- + # sqlite-tcl, sqlite-analyzer, the openldap server, debuginfod -- on the + # reasoning that had removed python-brotli earlier. Measured instead of + # assumed, tcl, unixodbc and libmicrohttpd each cost ZERO new packages: + # the closure had filled in around them. Building them is cheaper than + # four hooks, and it does not leave sqlite shipping an sqltclsh that + # cannot start. + # + # python still costs three (libffi, mpdecimal, gdbm) and is still avoided + # -- but for the ABI reason, not the cost one: python-audit and + # python-capng are cp313 wheels and Arch ships 3.14. Their hooks say so. + # + db5.3 gdbm e2fsprogs gnulib-l10n json-c keyutils p11-kit libsasl + libsodium libtasn1 libverto lmdb popt lvm2 tcl unixodbc libmicrohttpd + # ca-certificates-mozilla, which is the only thing here that is not a + # library. It is the LIST OF ROOT CERTIFICATES -- ca-certificates itself + # is only the trust machinery around it, so without this the target has a + # trust store containing nothing, and every HTTPS verification fails. + # curl declares ca-certificates, and pacman fetches through curl. + # + # It has no packaging repo of its own: the clone 404s, which + # gitlab.archlinux.org reports by asking for a login -- the same + # misleading shape that made libselinux look like a network problem. nss + # produces it as a sub-package, so nss is what gets built, and nspr comes + # with it. + # + # Measured before committing to it rather than estimated: nspr costs + # nothing new, nss needs only nspr plus mercurial on the host, and + # hg.mozilla.org answers from this build host (HTTP 302 in 0.3s -- worth + # checking, since dev.gnupg.org does not answer at all and libassuan + # needed a source change because of it). + nspr nss + # Closure, third round, and it is two packages. Both were pulled in by + # what the second round added, and both cost nothing further: libffi by + # libp11-kit, libevent by libverto. + # + # They are worth a line because of what they unblocked. p11-kit builds + # into three packages, and libp11-kit's dependency on libffi was holding + # up the whole chain ca-certificates -> ca-certificates-utils -> p11-kit + # -> libp11-kit. The resolver reported it as "ca-certificates required by + # curl" -- four links away from the missing name, and nothing in that + # message points at libffi. + libffi libevent # And finally the package manager itself, built as an Arch package. pacman )