The previous commit read the chroot's "coreutils needs libselinux.so.1" as a missing package. It is not one. Arch has no libselinux at all -- the clone 404s -- and Arch's coreutils declares no selinux dependency, because its build chroot has no selinux/selinux.h to find. Ours found one. Ubuntu carries libselinux1-dev, gnulib probes for the header unconditionally, and the audit names every victim: coreutils 13 binaries findutils find sed tar glibc makedb --without-selinux per package, which is what Arch gets for free. Arch ships neither chcon nor runcon either, so this converges with Arch rather than diverging. tar and find matter most: stage 2 runs makepkg inside this rootfs, and makepkg calls both. glibc is deliberately left alone. Nothing runs makedb, and rebuilding glibc would relink the foundation under sixty-nine other packages; stage 2 does it in a chroot where the header cannot be found. --- FR --- Le commit précédent a lu le « coreutils réclame libselinux.so.1 » du chroot comme un paquet manquant. Ce n'en est pas un. Arch n'a aucun libselinux — le clone rend un 404 — et son coreutils ne déclare aucune dépendance selinux, faute de selinux/selinux.h dans son chroot de construction. Le nôtre en a trouvé un. Ubuntu embarque libselinux1-dev, gnulib sonde l'en-tête sans condition, et l'audit nomme chaque victime : coreutils 13 binaires findutils find sed tar glibc makedb --without-selinux par paquet, ce qu'Arch obtient gratuitement. Arch ne livre ni chcon ni runcon non plus : on converge donc vers Arch au lieu de s'en écarter. tar et find sont les plus critiques — l'étage 2 lance makepkg dans ce rootfs, et makepkg les appelle tous deux. glibc est laissé tel quel, délibérément. Rien n'exécute makedb, et le reconstruire relierait la fondation sous soixante-neuf autres paquets ; l'étage 2 s'en charge dans un chroot où l'en-tête est introuvable. Assisted-by: Claude Opus 5
24 lines
1.2 KiB
Bash
Executable file
24 lines
1.2 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# findutils: --without-selinux. Same host artefact as coreutils.
|
|
#
|
|
# THE TRAP: fixing coreutils alone looks like the job is done. It is not.
|
|
#
|
|
# $ readelf -d repo/s390x/.../usr/bin/find | grep NEEDED
|
|
# (NEEDED) Shared library: [libselinux.so.1]
|
|
#
|
|
# and stage 2 runs makepkg INSIDE the stage-1 rootfs, where makepkg calls
|
|
# find. A find that will not load is a hard stop, not a cosmetic one.
|
|
#
|
|
# Arch's findutils declares depends=(glibc) and nothing else, because Arch's
|
|
# build chroot has no selinux/selinux.h for gnulib to probe. Ubuntu 25.10
|
|
# does, so ours linked it. patches/pkgbuild/coreutils.sh carries the full
|
|
# account, including why removing the header from the host is not available.
|
|
#
|
|
# One ./configure in this PKGBUILD (verified), so the anchor is unambiguous.
|
|
set -euo pipefail
|
|
grep -c -- '^ \./configure --prefix=/usr$' PKGBUILD | grep -qx 1 || {
|
|
echo "findutils: expected exactly one bare ./configure --prefix=/usr" >&2; exit 1; }
|
|
sed -i 's|^\(\s*\)\(\./configure --prefix=/usr\)$|\1\2 --without-selinux|' PKGBUILD
|
|
grep -c -- '--without-selinux' PKGBUILD | grep -qx 1 || {
|
|
echo "findutils: --without-selinux not inserted exactly once" >&2; exit 1; }
|
|
echo "findutils: --without-selinux (Arch has no libselinux; the host does)"
|