archlinux-s390x/patches/pkgbuild/ca-certificates.sh
Mathieu Benoit f2aff788ec [FIX] the chroot could not resolve a name, and wget could not fix itself
Four packages -- m4, libtool, groff, libnghttp2 -- failed in prepare() on

  fatal: unable to access 'https://github.com/...': Could not resolve host
  Failed to clone 'gl-mod/bootstrap' a second time, aborting

Arch takes its sources from git and these fetch gnulib as a submodule, so a
chroot with no resolv.conf cannot start the build at all. The retry line is what
makepkg prints; the reason sits one line above it.

Six more stopped on wget, which links libnettle.so.8 -- Ubuntu's soname, where
ours is .9. Our gnutls is already a stage-2 package and correctly wants .9; wget
was the last thing holding the old one, and gnulib's bootstrap fetches
translation catalogues WITH wget, so the tool it needed to fix itself was itself.
It joins libxml2 in STAGE2_HOST_EXTRACT: the host, which has a working wget, runs
prepare(); the chroot compiles.

Also fixed: my own ca-certificates hook left build() containing nothing but a
comment, which bash reports as a syntax error on the closing brace.

--- FR ---

Quatre paquets — m4, libtool, groff, libnghttp2 — ont échoué dans prepare() sur

  fatal: unable to access 'https://github.com/...': Could not resolve host
  Failed to clone 'gl-mod/bootstrap' a second time, aborting

Arch tire ses sources de git et ceux-là récupèrent gnulib en sous-module : un
chroot sans resolv.conf ne peut pas même commencer. La ligne de reprise est ce
qu'affiche makepkg ; la raison est juste au-dessus.

Six autres se sont arrêtés sur wget, qui lie libnettle.so.8 — le soname
d'Ubuntu, quand le nôtre est .9. Notre gnutls est déjà un paquet d'étage 2 et
demande bien .9 ; wget était le dernier à retenir l'ancien, et le bootstrap de
gnulib récupère les catalogues de traduction AVEC wget : l'outil dont il avait
besoin pour se réparer était lui-même. Il rejoint libxml2 dans
STAGE2_HOST_EXTRACT — l'hôte, qui a un wget valide, exécute prepare() ; le chroot
compile.

Corrigé aussi : mon propre hook ca-certificates laissait build() avec un seul
commentaire, ce que bash signale comme une erreur de syntaxe sur l'accolade.

Assisted-by: Claude Opus 5
2026-08-21 16:29:10 -04:00

37 lines
1.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# ca-certificates: no man page for update-ca-trust.
#
# a2x: command not found
#
# a2x belongs to asciidoc, a Python toolchain whose only job here is turning
# update-ca-trust.8.txt into update-ca-trust.8. TWO lines have to go, not one:
# build() renders it and package() installs it. Removing only the render leaves
#
# install: cannot stat 'update-ca-trust.8'
#
# which is the same shape as libxml2's docs split -- a failure on the last line
# of package(), naming a path, after a build that worked.
set -euo pipefail
python3 - <<'ZZPY'
import io, re
lines = io.open("PKGBUILD", encoding="utf-8").read().split("\n")
a2x = [i for i, l in enumerate(lines) if re.match(r"^[ \t]*a2x\b", l)]
man = [i for i, l in enumerate(lines) if "update-ca-trust.8" in l and "install " in l]
assert len(a2x) == 1, "ca-certificates: expected one a2x call, got %d" % len(a2x)
assert len(man) == 1, "ca-certificates: expected one man install, got %d" % len(man)
# `:` and not just a comment. a2x was the ONLY statement in build(), and a
# bash function whose body is a comment is a syntax error:
#
# PKGBUILD: line 37: `}'
# ==> ERROR: Failed to source PKGBUILD
#
# which reads like a corrupted file rather than an emptied function.
lines[a2x[0]] = (" : # a2x removed: no asciidoc toolchain at either stage."
" Kept as `:` because it was build()'s only statement.")
lines[man[0]] = " # man page not installed: nothing rendered it."
out = [l.replace(" asciidoc\n", "") for l in lines]
io.open("PKGBUILD", "w", encoding="utf-8").write("\n".join(out))
ZZPY
grep -q "a2x removed" PKGBUILD && grep -q "nothing rendered it" PKGBUILD || {
echo "ca-certificates: one of the two lines was not replaced" >&2; exit 1; }
echo "ca-certificates: update-ca-trust man page dropped"