archlinux-s390x/patches/pkgbuild/gnutls.sh
Mathieu Benoit 3c926f10a9 [FIX] declared, never linked: guile, libisl.so, leancrypto
An audit of every missing dependency spelled as a soname, asking the ARTEFACT
whether the package that declares it actually links it. It contradicted my
guesses: curl's krb5, ssh2 and idn2 are all real. Two were not.

  make      readelf -d usr/bin/make -> libc.so.6, and nothing else
  gcc       configure recorded ISLLIBS='' ISLINC=''; zero libisl in the tree

Both are false in our build environment and true in Arch's. --nodeps means
makepkg never checks, so each shipped a package asking for something this
port will never contain -- and only pacman ever notices, at install time.

Building isl was the first plan. Its Arch packaging repo was last touched in
2017 and its only source URL is isl.gforge.inria.fr, dead with INRIA's
GForge. There is nothing to build; the declaration goes instead, and Graphite
goes with it.

gnutls found the same shape from the other direction: --with-leancrypto
stopped configure, and 'leancrypto' sat in depends= where nothing checks it.

--- FR ---

Un audit de chaque dépendance manquante écrite en soname, demandant à
l'ARTEFACT si le paquet qui la déclare la lie vraiment. Il a contredit mes
suppositions : les krb5, ssh2 et idn2 de curl sont bien réels. Deux ne
l'étaient pas.

  make      readelf -d usr/bin/make -> libc.so.6, et rien d'autre
  gcc       configure a noté ISLLIBS='' ISLINC='' ; aucun libisl dans l'arbre

Les deux sont fausses dans notre environnement et vraies dans celui d'Arch.
--nodeps veut dire que makepkg ne vérifie jamais : chacun livrait donc un
paquet réclamant ce que ce portage ne contiendra jamais — et seul pacman s'en
aperçoit, à l'installation.

Bâtir isl était le premier plan. Son dépôt de packaging Arch n'a pas bougé
depuis 2017 et sa seule source pointe isl.gforge.inria.fr, morte avec le
GForge d'INRIA. Il n'y a rien à bâtir : c'est la déclaration qui part, et
Graphite avec elle.

gnutls a montré la même forme par l'autre bout : --with-leancrypto arrêtait
configure, et 'leancrypto' figurait dans depends= où rien ne le vérifie.

Assisted-by: Claude Opus 5
2026-08-19 05:28:32 -04:00

40 lines
1.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# gnutls: leancrypto is asked for, and Ubuntu has no such library.
#
# configure: error: leancrypto support was requested but the required
# libraries were not found.
#
# Arch packages leancrypto -- a post-quantum crypto library -- and gnutls
# links it for ML-KEM and ML-DSA. Nothing about s390x prevents it; the build
# host simply cannot supply it, and building leancrypto first would add a
# package to the closure for algorithms pacman does not use. It signs with
# OpenPGP through gpgme, and TLS to the mirrors needs none of this.
#
# TWO PLACES, and the second is the one that bites silently. The configure
# flag is what stops the build, so it is what gets noticed. But 'leancrypto'
# is ALSO in depends=, and --nodeps means makepkg never checks it: gnutls
# would build, pass, and enter the repository asking for a package this port
# will never contain. Same shape as gcc-libs declaring libhwasan, and as make
# declaring guile -- the third instance of it in this port, which is why the
# audit that finds them is now part of the routine rather than an afterthought.
set -euo pipefail
python3 - <<'PY'
import io
s = io.open("PKGBUILD", encoding="utf-8").read()
# (a) the flag that stops configure. It is the LAST option on the line, with
# no trailing backslash, so the preceding backslash goes with it.
old = " \\\n --with-leancrypto"
assert s.count(old) == 1, "gnutls: expected exactly one --with-leancrypto"
s = s.replace(old, "", 1)
# (b) the declaration nobody checks
old = "'leancrypto' "
assert s.count(old) == 1, "gnutls: expected exactly one leancrypto in depends"
s = s.replace(old, "", 1)
io.open("PKGBUILD", "w", encoding="utf-8").write(s)
PY
grep -q 'leancrypto' PKGBUILD && {
echo "gnutls: leancrypto still referenced" >&2; exit 1; }
echo "gnutls: leancrypto dropped from configure AND from depends"