An audit of every missing dependency spelled as a soname, asking the ARTEFACT whether the package that declares it actually links it. It contradicted my guesses: curl's krb5, ssh2 and idn2 are all real. Two were not. make readelf -d usr/bin/make -> libc.so.6, and nothing else gcc configure recorded ISLLIBS='' ISLINC=''; zero libisl in the tree Both are false in our build environment and true in Arch's. --nodeps means makepkg never checks, so each shipped a package asking for something this port will never contain -- and only pacman ever notices, at install time. Building isl was the first plan. Its Arch packaging repo was last touched in 2017 and its only source URL is isl.gforge.inria.fr, dead with INRIA's GForge. There is nothing to build; the declaration goes instead, and Graphite goes with it. gnutls found the same shape from the other direction: --with-leancrypto stopped configure, and 'leancrypto' sat in depends= where nothing checks it. --- FR --- Un audit de chaque dépendance manquante écrite en soname, demandant à l'ARTEFACT si le paquet qui la déclare la lie vraiment. Il a contredit mes suppositions : les krb5, ssh2 et idn2 de curl sont bien réels. Deux ne l'étaient pas. make readelf -d usr/bin/make -> libc.so.6, et rien d'autre gcc configure a noté ISLLIBS='' ISLINC='' ; aucun libisl dans l'arbre Les deux sont fausses dans notre environnement et vraies dans celui d'Arch. --nodeps veut dire que makepkg ne vérifie jamais : chacun livrait donc un paquet réclamant ce que ce portage ne contiendra jamais — et seul pacman s'en aperçoit, à l'installation. Bâtir isl était le premier plan. Son dépôt de packaging Arch n'a pas bougé depuis 2017 et sa seule source pointe isl.gforge.inria.fr, morte avec le GForge d'INRIA. Il n'y a rien à bâtir : c'est la déclaration qui part, et Graphite avec elle. gnutls a montré la même forme par l'autre bout : --with-leancrypto arrêtait configure, et 'leancrypto' figurait dans depends= où rien ne le vérifie. Assisted-by: Claude Opus 5
38 lines
1.8 KiB
Bash
Executable file
38 lines
1.8 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# make: it declares guile, and our make has no guile in it.
|
|
#
|
|
# depends=('glibc' 'guile')
|
|
#
|
|
# GNU make's configure AUTO-DETECTS guile -- the PKGBUILD passes a bare
|
|
# `./configure --prefix=/usr` and says nothing about it. This build host has
|
|
# no guile at all, so the $(guile ...) function was never compiled in, and the
|
|
# artefact says so plainly:
|
|
#
|
|
# $ readelf -d usr/bin/make | grep NEEDED
|
|
# (NEEDED) Shared library: [libc.so.6]
|
|
#
|
|
# One library. Nothing else.
|
|
#
|
|
# THE TRAP is that nothing fails. --nodeps means makepkg never checks the
|
|
# declaration, so make built, passed, and entered the repository asking for a
|
|
# package this port does not have and does not need. It is the same class as
|
|
# gcc-libs declaring libhwasan: a dependency that is real in Arch's build
|
|
# environment and false in ours, and the only thing that ever notices is
|
|
# pacman, at install time, long after the cause.
|
|
#
|
|
# It is worth the entry it costs. guile drags in bdw-gc and libffi behind it,
|
|
# so this single false line was three packages of closure for a feature the
|
|
# binary does not contain.
|
|
#
|
|
# WHY REMOVE RATHER THAN BUILD. Because the declaration should describe THIS
|
|
# artefact. Building guile and rebuilding make would be the other honest
|
|
# answer and would match Arch exactly -- TODO.md records it as deferred, with
|
|
# the cost, so the choice stays visible. What is not defensible is shipping a
|
|
# make that claims a feature it lacks.
|
|
set -euo pipefail
|
|
grep -q "^depends=('glibc' 'guile')$" PKGBUILD || {
|
|
echo "make: depends line is not the expected ('glibc' 'guile')" >&2; exit 1; }
|
|
sed -i "s/^depends=('glibc' 'guile')$/depends=('glibc')/" PKGBUILD
|
|
grep -q "^depends=('glibc')$" PKGBUILD || {
|
|
echo "make: guile not removed from depends" >&2; exit 1; }
|
|
echo "make: guile dropped from depends (the binary links libc only)"
|