archlinux-s390x/patches/pkgbuild/make.sh
Mathieu Benoit 3c926f10a9 [FIX] declared, never linked: guile, libisl.so, leancrypto
An audit of every missing dependency spelled as a soname, asking the ARTEFACT
whether the package that declares it actually links it. It contradicted my
guesses: curl's krb5, ssh2 and idn2 are all real. Two were not.

  make      readelf -d usr/bin/make -> libc.so.6, and nothing else
  gcc       configure recorded ISLLIBS='' ISLINC=''; zero libisl in the tree

Both are false in our build environment and true in Arch's. --nodeps means
makepkg never checks, so each shipped a package asking for something this
port will never contain -- and only pacman ever notices, at install time.

Building isl was the first plan. Its Arch packaging repo was last touched in
2017 and its only source URL is isl.gforge.inria.fr, dead with INRIA's
GForge. There is nothing to build; the declaration goes instead, and Graphite
goes with it.

gnutls found the same shape from the other direction: --with-leancrypto
stopped configure, and 'leancrypto' sat in depends= where nothing checks it.

--- FR ---

Un audit de chaque dépendance manquante écrite en soname, demandant à
l'ARTEFACT si le paquet qui la déclare la lie vraiment. Il a contredit mes
suppositions : les krb5, ssh2 et idn2 de curl sont bien réels. Deux ne
l'étaient pas.

  make      readelf -d usr/bin/make -> libc.so.6, et rien d'autre
  gcc       configure a noté ISLLIBS='' ISLINC='' ; aucun libisl dans l'arbre

Les deux sont fausses dans notre environnement et vraies dans celui d'Arch.
--nodeps veut dire que makepkg ne vérifie jamais : chacun livrait donc un
paquet réclamant ce que ce portage ne contiendra jamais — et seul pacman s'en
aperçoit, à l'installation.

Bâtir isl était le premier plan. Son dépôt de packaging Arch n'a pas bougé
depuis 2017 et sa seule source pointe isl.gforge.inria.fr, morte avec le
GForge d'INRIA. Il n'y a rien à bâtir : c'est la déclaration qui part, et
Graphite avec elle.

gnutls a montré la même forme par l'autre bout : --with-leancrypto arrêtait
configure, et 'leancrypto' figurait dans depends= où rien ne le vérifie.

Assisted-by: Claude Opus 5
2026-08-19 05:28:32 -04:00

38 lines
1.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# make: it declares guile, and our make has no guile in it.
#
# depends=('glibc' 'guile')
#
# GNU make's configure AUTO-DETECTS guile -- the PKGBUILD passes a bare
# `./configure --prefix=/usr` and says nothing about it. This build host has
# no guile at all, so the $(guile ...) function was never compiled in, and the
# artefact says so plainly:
#
# $ readelf -d usr/bin/make | grep NEEDED
# (NEEDED) Shared library: [libc.so.6]
#
# One library. Nothing else.
#
# THE TRAP is that nothing fails. --nodeps means makepkg never checks the
# declaration, so make built, passed, and entered the repository asking for a
# package this port does not have and does not need. It is the same class as
# gcc-libs declaring libhwasan: a dependency that is real in Arch's build
# environment and false in ours, and the only thing that ever notices is
# pacman, at install time, long after the cause.
#
# It is worth the entry it costs. guile drags in bdw-gc and libffi behind it,
# so this single false line was three packages of closure for a feature the
# binary does not contain.
#
# WHY REMOVE RATHER THAN BUILD. Because the declaration should describe THIS
# artefact. Building guile and rebuilding make would be the other honest
# answer and would match Arch exactly -- TODO.md records it as deferred, with
# the cost, so the choice stays visible. What is not defensible is shipping a
# make that claims a feature it lacks.
set -euo pipefail
grep -q "^depends=('glibc' 'guile')$" PKGBUILD || {
echo "make: depends line is not the expected ('glibc' 'guile')" >&2; exit 1; }
sed -i "s/^depends=('glibc' 'guile')$/depends=('glibc')/" PKGBUILD
grep -q "^depends=('glibc')$" PKGBUILD || {
echo "make: guile not removed from depends" >&2; exit 1; }
echo "make: guile dropped from depends (the binary links libc only)"