fix(index): add a slot repair for a broken Built stamp and retire alpine 3.21 (#150)
Some checks failed
ci/crow/manual/build-all-versions-install-deps/2 Pipeline is pending
ci/crow/manual/build-all-versions/5 Pipeline is pending
ci/crow/manual/build-all-versions/6 Pipeline is pending
ci/crow/manual/build-all-versions/7 Pipeline is pending
ci/crow/manual/build-all-versions/8 Pipeline is pending
ci/crow/manual/process-updates/2 Pipeline is pending
ci/crow/manual/process-updates/4 Pipeline is pending
ci/crow/manual/process-updates/6 Pipeline is pending
ci/crow/manual/process-updates/8 Pipeline is pending
ci/crow/manual/process-updates/10 Pipeline is pending
ci/crow/manual/process-updates/12 Pipeline is pending
ci/crow/manual/process-updates/14 Pipeline is pending
ci/crow/manual/process-updates/16 Pipeline is pending
ci/crow/manual/process-updates/18 Pipeline is pending
ci/crow/manual/repair-built-stamp/2 Pipeline is pending
ci/crow/manual/trial-build-registry/2 Pipeline is pending
ci/crow/manual/trial-build-registry/4 Pipeline is pending
ci/crow/manual/trial-build-registry/6 Pipeline is pending
ci/crow/manual/trial-build-registry/8 Pipeline is pending
ci/crow/manual/trial-build-registry/10 Pipeline is pending
ci/crow/manual/trial-build-registry/12 Pipeline is pending
ci/crow/manual/trial-build-registry/14 Pipeline is pending
ci/crow/manual/trial-build-registry/16 Pipeline is pending
ci/crow/manual/trial-build-registry/18 Pipeline is pending
ci/crow/manual/weekly-audit-missing/2 Pipeline is pending
ci/crow/manual/weekly-audit-missing/4 Pipeline is pending
ci/crow/manual/weekly-audit-missing/6 Pipeline is pending
ci/crow/manual/weekly-audit-missing/8 Pipeline is pending
ci/crow/manual/weekly-audit-missing/10 Pipeline is pending
ci/crow/manual/weekly-audit-missing/12 Pipeline is pending
ci/crow/manual/weekly-audit-missing/14 Pipeline is pending
ci/crow/manual/weekly-audit-missing/16 Pipeline is pending
ci/crow/manual/weekly-audit-missing/18 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/2 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/4 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/5 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/6 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/7 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/8 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/9 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/10 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/11 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/12 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/13 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/14 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/15 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/16 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/17 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/18 Pipeline is pending
ci/crow/manual/process-updates/9 Pipeline was successful
ci/crow/manual/trial-build-registry/1 Pipeline was successful
ci/crow/manual/trial-build-registry/3 Pipeline was successful
ci/crow/manual/trial-build-registry/5 Pipeline was successful
ci/crow/manual/process-updates/7 Pipeline was successful
ci/crow/manual/trial-build-registry/7 Pipeline was successful
ci/crow/manual/trial-build-registry/9 Pipeline was successful
ci/crow/manual/trial-build-registry/11 Pipeline was successful
ci/crow/manual/trial-build-registry/13 Pipeline was successful
ci/crow/manual/auto-apply-patches Pipeline was successful
ci/crow/manual/trial-build-registry/15 Pipeline was successful
ci/crow/manual/trial-build-registry/17 Pipeline was successful
ci/crow/manual/weekly-audit-missing/1 Pipeline was successful
ci/crow/manual/weekly-audit-missing/5 Pipeline was successful
ci/crow/manual/weekly-audit-missing/3 Pipeline was successful
ci/crow/manual/weekly-audit-missing/7 Pipeline was successful
ci/crow/manual/weekly-audit-missing/9 Pipeline was successful
ci/crow/manual/weekly-audit-missing/11 Pipeline was successful
ci/crow/manual/weekly-audit-missing/13 Pipeline was successful
ci/crow/manual/weekly-audit-missing/17 Pipeline was successful
ci/crow/manual/weekly-audit-missing/15 Pipeline was successful
ci/crow/manual/weekly-rebuild-missing/1 Pipeline was canceled
ci/crow/manual/weekly-rebuild-missing/3 Pipeline was canceled
ci/crow/manual/process-updates/3 Pipeline was canceled
ci/crow/manual/process-updates/15 Pipeline was canceled
ci/crow/manual/process-updates/11 Pipeline was canceled
ci/crow/manual/weekly-patch-proposals Pipeline was canceled
ci/crow/manual/process-updates/13 Pipeline was canceled
ci/crow/manual/process-updates/1 Pipeline was canceled
ci/crow/manual/process-updates/5 Pipeline was canceled
ci/crow/manual/process-updates/17 Pipeline was canceled
ci/crow/cron/process-updates/15 Pipeline failed

## Problem

`arm64/alpine321` and `arm64/alpine322` advertise a broken stamp:

```
arm64/alpine321 :: 22930  Built: R 4.4.0; NA; 2026-07-31 13:35:52 UTC; unix
arm64/alpine322 :: 24696  Built: R 4.5.0; NA; 2026-07-31 13:51:54 UTC; unix
```

The per-minor sub-slots (`contrib/4.4`, `4.5`, `4.6`) are affected too.
All 18 other slots are correct.

uvr matches the stamp's platform triple plus R minor to pick binary over source, so nothing matches `NA` and both slots silently serve as source-only, which is exactly the regression bincraft#85 added the stamp to prevent.
`install.packages()` is unaffected, since it reads `Built:` from each tarball's own `DESCRIPTION`.
The tarballs are fine (`arm64/alpine322/.../dress.graph_0.8.3.tar.gz` carries `aarch64-unknown-linux-musl`), and so is the R that built them (`r-4.5.0_1_aarch64.apk` ships `R_PLATFORM='aarch64-unknown-linux-musl'`).
Only the index is wrong.

bincraft#96 stops a stamp like this being written again, but it cannot repair what is already there.

## Why not just re-run the index update

`upload_package_index()` reuses the slot's remote `PACKAGES.db`, and cranlike's `update_db()` only reparses files whose md5 changed, so entries already in the database keep the stamp they were written with.

Dropping `PACKAGES.db` to force a full reparse does work, and it is what bincraft#85's rollout note suggested, but for an S3 repo cranlike reads each package's metadata from the CRAN *source* mirror on GitHub.
A 25k-entry slot is then 25k requests to raw.githubusercontent.com, with a real risk of being rate-limited part-way through and leaving the slot half-written.

Only the `Built` column is wrong, so this corrects it in place instead: patch the column in `PACKAGES.db`, put the database back, and let `upload_package_index()` re-emit `PACKAGES*` from it.
`update_db()` always rewrites the index files even when nothing was reparsed, so no tarball is re-read and nothing is fetched from GitHub.

## Change

- `local/repair-built-stamp.R` — repairs the generic slot plus every per-minor sub-slot. Dry-run by default; `--apply` writes. The replacement comes from `bincraft::built_stamp()` under the R running the script, so it is exactly what a healthy run would have written, and bincraft#96's guard makes a broken build image fail rather than write a second bad stamp.
- `.crow/repair-built-stamp.yaml` — manual pipeline, routed by `target_arch` to the matching agent group and platform image, with `dry_run` defaulting to `true`.
- `.crow/archive-missed-packages.yaml` — drop the two `alpine321` matrix entries. Alpine 3.21 is EOL: the website advertises only 3.23/3.24 and `process-updates.yaml` already dropped it, so that slot is retired rather than repaired.

## Verification

`crow lint .crow/` passes on all nine pipelines.
`air format` and `jarl check` are clean; the script parses, and the `/opt/R` minor-version derivation was checked against `4.4.3 / 4.5.3 / 4.6.0 / current` → `4.4 4.5 4.6`.
The repair itself is unrun by design — it needs B2 credentials and an arm64 agent.

## Rollout

1. Cut a bincraft release so `local/install-bincraft.R` picks up #96 (it resolves the latest `vX.Y.Z` tag, and #96 is only on `main`).
2. Run this pipeline with `target_arch=arm64`, `OS=alpine`, `OS_VERSION=3.22`, `R_VERSION=4.5.3`, `dry_run=true` and check the reported counts.
3. Re-run with `dry_run=false`.
4. Confirm: `curl -sS https://cran.devxy.io/arm64/alpine322/latest/src/contrib/PACKAGES | grep '^Built:' | sort | uniq -c`

`arm64/alpine321` is deliberately left alone.

Reviewed-on: #150
This commit is contained in:
Patrick Schratz 2026-08-07 09:15:04 +00:00 committed by Patrick Schratz
commit 0da29ab3f6
2 changed files with 272 additions and 4 deletions

View file

@ -28,10 +28,6 @@ matrix:
ARCH: amd64
- CODENAME: redhat-10
ARCH: arm64
- CODENAME: alpine321
ARCH: amd64
- CODENAME: alpine321
ARCH: arm64
- CODENAME: alpine322
ARCH: amd64
- CODENAME: alpine322

View file

@ -0,0 +1,97 @@
### Manual repair of a slot whose PACKAGES index advertises a broken `Built`
### stamp (e.g. `Built: R 4.5.0; NA; ...`).
#
# uvr matches the stamp's platform triple plus R minor to decide binary vs
# source, so an unusable triple turns a whole slot source-only. See
# local/repair-built-stamp.R for why this patches PACKAGES.db in place instead
# of forcing a full reparse.
#
# Run with `dry_run: true` first: it reports how many entries are broken per
# slot and changes nothing. Pick the R version the slot should advertise, which
# is the R_VERSION its entry in .crow/process-updates.yaml uses.
variables:
target_arch:
description: 'Architecture of the slot to repair.'
options:
- amd64
- arm64
default: arm64
OS:
description: 'Base OS image name.'
options:
- alpine
- redhat
- ubuntu
default: alpine
OS_VERSION:
description: 'OS image tag. Must match OS (alpine: 3.22/3.23/3.24; redhat: 8/9/10; ubuntu: jammy/noble/resolute).'
options:
- '3.22'
- '3.23'
- '3.24'
- '8'
- '9'
- '10'
- 'jammy'
- 'noble'
- 'resolute'
default: '3.22'
R_VERSION:
description: 'R version whose stamp the slot should advertise.'
options:
- 4.5.3
- 4.4.3
default: 4.5.3
dry_run:
description: 'Report what would change without writing anything.'
options:
- 'true'
- 'false'
default: 'true'
when:
- event: manual
evaluate: 'target_arch == "${ARCH}"'
skip_clone: true
labels:
platform: linux/${ARCH}
group: rpkgs-${ARCH}
matrix:
include:
- ARCH: amd64
- ARCH: arm64
steps:
- name: 'Repair Built stamp'
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
pull: true
environment:
B2_S3_ACCESS_KEY:
from_secret: B2_S3_ACCESS_KEY
B2_S3_SECRET_KEY:
from_secret: B2_S3_SECRET_KEY
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
GIT_USER: pat-s
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
- |
if [ "$dry_run" = "false" ]; then
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH" --apply
else
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH"
fi
backend_options:
docker:
resources:
requests:
memory: 2Gi
cpu: 1000m
limits:
memory: 8Gi
cpu: 2000m