From 6372f0f928f81c76aaca3c3b6f71541a04a976d4 Mon Sep 17 00:00:00 2001 From: pat-s Date: Mon, 10 Aug 2026 06:30:25 +0000 Subject: [PATCH] fix(ci): refresh the apt index before uvr installs system dependencies (#161) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Unblocks the ubuntu 26.04 builds without waiting for an image rebuild. ## What broke ``` i Installing R package dependencies ! Error in installing dependencies for package huge with tag 2.0.1: uvr sync --install-system-deps --library /mnt/cache/R-pkgs-4.4 failed (exit 1) ! WARN Missing system dependencies for 1 package(s) igraph needs: libglpk-dev > Running: apt-get install -y libglpk-dev E: Unable to locate package libglpk-dev ``` Neither the package name nor the sysreq mapping is wrong. `libglpk-dev` is `5.0-2build1` in `universe`, which `ubuntu:resolute` enables by default. What is missing is the apt index: uvr v0.4.5 runs `apt-get install` with no `apt-get update` before it, and every ubuntu build image ends its apt layers with `rm -rf /var/lib/apt/lists/*`, so the shipped image has no index at all. Not specific to 26.04 — jammy and noble fail identically for any sysreq the image's preinstall line doesn't already cover. 26.04 surfaced it first, through `igraph` and everything depending on it (`huge` was the first to fail). ## Fix `apt-get update` before the sync in `local/uvr-install.sh`. That one site covers every pipeline: `build-all-versions`, `build-all-versions-install-deps`, `weekly-rebuild-missing`, `weekly-audit-missing`, `trial-build-registry`, `auto-apply-patches` and `weekly-patch-proposals` all reach it, either directly or through `install-bincraft.R`. The index it populates persists for the rest of the step, so the bincraft-driven `uvr sync` calls that follow are covered too. Guarded on `apt-get` and non-fatal: `apk add` fetches its index implicitly and dnf refreshes expired metadata on its own, so alpine and redhat are unaffected and skip it. ## Why here as well as in the image The real fix is upstream `e491b2e`, which refreshes the index before the auto-install. It landed one day after v0.4.5 was tagged, so no release carries it ([nbafrank/uvr#250](https://github.com/nbafrank/uvr/issues/250)); [build-env-images#23](https://codefloe.com/rpkgs/build-env-images/pulls/23) pins the ubuntu image to a commit that has it. That only reaches CI after an image rebuild is triggered. This change takes effect on the next pipeline run. It also stays useful afterwards: a baked index goes stale within weeks, and a stale index turns the same install into a 404 on the `.deb`. ## Verified In `ubuntu:resolute`, with the image state reproduced exactly (R installed, then `rm -rf /var/lib/apt/lists/*` to empty the index again): | Check | Result | |---|---| | `apt-get install -y libglpk-dev`, empty index | `E: Unable to locate package libglpk-dev` — the reported failure, reproduced | | Same container after `apt-get update` | `Candidate: 5.0-2build1`, `Components: main universe restricted multiverse` | | `igraph` + `UVR_INSTALL_SYSREQS=1 uvr sync`, empty index, uvr with the refresh | `Setting up libglpk-dev:amd64 (5.0-2build1)`, `System dependencies installed.`, `Installed 11 package(s)` | | `sh -n` and `shellcheck local/uvr-install.sh` | pass | ## Reverting Delete the guarded block. It is marked TEMPORARY with the upstream reference, and can go once the images ship a uvr above v0.4.5. Reviewed-on: https://git.devxy.io/devxy/build-cran-binaries/pulls/161 --- local/uvr-install.sh | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/local/uvr-install.sh b/local/uvr-install.sh index 14b7f78..c5d37d3 100755 --- a/local/uvr-install.sh +++ b/local/uvr-install.sh @@ -87,4 +87,23 @@ cd "$project_dir" # --no-install: resolve and lock only. The install happens in the sync below, # which is the only command that honours --library. "$uvr_bin" add --no-install "$@" + +# TEMPORARY (drop once the images ship a uvr above v0.4.5): the sync below runs +# `apt-get install` for every resolved system dependency without refreshing the +# index first, and the ubuntu build images end their apt layers with +# `rm -rf /var/lib/apt/lists/*`. With no index apt cannot resolve a package that +# exists and is enabled, so `igraph needs: libglpk-dev` fails the whole build +# with `E: Unable to locate package libglpk-dev` on ubuntu 26.04. +# +# Fixed upstream in `e491b2e`, tagged one day after v0.4.5 (nbafrank/uvr#250), +# and the images pick it up via build-env-images#23 — but only after an image +# rebuild is triggered, which is why this runs here too. +# +# apt only: `apk add` fetches its index implicitly and dnf refreshes expired +# metadata on its own. Non-fatal, since a refresh failure still leaves whatever +# index is already there, and the install's own error is the more actionable one. +if command -v apt-get >/dev/null 2>&1; then + apt-get update -qq || echo "warning: apt-get update failed; continuing" >&2 +fi + "$uvr_bin" sync --library "$target_lib" --install-system-deps