fix(index): add a slot repair for a broken Built stamp and retire alpine 3.21

`arm64/alpine321` (22,930 entries) and `arm64/alpine322` (24,696 entries)
advertise `Built: R <ver>; NA; ...`. uvr matches the stamp's platform triple
plus R minor to pick binary over source, so no client matches those slots and
both silently serve as source-only, which is the regression the stamp was added
to prevent. The tarballs themselves carry the correct triple; only the index is
wrong.

Re-running the normal index update does not fix it: `upload_package_index()`
reuses the slot's remote `PACKAGES.db` and cranlike's `update_db()` only
reparses files whose md5 changed. Dropping `PACKAGES.db` to force a full reparse
does work, but for an S3 repo cranlike reads each package's metadata from the
CRAN source mirror on GitHub, so a 25k-entry slot means 25k requests to
raw.githubusercontent.com and a real risk of being rate-limited part-way.

Only the `Built` column is wrong, so correct it in place: patch the column in
`PACKAGES.db`, put it back, and let `upload_package_index()` re-emit `PACKAGES*`
from it. `update_db()` always rewrites the index files even when nothing was
reparsed, so no tarball is re-read and nothing is fetched from GitHub.

Alpine 3.21 is EOL: the website advertises only 3.23/3.24 and
`process-updates.yaml` dropped it, so remove its two leftover matrix entries
from the archive pipeline rather than repairing that slot.
This commit is contained in:
Patrick Schratz 2026-08-07 09:05:52 +00:00
commit 72de7ae6d1
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC
2 changed files with 272 additions and 4 deletions

View file

@ -28,10 +28,6 @@ matrix:
ARCH: amd64
- CODENAME: redhat-10
ARCH: arm64
- CODENAME: alpine321
ARCH: amd64
- CODENAME: alpine321
ARCH: arm64
- CODENAME: alpine322
ARCH: amd64
- CODENAME: alpine322

View file

@ -0,0 +1,97 @@
### Manual repair of a slot whose PACKAGES index advertises a broken `Built`
### stamp (e.g. `Built: R 4.5.0; NA; ...`).
#
# uvr matches the stamp's platform triple plus R minor to decide binary vs
# source, so an unusable triple turns a whole slot source-only. See
# local/repair-built-stamp.R for why this patches PACKAGES.db in place instead
# of forcing a full reparse.
#
# Run with `dry_run: true` first: it reports how many entries are broken per
# slot and changes nothing. Pick the R version the slot should advertise, which
# is the R_VERSION its entry in .crow/process-updates.yaml uses.
variables:
target_arch:
description: 'Architecture of the slot to repair.'
options:
- amd64
- arm64
default: arm64
OS:
description: 'Base OS image name.'
options:
- alpine
- redhat
- ubuntu
default: alpine
OS_VERSION:
description: 'OS image tag. Must match OS (alpine: 3.22/3.23/3.24; redhat: 8/9/10; ubuntu: jammy/noble/resolute).'
options:
- '3.22'
- '3.23'
- '3.24'
- '8'
- '9'
- '10'
- 'jammy'
- 'noble'
- 'resolute'
default: '3.22'
R_VERSION:
description: 'R version whose stamp the slot should advertise.'
options:
- 4.5.3
- 4.4.3
default: 4.5.3
dry_run:
description: 'Report what would change without writing anything.'
options:
- 'true'
- 'false'
default: 'true'
when:
- event: manual
evaluate: 'target_arch == "${ARCH}"'
skip_clone: true
labels:
platform: linux/${ARCH}
group: rpkgs-${ARCH}
matrix:
include:
- ARCH: amd64
- ARCH: arm64
steps:
- name: 'Repair Built stamp'
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
pull: true
environment:
B2_S3_ACCESS_KEY:
from_secret: B2_S3_ACCESS_KEY
B2_S3_SECRET_KEY:
from_secret: B2_S3_SECRET_KEY
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
GIT_USER: pat-s
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
- |
if [ "$dry_run" = "false" ]; then
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH" --apply
else
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH"
fi
backend_options:
docker:
resources:
requests:
memory: 2Gi
cpu: 1000m
limits:
memory: 8Gi
cpu: 2000m