fix: audit workflows
Some checks failed
ci/crow/manual/weekly-audit-missing-alpine-323-amd64 Pipeline was successful
ci/crow/cron/weekly-audit-missing-redhat-9-amd64 Pipeline failed
ci/crow/manual/weekly-rebuild-missing-alpine-323-amd64 Pipeline was successful

This commit is contained in:
Patrick Schratz 2026-04-21 20:30:33 +02:00
commit db80080f95
Signed by: pat-s
GPG key ID: 3C6318841EF78925
2 changed files with 333 additions and 214 deletions

View file

@ -0,0 +1,87 @@
library(httr2, quietly = TRUE)
forgejo_base <- "https://git.devxy.io/api/v1"
repo <- "devxy/build-cran-binaries"
platform <- Sys.getenv("PLATFORM")
arch <- Sys.getenv("ARCH")
token <- Sys.getenv("FORGEJO_TOKEN")
output_file <- Sys.getenv("REBUILD_PKG_LIST", "/tmp/rebuild_pkgs.txt")
if (nchar(platform) == 0) stop("PLATFORM env var is not set")
if (nchar(arch) == 0) stop("ARCH env var is not set")
if (nchar(token) == 0) stop("FORGEJO_TOKEN env var is not set")
os_family <- if (grepl("^ubuntu", platform)) {
"Ubuntu"
} else if (grepl("^alpine", platform)) {
"Alpine"
} else if (grepl("^redhat", platform)) {
"Red Hat"
} else {
platform
}
issue_title <- sprintf("Missing package binaries for latest version (%s)", os_family)
cat(sprintf("Searching for issue: %s\n", issue_title))
search_url <- sprintf(
"%s/repos/%s/issues?type=issues&state=open&q=%s&limit=50",
forgejo_base, repo,
utils::URLencode(issue_title, reserved = TRUE)
)
search_resp <- request(search_url) |>
req_headers(Authorization = paste("token", token)) |>
req_perform()
issues <- resp_body_json(search_resp, simplifyVector = FALSE)
match_idx <- which(vapply(issues, function(x) x$title, character(1)) == issue_title)
if (length(match_idx) == 0) {
cat("No matching issue found - nothing to rebuild\n")
writeLines(character(0), output_file)
q("no")
}
body <- issues[[match_idx[1]]]$body
if (is.null(body) || nchar(body) == 0) {
cat("Issue body is empty - nothing to rebuild\n")
writeLines(character(0), output_file)
q("no")
}
lines <- strsplit(body, "\n", fixed = TRUE)[[1]]
# Find the platform section (## alpine-322)
plat_header <- sprintf("## %s", platform)
plat_idx <- which(lines == plat_header)
if (length(plat_idx) == 0) {
cat(sprintf("No section found for platform %s - nothing to rebuild\n", platform))
writeLines(character(0), output_file)
q("no")
}
# Find the arch subsection (### arm64 (...))
arch_pattern <- sprintf("^### %s ", arch)
arch_idx <- which(grepl(arch_pattern, lines) & seq_along(lines) > plat_idx[1])
if (length(arch_idx) == 0) {
cat(sprintf("No section found for arch %s under %s - nothing to rebuild\n", arch, platform))
writeLines(character(0), output_file)
q("no")
}
ai <- arch_idx[1]
# Find the end of the rebuildable section: stop at ####, ###, ##, ---, or EOF
end_idx <- which(grepl("^####|^###|^##|^---", lines) & seq_along(lines) > ai)
end_idx <- if (length(end_idx) > 0) end_idx[1] - 1 else length(lines)
section_lines <- lines[seq(ai + 1, end_idx)]
# Extract package names from "- PackageName (Version)" lines
pkg_lines <- section_lines[grepl("^- ", section_lines)]
pkgs <- sub("^- ([^ ]+) \\(.*\\)$", "\\1", pkg_lines)
pkgs <- pkgs[nchar(pkgs) > 0 & pkgs != "_None_"]
cat(sprintf("Found %d rebuildable packages for %s/%s\n", length(pkgs), platform, arch))
writeLines(pkgs, output_file)
cat(sprintf("Wrote package list to %s\n", output_file))

View file

@ -38,7 +38,38 @@ cat(sprintf("Platform: %s | Arch: %s | S3 codename: %s | OS family: %s\n",
platform, arch, s3_codename, os_family))
# ---------------------------------------------------------------------------
# 1. CRAN release packages
# 1. Query PostgreSQL for known build failures (before s3fs init to avoid
# C++ pointer conflicts between s3fs/curl and RPostgres/libpq)
# ---------------------------------------------------------------------------
cat("Connecting to PostgreSQL...\n")
con <- DBI::dbConnect(
RPostgres::Postgres(),
dbname = "build_metadata",
host = "r-binaries.devxy.io",
port = 15432,
user = "rpkgs",
password = Sys.getenv("PGPASS"),
sslmode = "require"
)
errored_pkgs <- DBI::dbGetQuery(
con,
sprintf(
"SELECT name, tag FROM single_builds WHERE error_occurred = TRUE AND platform = '%s' AND arch = '%s'",
platform, arch
)
)
DBI::dbDisconnect(con)
errored_dt <- as.data.table(errored_pkgs)
if (nrow(errored_dt) > 0) {
setnames(errored_dt, c("Package", "Version"))
setkey(errored_dt, Package, Version)
}
cat(sprintf("Found %d known build failures for %s/%s\n", nrow(errored_dt), platform, arch))
# ---------------------------------------------------------------------------
# 2. CRAN release packages (uses curl internally - must come after PG)
# ---------------------------------------------------------------------------
cat("Fetching CRAN package database...\n")
cran_release <- tools::CRAN_package_db()
@ -48,7 +79,7 @@ cran_dt <- data.table(
)
# ---------------------------------------------------------------------------
# 2. S3 tarballs
# 3. S3 tarballs
# ---------------------------------------------------------------------------
cat("Connecting to S3...\n")
s3fs::s3_file_system(
@ -82,7 +113,7 @@ s3_dt <- data.table(
cat(sprintf("S3 contains %d tarballs for %s/%s\n", nrow(s3_dt), arch, s3_codename))
# ---------------------------------------------------------------------------
# 3. Find missing packages (CRAN release version not in S3)
# 4. Find missing packages (CRAN release version not in S3)
# ---------------------------------------------------------------------------
setkey(cran_dt, Package, Version)
setkey(s3_dt, Package, Version)
@ -90,7 +121,7 @@ missing_dt <- cran_dt[!s3_dt]
cat(sprintf("%d CRAN release packages missing from S3\n", nrow(missing_dt)))
# ---------------------------------------------------------------------------
# 4. Remove excluded packages
# 5. Remove excluded packages
# ---------------------------------------------------------------------------
script_dir <- tryCatch(
dirname(normalizePath(
@ -114,36 +145,6 @@ if (file.exists(excluded_path)) {
cat(sprintf("No excluded-packages.json found at %s -- skipping exclusion step\n", excluded_path))
}
# ---------------------------------------------------------------------------
# 5. Query PostgreSQL for known build failures
# ---------------------------------------------------------------------------
cat("Connecting to PostgreSQL...\n")
con <- DBI::dbConnect(
RPostgres::Postgres(),
dbname = "build_metadata",
host = "r-binaries.devxy.io",
port = 15432,
user = "rpkgs",
password = Sys.getenv("PGPASS"),
sslmode = "require"
)
on.exit(DBI::dbDisconnect(con), add = TRUE)
errored_pkgs <- DBI::dbGetQuery(
con,
sprintf(
"SELECT name, tag FROM single_builds WHERE error_occurred = TRUE AND platform = '%s' AND arch = '%s'",
platform, arch
)
)
errored_dt <- as.data.table(errored_pkgs)
if (nrow(errored_dt) > 0) {
setnames(errored_dt, c("Package", "Version"))
setkey(errored_dt, Package, Version)
}
cat(sprintf("Found %d known build failures for %s/%s\n", nrow(errored_dt), platform, arch))
# ---------------------------------------------------------------------------
# 6. Split into rebuildable vs known failures
# ---------------------------------------------------------------------------