refactor: migrate package installation from pak to uvr

bincraft dropped pak in favour of uvr, so the pipelines, helper scripts
and images in this repo move with it.

- add local/uvr-install.sh as the single replacement for pak::pak(); it
  bootstraps a pinned uvr, mints a throwaway project under TMPDIR and
  runs `uvr add --no-install` + `uvr sync --library`, because `uvr add`
  refuses to run outside a project and only `sync` honours --library
- install bincraft via its Forgejo spec (forgejo::codefloe.com/rpkgs/
  bincraft@<tag>) instead of a git:: URL, keeping the git ls-remote tag
  resolution
- pass UVR_R_BIN/UVR_TARGET_LIB from install-bincraft.R so the
  per-R-minor passes target their own R and library
- replace R_PKG_CACHE_DIR with UVR_CACHE_DIR/UVR_PACKAGES_DIR on the
  persistent volume, preserving the amd64-off/arm64-on split
- drop trim_pkgcache_metadata() and its test; uvr's cache does not grow
  the way pkgcache's _metadata dir did
- let uvr install system requirements from its vendored
  r-system-requirements rules, replacing pak::sysreqs_db_update()
- migrate the shiny app image, the alpine reprex and the CRAN loading
  test; ship uvr-install.sh in the build-one image
- track the uvr pin with renovate
This commit is contained in:
Patrick Schratz 2026-07-31 12:16:32 +00:00
commit f3c18b6805
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC
7 changed files with 327 additions and 245 deletions

View file

@ -45,7 +45,7 @@ steps:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/R -q -e 'pak::pak(c("httr2", "jsonlite"))'
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2 jsonlite
- /opt/R/$R_VERSION/bin/Rscript local/propose-patches.R --open-pr --limit $PATCH_LIMIT
backend_options:
kubernetes:

View file

@ -10,22 +10,22 @@ variables:
- arm64
default: amd64
OS:
description: "Base OS image name."
description: 'Base OS image name.'
options:
- alpine
- redhat
- ubuntu
default: alpine
OS_VERSION:
description: "OS image tag. Must match OS (alpine: 3.24; redhat: 8/9/10; ubuntu: jammy/noble)."
description: 'OS image tag. Must match OS (alpine: 3.24; redhat: 8/9/10; ubuntu: jammy/noble).'
options:
- "3.24"
- "8"
- "9"
- "10"
- "jammy"
- "noble"
default: "3.24"
- '3.24'
- '8'
- '9'
- '10'
- 'jammy'
- 'noble'
default: '3.24'
R_VERSION:
description: 'Primary R version under /opt/R.'
options:
@ -66,23 +66,24 @@ steps:
from_secret: B2_S3_SECRET_KEY
PGPASS:
from_secret: PGPASS
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
R_LIBS_USER: /mnt/cache/R-pkgs
# Keep uvr's downloads and extracted-package entries on the persistent
# volume instead of the container-local ~/.uvr default.
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
CCACHE_DIR: /mnt/cache/ccache
volumes:
- ${ARCH}-binaries-r-dep-cache-${OS}-${OS_VERSION//./}:/mnt/cache
commands:
# one-time full wipe to fix corrupted .so files from previous failed builds
# - rm -rf /mnt/cache/R-pkgs
# Clear churny pkgcache metadata left by a prior crashed run (the "patched"
# repo mints a new hash per PACKAGES change -> unbounded pkgs-*.rds/patched-*).
# Keep pkg/ downloads and the stable CRAN/BioC/INLA repo dirs.
- rm -rf /mnt/cache/pkgcache/R/pkgcache/_metadata/patched-* /mnt/cache/pkgcache/R/pkgcache/_metadata/pkgs-*.rds || true
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
# Pin the same bincraft version the build steps use, so the precomputed
# snapshot and the per-agent library stay consistent across the pipeline.
- /opt/R/$R_VERSION/bin/R -q -e 'pak::sysreqs_db_update(); source("local/install-bincraft.R"); pak::pak(c("RPostgres", "s3fs", "data.table", "future", "jsonlite")); packageVersion("bincraft")'
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh RPostgres s3fs data.table future jsonlite
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
- /opt/R/$R_VERSION/bin/R -q -e "source('local/packages-to-build.R'); saveRDS(pkgs, '/mnt/cache/packages/pkgs_to_build.rds'); saveRDS(pkgs[r_minor_sensitive == TRUE], '/mnt/cache/packages/r_minor_sensitive_pkgs.rds'); sprintf('Precomputed %s package versions (%s r-minor-sensitive)', nrow(pkgs), nrow(pkgs[r_minor_sensitive == TRUE]))"
backend_options:
docker:

View file

@ -11,25 +11,25 @@ variables:
- arm64
default: amd64
OS:
description: "Base OS image name."
description: 'Base OS image name.'
options:
- alpine
- redhat
- ubuntu
default: alpine
OS_VERSION:
description: "OS image tag. Must match OS (alpine: 3.24; redhat: 8/9/10; ubuntu: jammy/noble)."
description: 'OS image tag. Must match OS (alpine: 3.24; redhat: 8/9/10; ubuntu: jammy/noble).'
options:
- "3.22"
- "3.23"
- "3.24"
- "8"
- "9"
- "10"
- "jammy"
- "noble"
- "resolute"
default: "3.24"
- '3.22'
- '3.23'
- '3.24'
- '8'
- '9'
- '10'
- 'jammy'
- 'noble'
- 'resolute'
default: '3.24'
R_VERSION:
description: 'Primary R version under /opt/R.'
options:
@ -47,38 +47,49 @@ labels:
platform: linux/${ARCH}
group: rpkgs-${ARCH}
# Empty UVR_CACHE_DIR/UVR_PACKAGES_DIR fall back to uvr's container-local
# ~/.uvr defaults; amd64 deliberately does not persist them (as with the
# pkgcache dir it replaces), arm64 does.
matrix:
include:
- ARCH: amd64
R_PKG_CACHE_DIR: ''
UVR_CACHE_DIR: ''
UVR_PACKAGES_DIR: ''
SPLIT_INTO: 4
SPLIT_INDEX: 1
- ARCH: amd64
R_PKG_CACHE_DIR: ''
UVR_CACHE_DIR: ''
UVR_PACKAGES_DIR: ''
SPLIT_INTO: 4
SPLIT_INDEX: 2
- ARCH: amd64
R_PKG_CACHE_DIR: ''
UVR_CACHE_DIR: ''
UVR_PACKAGES_DIR: ''
SPLIT_INTO: 4
SPLIT_INDEX: 3
- ARCH: amd64
R_PKG_CACHE_DIR: ''
UVR_CACHE_DIR: ''
UVR_PACKAGES_DIR: ''
SPLIT_INTO: 4
SPLIT_INDEX: 4
- ARCH: arm64
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
SPLIT_INTO: 4
SPLIT_INDEX: 1
- ARCH: arm64
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
SPLIT_INTO: 4
SPLIT_INDEX: 2
- ARCH: arm64
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
SPLIT_INTO: 4
SPLIT_INDEX: 3
- ARCH: arm64
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
SPLIT_INTO: 4
SPLIT_INDEX: 4
@ -107,8 +118,10 @@ steps:
from_secret: GITHUB_PAT
# normal env vars
GIT_USER: pat-s
# set the location of the 'pkgcache' cache dir which persists the R package dependencies needed to install the packages themselves
R_PKG_CACHE_DIR: ${R_PKG_CACHE_DIR}
# set the location of uvr's caches, which persist the R package
# dependencies needed to install the packages themselves
UVR_CACHE_DIR: ${UVR_CACHE_DIR}
UVR_PACKAGES_DIR: ${UVR_PACKAGES_DIR}
R_LIBS_USER: /mnt/cache/R-pkgs
CCACHE_DIR: /mnt/cache/ccache
NCPUS: 2
@ -116,12 +129,7 @@ steps:
- ${ARCH}-binaries-r-dep-cache-${OS}-${OS_VERSION//./}:/mnt/cache
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
# Clear churny pkgcache metadata left by a prior crashed run (the "patched"
# repo mints a new hash per PACKAGES change -> unbounded pkgs-*.rds/patched-*).
# Keep pkg/ downloads and the stable CRAN/BioC/INLA repo dirs. Within-run
# growth is bounded separately by trim_pkgcache_metadata() in build-all.R.
- rm -rf /mnt/cache/pkgcache/R/pkgcache/_metadata/patched-* /mnt/cache/pkgcache/R/pkgcache/_metadata/pkgs-*.rds || true
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
# The primary pass must not rely on build-all-versions-install-deps having
# run on *this* agent: depends_on only orders the steps, but the cache
# volume is per-agent, so a job landing on an agent where install-deps did

View file

@ -49,109 +49,109 @@ matrix:
R_VERSION: 4.5.3
IMG: alpine:3.22
OS_ID: alpine322
PROCESS_NEW: "FALSE"
PROCESS_NEW: 'FALSE'
- OS: alpine-322
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.23
OS_ID: alpine322
PROCESS_NEW: "FALSE"
PROCESS_NEW: 'FALSE'
- OS: alpine-323
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.23
OS_ID: alpine323
PROCESS_NEW: "FALSE"
PROCESS_NEW: 'FALSE'
- OS: alpine-323
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.23
OS_ID: alpine323
PROCESS_NEW: "FALSE"
PROCESS_NEW: 'FALSE'
- OS: alpine-324
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.24
OS_ID: alpine324
PROCESS_NEW: "FALSE"
PROCESS_NEW: 'FALSE'
- OS: alpine-324
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.24
OS_ID: alpine324
PROCESS_NEW: "FALSE"
PROCESS_NEW: 'FALSE'
- OS: redhat-8
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:8
OS_ID: rhel8
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: redhat-8
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:8
OS_ID: rhel8
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: redhat-9
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:9
OS_ID: rhel9
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: redhat-9
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:9
OS_ID: rhel9
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: redhat-10
ARCH: amd64
R_VERSION: 4.5.3
IMG: redhat:10
OS_ID: rhel10
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: redhat-10
ARCH: arm64
R_VERSION: 4.5.3
IMG: redhat:10
OS_ID: rhel10
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: ubuntu-2204
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
OS_ID: jammy
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: ubuntu-2204
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
OS_ID: jammy
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: ubuntu-2404
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:noble
OS_ID: noble
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: ubuntu-2404
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:noble
OS_ID: noble
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: ubuntu-2604
ARCH: amd64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
OS_ID: resolute
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
- OS: ubuntu-2604
ARCH: arm64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
OS_ID: resolute
PROCESS_NEW: "TRUE"
PROCESS_NEW: 'TRUE'
steps:
- name: 'Processing Updates'
@ -182,8 +182,10 @@ steps:
NTFY_AUTH: TRUE
NTFY_PASSWORD:
from_secret: ntfy_token
# set the location of the 'pkgcache' cache dir which persists the R package dependencies needed to install the packages themselves
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
# set the location of uvr's caches, which persist the R package
# dependencies needed to install the packages themselves
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
R_LIBS_USER: /mnt/cache/R-pkgs
R_VERSION: ${R_VERSION}
CCACHE_DIR: /mnt/cache/ccache
@ -194,10 +196,10 @@ steps:
INTERVAL: lubridate::interval(lubridate::today() - 6, lubridate::today() - 3)
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- rm -rf /mnt/cache/R-pkgs/00LOCK-* /mnt/cache/R-pkgs/bincraft /mnt/cache/R-pkgs/pkgcache /mnt/cache/pkgcache/R/pkgcache
- rm -rf /mnt/cache/R-pkgs/00LOCK-* /mnt/cache/R-pkgs/bincraft
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
# rhel-10 ships xwfb-run (Xwayland) instead of xvfb-run; prefer it and start weston, else fall back to xvfb-run
- XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run); XVFB_ARGS=""; if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi
# options(future.globals.onReference = NULL): for some reason s3fs::file_delete() throws 'Error: Detected a non-exportable reference ('externalptr') in one of the globals ('FUN' of class 'function') used in the future expression' otherwise

View file

@ -142,7 +142,9 @@ steps:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/packages /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/R -q -e 'pak::pak(c("git::https://codefloe.com/rpkgs/bincraft.git", "httr2", "jsonlite"))'
# bincraft is taken from the default branch here (not the latest release
# tag), matching what the pak call did before the uvr migration.
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh forgejo::codefloe.com/rpkgs/bincraft httr2 jsonlite
- /opt/R/$R_VERSION/bin/R -q -e 'source("local/weekly-missing-binaries-audit.R")'
backend_options:
docker:

View file

@ -35,7 +35,7 @@ steps:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/R -q -e 'pak::pak(c("httr2", "jsonlite"))'
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2 jsonlite
- /opt/R/$R_VERSION/bin/Rscript local/propose-patches.R --open-issue
- /opt/R/$R_VERSION/bin/Rscript local/proposal-tracking.R --open-issue
backend_options:

View file

@ -141,7 +141,8 @@ steps:
FORGEJO_TOKEN:
from_secret: FORGEJO_TOKEN
GIT_USER: pat-s
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
UVR_CACHE_DIR: /mnt/cache/uvr/cache
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
R_LIBS_USER: /mnt/cache/R-pkgs
R_VERSION: ${R_VERSION}
CCACHE_DIR: /mnt/cache/ccache
@ -150,12 +151,12 @@ steps:
NCPUS: 2
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
- XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run); XVFB_ARGS=""; if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi
- /opt/R/$R_VERSION/bin/R -q -e 'pak::pak("httr2")'
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2
- /opt/R/$R_VERSION/bin/R -q -e 'source("local/fetch-rebuild-packages-from-issue.R")'
- $XVFB $XVFB_ARGS -- /opt/R/$R_VERSION/bin/R -q -e "sink(stdout(), type = 'message'); options(crayon.enabled = TRUE, Ncpus = $NCPUS, future.globals.onReference = NULL); pkgs <- readLines('/tmp/rebuild_pkgs.txt'); if (length(pkgs) == 0) { cat('Nothing to rebuild\n'); q('no') }; excluded <- jsonlite::fromJSON('local/excluded-packages.json')[['package']]; pkgs <- setdiff(pkgs, excluded); cat(sprintf('Rebuilding %d packages\n', length(pkgs))); n <- length(pkgs); for (i in seq_along(pkgs)) { x <- pkgs[i]; cat(sprintf('[%d/%d] %s\n', i, n, x)); tryCatch(bincraft::build_binary_package(x, tag_limit = 1L, patches = 'local/patches', s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'), metadata_db_host = 'r-binaries.devxy.io', metadata_db_name = 'build_metadata', metadata_db_table = 'single_builds', metadata_db_user = 'rpkgs', metadata_db_password = Sys.getenv('PGPASS'), metadata_db_sslmode = 'require', metadata_db_port = 15432, archive = TRUE, upload = TRUE, store_build_metadata = TRUE), error = function(e) cat(sprintf('ERROR building %s - %s\n', x, conditionMessage(e)))) }" 2>&1
backend_options: