# syntax=docker/dockerfile:1 # Targeted (re)build of specific package versions, executed on a remote buildx # builder. The build's effect is the S3 upload performed by build-one.R; no # image is kept (the justfile uses --output type=cacheonly). CACHEBUST forces # the RUN to re-execute on every invocation. # # Build context is `local/` (see the `rebuild` recipe in the justfile). ARG OS ARG OS_VERSION FROM reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION} ARG R_VERSION=4.5.3 ARG PACKAGE ARG VERSIONS ARG CACHEBUST WORKDIR /work COPY build-one.R /work/build-one.R # Resolve and install the latest bincraft release dynamically (no hardcoded pin). COPY install-bincraft.R /work/install-bincraft.R # Ship the patch registry so build-one.R's `patches = "local/patches"` resolves # (build context is `local/`, CWD is /work). COPY patches /work/local/patches RUN --mount=type=secret,id=b2_access,required=true \ --mount=type=secret,id=b2_secret,required=true \ --mount=type=secret,id=pgpass,required=true \ --mount=type=secret,id=github_pat,required=false \ export B2_S3_ACCESS_KEY="$(cat /run/secrets/b2_access)" && \ export B2_S3_SECRET_KEY="$(cat /run/secrets/b2_secret)" && \ export PGPASS="$(cat /run/secrets/pgpass)" && \ export GITHUB_PAT="$(cat /run/secrets/github_pat 2>/dev/null || true)" && \ export GIT_TERMINAL_PROMPT=0 && \ export OTEL_SDK_DISABLED=true && \ export OTEL_R_TRACES_EXPORTER=none && \ export OTEL_R_LOGS_EXPORTER=none && \ export OTEL_R_METRICS_EXPORTER=none && \ XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run || true); \ XVFB_ARGS=""; \ if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi; \ USE_XVFB=0; \ if [ -n "$XVFB" ] && $XVFB -a $XVFB_ARGS -- true >/dev/null 2>&1; then \ USE_XVFB=1; echo "Using virtual display via $XVFB"; \ else \ echo "No working virtual display; building without xvfb" >&2; \ fi; \ run_build() { if [ "$USE_XVFB" = 1 ]; then $XVFB -a $XVFB_ARGS -- "$@"; else "$@"; fi; }; \ ensure_bincraft() { "$1" -q -e 'source("/work/install-bincraft.R")'; }; \ PRIMARY_MINOR=$(echo "$R_VERSION" | cut -d. -f1-2); \ seen=" $PRIMARY_MINOR "; \ prc=0; failed=""; \ rm -f .r_minor_sensitive; \ echo "=== primary pass under R $R_VERSION ==="; \ ensure_bincraft /opt/R/${R_VERSION}/bin/R; \ run_build /opt/R/${R_VERSION}/bin/Rscript /work/build-one.R "${PACKAGE}" ${VERSIONS} || prc=$?; \ if [ -f .r_minor_sensitive ]; then \ for RBIN in /opt/R/*/bin/Rscript; do \ [ -x "$RBIN" ] || continue; \ RV=$(basename "$(dirname "$(dirname "$RBIN")")"); \ case "$RV" in [0-9]*) ;; *) continue ;; esac; \ RMINOR=$(echo "$RV" | cut -d. -f1-2); \ case "$seen" in *" $RMINOR "*) continue ;; esac; \ seen="$seen$RMINOR "; \ echo "=== sensitive-only pass under R $RV ==="; \ ensure_bincraft "$(dirname "$RBIN")/R"; \ run_build "$RBIN" /work/build-one.R --sensitive-only "${PACKAGE}" ${VERSIONS} || failed="$failed $RV"; \ done; \ else \ echo "Package not r-minor-sensitive; skipping per-minor passes."; \ fi; \ if [ -n "$failed" ]; then echo "WARNING: extra-minor build(s) failed (non-fatal; e.g. a version too old to compile on a newer R):$failed" >&2; fi; \ if [ "$prc" != 0 ]; then echo "primary pass under R $R_VERSION failed (exit $prc)" >&2; fi; \ exit "$prc"