Some checks failed
ci/crow/cron/auto-apply-patches Pipeline was successful
ci/crow/cron/weekly-audit-missing/1 Pipeline was successful
ci/crow/cron/weekly-audit-missing/2 Pipeline failed
ci/crow/cron/weekly-audit-missing/3 Pipeline was successful
ci/crow/cron/weekly-audit-missing/4 Pipeline was successful
ci/crow/cron/weekly-audit-missing/7 Pipeline was successful
ci/crow/cron/weekly-audit-missing/8 Pipeline failed
ci/crow/cron/weekly-audit-missing/9 Pipeline was successful
ci/crow/cron/weekly-audit-missing/10 Pipeline was successful
ci/crow/cron/weekly-audit-missing/11 Pipeline was successful
ci/crow/cron/weekly-audit-missing/12 Pipeline was successful
ci/crow/cron/weekly-audit-missing/13 Pipeline was successful
ci/crow/cron/weekly-audit-missing/14 Pipeline failed
ci/crow/cron/weekly-audit-missing/15 Pipeline was successful
ci/crow/cron/weekly-audit-missing/16 Pipeline was successful
ci/crow/cron/trial-build-registry/7 Pipeline was successful
ci/crow/cron/trial-build-registry/11 Pipeline was successful
ci/crow/cron/trial-build-registry/15 Pipeline was successful
ci/crow/cron/trial-build-registry/10 Pipeline was successful
ci/crow/cron/trial-build-registry/5 Pipeline was successful
ci/crow/cron/trial-build-registry/8 Pipeline was successful
ci/crow/cron/trial-build-registry/9 Pipeline was successful
ci/crow/cron/trial-build-registry/17 Pipeline was successful
ci/crow/cron/trial-build-registry/6 Pipeline was successful
ci/crow/cron/trial-build-registry/1 Pipeline was successful
ci/crow/cron/trial-build-registry/3 Pipeline was successful
ci/crow/cron/trial-build-registry/13 Pipeline was successful
ci/crow/cron/trial-build-registry/14 Pipeline was successful
ci/crow/cron/trial-build-registry/2 Pipeline failed
ci/crow/cron/trial-build-registry/18 Pipeline was successful
ci/crow/cron/trial-build-registry/16 Pipeline was successful
ci/crow/cron/trial-build-registry/12 Pipeline was successful
ci/crow/cron/trial-build-registry/4 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/8 Pipeline failed
ci/crow/cron/weekly-rebuild-missing/7 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/2 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/14 Pipeline failed
ci/crow/cron/weekly-rebuild-missing/9 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/3 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/10 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/13 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/11 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/4 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/12 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/1 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/16 Pipeline was successful
ci/crow/cron/weekly-rebuild-missing/15 Pipeline was successful
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
ci/crow/cron/process-updates/13 Pipeline was successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was successful
ci/crow/cron/process-updates/12 Pipeline was successful
ci/crow/cron/process-updates/6 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline was successful
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/2 Pipeline was successful
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/8 Pipeline was successful
ci/crow/cron/process-updates/9 Pipeline was successful
ci/crow/cron/process-updates/3 Pipeline was successful
`bincraft` dropped pak in favour of uvr (5.0.x, "Dependencies and their system requirements are now installed with `uvr` instead of pak during `build_binary_package()`"), so the pipelines, helper scripts and images in this repo move with it. ## Approach uvr is project-scoped in a way pak is not: `uvr add` refuses to run outside a project and always installs into `.uvr/library/`, and only `uvr sync` honours `--library`. So there is no one-line `pak::pak(...)` equivalent. `local/uvr-install.sh` encapsulates the dance — bootstrap a pinned uvr, mint a throwaway project under `TMPDIR`, `uvr add --no-install`, then `uvr sync --library <target>`. Keeping the project outside the checkout also keeps `uvr init`'s `.Rprofile` from hijacking `.libPaths()` for every other R call in the pipeline. This matches what bincraft itself does (`uvr sync --install-system-deps --library <lib>`), and bincraft requires `uvr` on `PATH`, which the bootstrap provides: every pipeline that calls `bincraft::` runs `install-bincraft.R` (and therefore the bootstrap) first. ## Changes | File | Change | | --- | --- | | `local/uvr-install.sh` | **New.** The single replacement for `pak::pak(...)`. Bootstraps uvr `v0.4.4`, resolves the R interpreter from `UVR_R_BIN`/`R_VERSION`/`PATH`, pins the manifest to that R's exact version, and syncs into `UVR_TARGET_LIB`/`R_LIBS_USER`. | | `local/install-bincraft.R` | Installs `forgejo::codefloe.com/rpkgs/bincraft@<tag>` instead of a `git::` URL; keeps the `git ls-remote` tag resolution. Exports `UVR_R_BIN`/`UVR_TARGET_LIB` from `R.home()`/`.libPaths()[1]` so the per-R-minor passes target their own R and library. | | `.crow/auto-apply-patches.yaml`, `.crow/weekly-patch-proposals.yaml`, `.crow/weekly-audit-missing.yaml`, `.crow/weekly-rebuild-missing.yaml`, `.crow/build-all-versions-install-deps.yaml` | `pak::pak(...)` → `UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh ...`. The explicit `UVR_R_BIN` matters in `build-all-versions-install-deps.yaml`, which has no `R_VERSION` in its step environment. | | `.crow/build-all-versions.yaml`, `.crow/process-updates.yaml`, `.crow/weekly-rebuild-missing.yaml` | `R_PKG_CACHE_DIR` → `UVR_CACHE_DIR` + `UVR_PACKAGES_DIR` on the same `/mnt/cache` volume, preserving the amd64-off/arm64-on split. Drops the `rm -rf .../pkgcache/_metadata/...` cleanup. | | `local/r-minor-helpers.R`, `local/build-all.R`, `local/tests/test-trim-pkgcache.R` | Removes `trim_pkgcache_metadata()`, its every-25-packages call and its tests. uvr's cache does not mint a fresh ~70 MB snapshot per `PACKAGES` change. | | `.crow/build-all-versions-install-deps.yaml` | Drops `pak::sysreqs_db_update()`; uvr resolves sysreqs from its vendored `r-system-requirements` rules via `--install-system-deps`. | | `docker/Containerfile-shiny-app` | Bootstraps uvr and drives both dependency installs through one uvr project with `UVR_LIBRARY` pointed at the image's R library. | | `docker/build-one.Dockerfile` | Ships `uvr-install.sh` at `/work/local/` so `install-bincraft.R` finds it. | | `docker/reprex/alpine.sh` | Replaces `pak::local_install_deps()` with DESCRIPTION parsing + `uvr add`. | | `local/test-package-loading.R` | Installs via the helper instead of `pak::pkg_install()`. | | `README.md` | Documents uvr for sysreq inference, archived-version installs and cache clearing. | | `renovate.json` | Tracks the `UVR_PIN` in `uvr-install.sh` via `github-releases`. | ## Behaviour notes - **`weekly-audit-missing` still takes bincraft from the default branch**, not the latest release tag, matching what the `git::` pak call did. Called out in a comment rather than silently changed. - **The uvr pin is repo-wide.** bincraft resolves `uvr` from `PATH` and pins no version of its own, so `UVR_PIN` in `uvr-install.sh` governs the whole pipeline. - **Persistent caches now also benefit bincraft**, which reads `UVR_CACHE_DIR`/`UVR_PACKAGES_DIR` from the inherited pipeline environment. - **`uvr sync` will not prune the shared library.** Pruning is disabled whenever `--library` is passed (`do_prune = prune && library_override.is_none()`), so `/mnt/cache/R-pkgs` keeps bincraft and its dependencies. The wipe-on-ABI-mismatch path is *not* similarly guarded, which is why the helper pins the manifest to the active R's exact version. - **`plans/` and `specs/` are untouched** — they are dated records of decisions made in June 2026 and describe bincraft's then-pak-based internals; rewriting them would misstate history. ## Verification `shellcheck`, all pre-commit hooks (on this commit's file range) and the `local/tests/` suite (100 assertions) pass. Not yet exercised in CI: the build-env images do not ship `uvr`, so the per-step `curl install.sh` bootstrap is untested against a real image. Worth a manual `build-all-versions-install-deps` run before merging. Reviewed-on: #147
76 lines
3.6 KiB
Docker
76 lines
3.6 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Targeted (re)build of specific package versions, executed on a remote buildx
|
|
# builder. The build's effect is the S3 upload performed by build-one.R; no
|
|
# image is kept (the justfile uses --output type=cacheonly). CACHEBUST forces
|
|
# the RUN to re-execute on every invocation.
|
|
#
|
|
# Build context is `local/` (see the `rebuild` recipe in the justfile).
|
|
ARG OS
|
|
ARG OS_VERSION
|
|
FROM reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}
|
|
|
|
ARG R_VERSION=4.5.3
|
|
ARG PACKAGE
|
|
ARG VERSIONS
|
|
ARG CACHEBUST
|
|
|
|
WORKDIR /work
|
|
COPY build-one.R /work/build-one.R
|
|
# Resolve and install the latest bincraft release dynamically (no hardcoded pin).
|
|
# uvr-install.sh lands under /work/local/ because install-bincraft.R looks for it
|
|
# there when the working directory is not a repo checkout.
|
|
COPY install-bincraft.R /work/install-bincraft.R
|
|
COPY uvr-install.sh /work/local/uvr-install.sh
|
|
# Ship the patch registry so build-one.R's `patches = "local/patches"` resolves
|
|
# (build context is `local/`, CWD is /work).
|
|
COPY patches /work/local/patches
|
|
|
|
RUN --mount=type=secret,id=b2_access,required=true \
|
|
--mount=type=secret,id=b2_secret,required=true \
|
|
--mount=type=secret,id=pgpass,required=true \
|
|
--mount=type=secret,id=github_pat,required=false \
|
|
export B2_S3_ACCESS_KEY="$(cat /run/secrets/b2_access)" && \
|
|
export B2_S3_SECRET_KEY="$(cat /run/secrets/b2_secret)" && \
|
|
export PGPASS="$(cat /run/secrets/pgpass)" && \
|
|
export GITHUB_PAT="$(cat /run/secrets/github_pat 2>/dev/null || true)" && \
|
|
export GIT_TERMINAL_PROMPT=0 && \
|
|
export OTEL_SDK_DISABLED=true && \
|
|
export OTEL_R_TRACES_EXPORTER=none && \
|
|
export OTEL_R_LOGS_EXPORTER=none && \
|
|
export OTEL_R_METRICS_EXPORTER=none && \
|
|
XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run || true); \
|
|
XVFB_ARGS=""; \
|
|
if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi; \
|
|
USE_XVFB=0; \
|
|
if [ -n "$XVFB" ] && $XVFB -a $XVFB_ARGS -- true >/dev/null 2>&1; then \
|
|
USE_XVFB=1; echo "Using virtual display via $XVFB"; \
|
|
else \
|
|
echo "No working virtual display; building without xvfb" >&2; \
|
|
fi; \
|
|
run_build() { if [ "$USE_XVFB" = 1 ]; then $XVFB -a $XVFB_ARGS -- "$@"; else "$@"; fi; }; \
|
|
ensure_bincraft() { "$1" -q -e 'source("/work/install-bincraft.R")'; }; \
|
|
PRIMARY_MINOR=$(echo "$R_VERSION" | cut -d. -f1-2); \
|
|
seen=" $PRIMARY_MINOR "; \
|
|
prc=0; failed=""; \
|
|
rm -f .r_minor_sensitive; \
|
|
echo "=== primary pass under R $R_VERSION ==="; \
|
|
ensure_bincraft /opt/R/${R_VERSION}/bin/R; \
|
|
run_build /opt/R/${R_VERSION}/bin/Rscript /work/build-one.R "${PACKAGE}" ${VERSIONS} || prc=$?; \
|
|
if [ -f .r_minor_sensitive ]; then \
|
|
for RBIN in /opt/R/*/bin/Rscript; do \
|
|
[ -x "$RBIN" ] || continue; \
|
|
RV=$(basename "$(dirname "$(dirname "$RBIN")")"); \
|
|
case "$RV" in [0-9]*) ;; *) continue ;; esac; \
|
|
RMINOR=$(echo "$RV" | cut -d. -f1-2); \
|
|
case "$seen" in *" $RMINOR "*) continue ;; esac; \
|
|
seen="$seen$RMINOR "; \
|
|
echo "=== sensitive-only pass under R $RV ==="; \
|
|
ensure_bincraft "$(dirname "$RBIN")/R"; \
|
|
run_build "$RBIN" /work/build-one.R --sensitive-only "${PACKAGE}" ${VERSIONS} || failed="$failed $RV"; \
|
|
done; \
|
|
else \
|
|
echo "Package not r-minor-sensitive; skipping per-minor passes."; \
|
|
fi; \
|
|
if [ -n "$failed" ]; then echo "WARNING: extra-minor build(s) failed (non-fatal; e.g. a version too old to compile on a newer R):$failed" >&2; fi; \
|
|
if [ "$prc" != 0 ]; then echo "primary pass under R $R_VERSION failed (exit $prc)" >&2; fi; \
|
|
exit "$prc"
|