build-cran-binaries/local/uvr-install.sh
pat-s 6372f0f928 fix(ci): refresh the apt index before uvr installs system dependencies (#161)
Unblocks the ubuntu 26.04 builds without waiting for an image rebuild.

## What broke

```
i Installing R package dependencies
! Error in installing dependencies for package huge with tag 2.0.1:
  uvr sync --install-system-deps --library /mnt/cache/R-pkgs-4.4 failed (exit 1)

 ! WARN  Missing system dependencies for 1 package(s)
  igraph needs: libglpk-dev
> Running: apt-get install -y libglpk-dev
E: Unable to locate package libglpk-dev
```

Neither the package name nor the sysreq mapping is wrong. `libglpk-dev` is `5.0-2build1` in `universe`, which `ubuntu:resolute` enables by default. What is missing is the apt index: uvr v0.4.5 runs `apt-get install` with no `apt-get update` before it, and every ubuntu build image ends its apt layers with `rm -rf /var/lib/apt/lists/*`, so the shipped image has no index at all.

Not specific to 26.04 — jammy and noble fail identically for any sysreq the image's preinstall line doesn't already cover. 26.04 surfaced it first, through `igraph` and everything depending on it (`huge` was the first to fail).

## Fix

`apt-get update` before the sync in `local/uvr-install.sh`.

That one site covers every pipeline: `build-all-versions`, `build-all-versions-install-deps`, `weekly-rebuild-missing`, `weekly-audit-missing`, `trial-build-registry`, `auto-apply-patches` and `weekly-patch-proposals` all reach it, either directly or through `install-bincraft.R`. The index it populates persists for the rest of the step, so the bincraft-driven `uvr sync` calls that follow are covered too.

Guarded on `apt-get` and non-fatal: `apk add` fetches its index implicitly and dnf refreshes expired metadata on its own, so alpine and redhat are unaffected and skip it.

## Why here as well as in the image

The real fix is upstream `e491b2e`, which refreshes the index before the auto-install. It landed one day after v0.4.5 was tagged, so no release carries it ([nbafrank/uvr#250](https://github.com/nbafrank/uvr/issues/250)); [build-env-images#23](https://codefloe.com/rpkgs/build-env-images/pulls/23) pins the ubuntu image to a commit that has it.

That only reaches CI after an image rebuild is triggered. This change takes effect on the next pipeline run. It also stays useful afterwards: a baked index goes stale within weeks, and a stale index turns the same install into a 404 on the `.deb`.

## Verified

In `ubuntu:resolute`, with the image state reproduced exactly (R installed, then `rm -rf /var/lib/apt/lists/*` to empty the index again):

| Check | Result |
|---|---|
| `apt-get install -y libglpk-dev`, empty index | `E: Unable to locate package libglpk-dev` — the reported failure, reproduced |
| Same container after `apt-get update` | `Candidate: 5.0-2build1`, `Components: main universe restricted multiverse` |
| `igraph` + `UVR_INSTALL_SYSREQS=1 uvr sync`, empty index, uvr with the refresh | `Setting up libglpk-dev:amd64 (5.0-2build1)`, `System dependencies installed.`, `Installed 11 package(s)` |
| `sh -n` and `shellcheck local/uvr-install.sh` | pass |

## Reverting

Delete the guarded block. It is marked TEMPORARY with the upstream reference, and can go once the images ship a uvr above v0.4.5.

Reviewed-on: #161
2026-08-10 06:30:25 +00:00

109 lines
4.6 KiB
Shell
Executable file

#!/bin/sh
# Install R packages into the CI library with uvr (https://github.com/nbafrank/uvr).
#
# Usage:
# local/uvr-install.sh httr2 jsonlite
# local/uvr-install.sh forgejo::codefloe.com/rpkgs/bincraft@v4.4.3
#
# Replaces `pak::pak(...)`. uvr is project-scoped: `uvr add` refuses to run
# outside a project and always writes to `.uvr/library/`, and only
# `uvr sync --library` can target an existing library. The project is therefore
# minted in a scratch directory under TMPDIR and thrown away afterwards; that
# also keeps `uvr init`'s `.Rprofile` out of the repo checkout, where it would
# hijack `.libPaths()` for every other R call in the pipeline.
#
# Pruning is a no-op here: uvr disables it whenever `--library` is passed,
# precisely because such a target may be shared (`/mnt/cache/R-pkgs` holds
# bincraft and its dependencies alongside whatever this script installs).
#
# System dependencies come from uvr's vendored r-system-requirements rules, so
# `pak::sysreqs_db_update()` and `PKG_SYSREQS_PLATFORM` are no longer needed.
#
# Environment:
# UVR_R_BIN R interpreter to install for; set by install-bincraft.R so
# the per-R-minor passes target their own R, not the primary
# R_VERSION fallback interpreter selector (/opt/R/<version>/bin/R)
# UVR_TARGET_LIB target library; defaults to R_LIBS_USER, then to the
# active R's .libPaths()[1] (which is where pak wrote)
# UVR_INSTALL_DIR where the uvr binary lands (default /usr/local/bin)
set -eu
# renovate: datasource=github-releases depName=nbafrank/uvr
UVR_PIN="v0.4.5"
if [ "$#" -eq 0 ]; then
echo "usage: $0 <pkg-spec>..." >&2
exit 2
fi
# The build images keep R under /opt/R/<version> and off PATH. uvr resolves the
# interpreter via PATH and never downloads one unless `uvr r install` is run, so
# put the requested R first.
r_bin="${UVR_R_BIN:-}"
if [ -z "$r_bin" ] && [ -n "${R_VERSION:-}" ] && [ -x "/opt/R/${R_VERSION}/bin/R" ]; then
r_bin="/opt/R/${R_VERSION}/bin/R"
fi
if [ -n "$r_bin" ]; then
PATH="$(dirname "$r_bin"):$PATH"
export PATH
else
r_bin="$(command -v R)"
fi
target_lib="${UVR_TARGET_LIB:-${R_LIBS_USER:-}}"
if [ -z "$target_lib" ]; then
target_lib="$("$r_bin" --no-echo --no-save -e 'cat(.libPaths()[1])')"
fi
if [ -z "$target_lib" ]; then
echo "error: could not determine a target library; set UVR_TARGET_LIB" >&2
exit 2
fi
mkdir -p "$target_lib"
# Pin the manifest to the active R so the lockfile's R stays in step with the
# library's R sentinel. Without that, uvr can decide the library is ABI-stale
# and wipe it -- and this target is shared with bincraft. uvr only discovers R
# via PATH/R_HOME (it does not scan /opt/R), so the R put on PATH above is the
# only candidate this constraint can resolve to.
# shellcheck disable=SC2016 # $major/$minor are R expressions, not shell vars
r_full="$("$r_bin" --no-echo --no-save -e 'cat(paste(R.version$major, R.version$minor, sep = "."))')"
install_dir="${UVR_INSTALL_DIR:-/usr/local/bin}"
uvr_bin="${install_dir}/uvr"
if [ ! -x "$uvr_bin" ]; then
echo "Bootstrapping uvr ${UVR_PIN} into ${install_dir}"
UVR_INSTALL_DIR="$install_dir" UVR_VERSION="$UVR_PIN" \
sh -c 'curl -fsSL https://raw.githubusercontent.com/nbafrank/uvr/main/install.sh | sh'
fi
project_dir="${TMPDIR:-/tmp}/uvr-ci-$$"
rm -rf "$project_dir"
mkdir -p "$project_dir"
trap 'rm -rf "$project_dir"' EXIT
cd "$project_dir"
"$uvr_bin" init --here --r-version "$r_full"
# --no-install: resolve and lock only. The install happens in the sync below,
# which is the only command that honours --library.
"$uvr_bin" add --no-install "$@"
# TEMPORARY (drop once the images ship a uvr above v0.4.5): the sync below runs
# `apt-get install` for every resolved system dependency without refreshing the
# index first, and the ubuntu build images end their apt layers with
# `rm -rf /var/lib/apt/lists/*`. With no index apt cannot resolve a package that
# exists and is enabled, so `igraph needs: libglpk-dev` fails the whole build
# with `E: Unable to locate package libglpk-dev` on ubuntu 26.04.
#
# Fixed upstream in `e491b2e`, tagged one day after v0.4.5 (nbafrank/uvr#250),
# and the images pick it up via build-env-images#23 — but only after an image
# rebuild is triggered, which is why this runs here too.
#
# apt only: `apk add` fetches its index implicitly and dnf refreshes expired
# metadata on its own. Non-fatal, since a refresh failure still leaves whatever
# index is already there, and the install's own error is the more actionable one.
if command -v apt-get >/dev/null 2>&1; then
apt-get update -qq || echo "warning: apt-get update failed; continuing" >&2
fi
"$uvr_bin" sync --library "$target_lib" --install-system-deps