build-cran-binaries/local/repair-built-stamp.R
pat-s 0da29ab3f6
Some checks failed
ci/crow/manual/build-all-versions-install-deps/2 Pipeline is pending
ci/crow/manual/build-all-versions/5 Pipeline is pending
ci/crow/manual/build-all-versions/6 Pipeline is pending
ci/crow/manual/build-all-versions/7 Pipeline is pending
ci/crow/manual/build-all-versions/8 Pipeline is pending
ci/crow/manual/process-updates/2 Pipeline is pending
ci/crow/manual/process-updates/4 Pipeline is pending
ci/crow/manual/process-updates/6 Pipeline is pending
ci/crow/manual/process-updates/8 Pipeline is pending
ci/crow/manual/process-updates/10 Pipeline is pending
ci/crow/manual/process-updates/12 Pipeline is pending
ci/crow/manual/process-updates/14 Pipeline is pending
ci/crow/manual/process-updates/16 Pipeline is pending
ci/crow/manual/process-updates/18 Pipeline is pending
ci/crow/manual/repair-built-stamp/2 Pipeline is pending
ci/crow/manual/trial-build-registry/2 Pipeline is pending
ci/crow/manual/trial-build-registry/4 Pipeline is pending
ci/crow/manual/trial-build-registry/6 Pipeline is pending
ci/crow/manual/trial-build-registry/8 Pipeline is pending
ci/crow/manual/trial-build-registry/10 Pipeline is pending
ci/crow/manual/trial-build-registry/12 Pipeline is pending
ci/crow/manual/trial-build-registry/14 Pipeline is pending
ci/crow/manual/trial-build-registry/16 Pipeline is pending
ci/crow/manual/trial-build-registry/18 Pipeline is pending
ci/crow/manual/weekly-audit-missing/2 Pipeline is pending
ci/crow/manual/weekly-audit-missing/4 Pipeline is pending
ci/crow/manual/weekly-audit-missing/6 Pipeline is pending
ci/crow/manual/weekly-audit-missing/8 Pipeline is pending
ci/crow/manual/weekly-audit-missing/10 Pipeline is pending
ci/crow/manual/weekly-audit-missing/12 Pipeline is pending
ci/crow/manual/weekly-audit-missing/14 Pipeline is pending
ci/crow/manual/weekly-audit-missing/16 Pipeline is pending
ci/crow/manual/weekly-audit-missing/18 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/2 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/4 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/5 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/6 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/7 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/8 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/9 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/10 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/11 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/12 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/13 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/14 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/15 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/16 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/17 Pipeline is pending
ci/crow/manual/weekly-rebuild-missing/18 Pipeline is pending
ci/crow/manual/process-updates/9 Pipeline was successful
ci/crow/manual/trial-build-registry/1 Pipeline was successful
ci/crow/manual/trial-build-registry/3 Pipeline was successful
ci/crow/manual/trial-build-registry/5 Pipeline was successful
ci/crow/manual/process-updates/7 Pipeline was successful
ci/crow/manual/trial-build-registry/7 Pipeline was successful
ci/crow/manual/trial-build-registry/9 Pipeline was successful
ci/crow/manual/trial-build-registry/11 Pipeline was successful
ci/crow/manual/trial-build-registry/13 Pipeline was successful
ci/crow/manual/auto-apply-patches Pipeline was successful
ci/crow/manual/trial-build-registry/15 Pipeline was successful
ci/crow/manual/trial-build-registry/17 Pipeline was successful
ci/crow/manual/weekly-audit-missing/1 Pipeline was successful
ci/crow/manual/weekly-audit-missing/5 Pipeline was successful
ci/crow/manual/weekly-audit-missing/3 Pipeline was successful
ci/crow/manual/weekly-audit-missing/7 Pipeline was successful
ci/crow/manual/weekly-audit-missing/9 Pipeline was successful
ci/crow/manual/weekly-audit-missing/11 Pipeline was successful
ci/crow/manual/weekly-audit-missing/13 Pipeline was successful
ci/crow/manual/weekly-audit-missing/17 Pipeline was successful
ci/crow/manual/weekly-audit-missing/15 Pipeline was successful
ci/crow/manual/weekly-rebuild-missing/1 Pipeline was canceled
ci/crow/manual/weekly-rebuild-missing/3 Pipeline was canceled
ci/crow/manual/process-updates/3 Pipeline was canceled
ci/crow/manual/process-updates/15 Pipeline was canceled
ci/crow/manual/process-updates/11 Pipeline was canceled
ci/crow/manual/weekly-patch-proposals Pipeline was canceled
ci/crow/manual/process-updates/13 Pipeline was canceled
ci/crow/manual/process-updates/1 Pipeline was canceled
ci/crow/manual/process-updates/5 Pipeline was canceled
ci/crow/manual/process-updates/17 Pipeline was canceled
ci/crow/cron/process-updates/15 Pipeline failed
fix(index): add a slot repair for a broken Built stamp and retire alpine 3.21 (#150)
## Problem

`arm64/alpine321` and `arm64/alpine322` advertise a broken stamp:

```
arm64/alpine321 :: 22930  Built: R 4.4.0; NA; 2026-07-31 13:35:52 UTC; unix
arm64/alpine322 :: 24696  Built: R 4.5.0; NA; 2026-07-31 13:51:54 UTC; unix
```

The per-minor sub-slots (`contrib/4.4`, `4.5`, `4.6`) are affected too.
All 18 other slots are correct.

uvr matches the stamp's platform triple plus R minor to pick binary over source, so nothing matches `NA` and both slots silently serve as source-only, which is exactly the regression bincraft#85 added the stamp to prevent.
`install.packages()` is unaffected, since it reads `Built:` from each tarball's own `DESCRIPTION`.
The tarballs are fine (`arm64/alpine322/.../dress.graph_0.8.3.tar.gz` carries `aarch64-unknown-linux-musl`), and so is the R that built them (`r-4.5.0_1_aarch64.apk` ships `R_PLATFORM='aarch64-unknown-linux-musl'`).
Only the index is wrong.

bincraft#96 stops a stamp like this being written again, but it cannot repair what is already there.

## Why not just re-run the index update

`upload_package_index()` reuses the slot's remote `PACKAGES.db`, and cranlike's `update_db()` only reparses files whose md5 changed, so entries already in the database keep the stamp they were written with.

Dropping `PACKAGES.db` to force a full reparse does work, and it is what bincraft#85's rollout note suggested, but for an S3 repo cranlike reads each package's metadata from the CRAN *source* mirror on GitHub.
A 25k-entry slot is then 25k requests to raw.githubusercontent.com, with a real risk of being rate-limited part-way through and leaving the slot half-written.

Only the `Built` column is wrong, so this corrects it in place instead: patch the column in `PACKAGES.db`, put the database back, and let `upload_package_index()` re-emit `PACKAGES*` from it.
`update_db()` always rewrites the index files even when nothing was reparsed, so no tarball is re-read and nothing is fetched from GitHub.

## Change

- `local/repair-built-stamp.R` — repairs the generic slot plus every per-minor sub-slot. Dry-run by default; `--apply` writes. The replacement comes from `bincraft::built_stamp()` under the R running the script, so it is exactly what a healthy run would have written, and bincraft#96's guard makes a broken build image fail rather than write a second bad stamp.
- `.crow/repair-built-stamp.yaml` — manual pipeline, routed by `target_arch` to the matching agent group and platform image, with `dry_run` defaulting to `true`.
- `.crow/archive-missed-packages.yaml` — drop the two `alpine321` matrix entries. Alpine 3.21 is EOL: the website advertises only 3.23/3.24 and `process-updates.yaml` already dropped it, so that slot is retired rather than repaired.

## Verification

`crow lint .crow/` passes on all nine pipelines.
`air format` and `jarl check` are clean; the script parses, and the `/opt/R` minor-version derivation was checked against `4.4.3 / 4.5.3 / 4.6.0 / current` → `4.4 4.5 4.6`.
The repair itself is unrun by design — it needs B2 credentials and an arm64 agent.

## Rollout

1. Cut a bincraft release so `local/install-bincraft.R` picks up #96 (it resolves the latest `vX.Y.Z` tag, and #96 is only on `main`).
2. Run this pipeline with `target_arch=arm64`, `OS=alpine`, `OS_VERSION=3.22`, `R_VERSION=4.5.3`, `dry_run=true` and check the reported counts.
3. Re-run with `dry_run=false`.
4. Confirm: `curl -sS https://cran.devxy.io/arm64/alpine322/latest/src/contrib/PACKAGES | grep '^Built:' | sort | uniq -c`

`arm64/alpine321` is deliberately left alone.

Reviewed-on: #150
2026-08-07 09:15:04 +00:00

175 lines
5.7 KiB
R

#!/usr/bin/env Rscript
### Rewrite a broken `Built` stamp across one arch/codename slot.
###
### A slot's index can end up advertising a stamp whose platform triple is
### unusable, e.g. `Built: R 4.5.0; NA; ...`. uvr picks binary vs source by
### matching that triple plus the R minor, so no client matches it and the whole
### slot silently reverts to source-only, which makes uvr compile everything and
### fail wherever a system `-dev` library is missing.
###
### Rewriting it is not a matter of re-running the normal index update.
### `upload_package_index()` reuses the slot's remote `PACKAGES.db`, and
### cranlike's `update_db()` only reparses files whose md5 changed, so entries
### already in the database keep the stamp they were written with. Dropping
### `PACKAGES.db` to force a full reparse does work, but for an S3 repo cranlike
### reads each package's metadata from the CRAN *source* mirror on GitHub, so a
### 25k-entry slot means 25k requests to raw.githubusercontent.com and a real
### risk of being rate-limited part-way through.
###
### Only the `Built` column is wrong, so correct it in place instead: patch the
### column in `PACKAGES.db`, put the database back, and let
### `upload_package_index()` re-emit `PACKAGES*` from it. `update_db()` always
### rewrites the index files even when nothing was reparsed, so no tarball is
### re-read and nothing is fetched from GitHub.
###
### The replacement comes from `bincraft::built_stamp()` under the R running
### this script, so run it under the R version the slot should advertise (the
### `R_VERSION` its entry in `.crow/process-updates.yaml` uses). That is what a
### healthy `upload_package_index()` run would have written.
###
### Usage, inside the platform's build image:
### Rscript local/repair-built-stamp.R <arch> [--apply]
###
### Without `--apply` it reports what it would change and touches nothing.
suppressPackageStartupMessages({
library(bincraft)
})
args <- commandArgs(trailingOnly = TRUE)
arch <- args[1L]
apply_changes <- "--apply" %in% args
if (is.na(arch) || !nzchar(arch)) {
stop(
"Usage: Rscript local/repair-built-stamp.R <arch> [--apply]",
call. = FALSE
)
}
bucket <- "devxy-rpkgs-binaries"
endpoint <- "https://s3.eu-central-003.backblazeb2.com"
region <- "eu-central-003"
codename <- bincraft::set_codename(NULL)
if (is.null(codename) || is.na(codename) || !nzchar(codename)) {
stop(
"Could not detect a codename from /etc/os-release; run this in a build image.",
call. = FALSE
)
}
# built_stamp() refuses an unusable platform, so a broken build image fails here
# rather than writing a second bad stamp over the first one.
stamp <- bincraft::built_stamp()
message(sprintf("Slot: %s/%s", arch, codename))
message(sprintf("New stamp: %s", stamp))
s3fs::s3_file_system(
aws_access_key_id = Sys.getenv("B2_S3_ACCESS_KEY"),
aws_secret_access_key = Sys.getenv("B2_S3_SECRET_KEY"),
endpoint = endpoint,
region_name = region,
refresh = TRUE
)
base_dir <- file.path(bucket, arch, codename, "latest", "src", "contrib")
# A stamp is broken when its platform component is absent or literally "NA".
broken_stamp_where <- paste(
"Built IS NULL",
"OR Built LIKE '%; NA;%'",
"OR Built LIKE '%; ;%'"
)
# The generic slot plus every per-minor sub-slot, which carry the same stamp and
# are poisoned by the same run.
r_minors <- sub(
"^.*/R/([0-9]+\\.[0-9]+)\\.[0-9]+$",
"\\1",
list.dirs("/opt/R", recursive = FALSE)
)
r_minors <- unique(grep("^[0-9]+\\.[0-9]+$", r_minors, value = TRUE))
slots <- c(base_dir, file.path(base_dir, r_minors))
repair_slot <- function(slot) {
db_remote <- file.path(slot, "PACKAGES.db")
if (!s3fs::s3_file_exists(db_remote)) {
message(sprintf(" %s: no PACKAGES.db, skipping", slot))
return(invisible(NULL))
}
db_local <- tempfile(fileext = ".db")
s3fs::s3_file_download(db_remote, db_local, overwrite = TRUE)
con <- DBI::dbConnect(RSQLite::SQLite(), db_local)
on.exit(DBI::dbDisconnect(con), add = TRUE)
total <- DBI::dbGetQuery(con, "SELECT COUNT(*) AS n FROM packages")$n
broken <- DBI::dbGetQuery(
con,
sprintf("SELECT COUNT(*) AS n FROM packages WHERE %s", broken_stamp_where)
)$n
message(sprintf(" %s: %s entries, %s broken", slot, total, broken))
if (broken == 0L) {
return(invisible(NULL))
}
if (!apply_changes) {
message(" (dry run, pass --apply to rewrite)")
return(invisible(NULL))
}
DBI::dbExecute(
con,
sprintf("UPDATE packages SET Built = ? WHERE %s", broken_stamp_where),
params = list(stamp)
)
DBI::dbDisconnect(con)
on.exit()
s3fs::s3_file_upload(db_local, db_remote, overwrite = TRUE)
message(sprintf(" rewrote %s entries and uploaded PACKAGES.db", broken))
invisible(NULL)
}
invisible(lapply(slots, repair_slot))
if (!apply_changes) {
message("Dry run complete; nothing was changed.")
quit(save = "no")
}
# Re-emit PACKAGES/PACKAGES.gz/PACKAGES.rds from the corrected database. Nothing
# is reparsed, because no tarball's md5 changed.
message("Re-emitting index files from the corrected database...")
bincraft::upload_package_index(
codename = codename,
s3_endpoint = endpoint,
s3_region = region,
s3_bucket = bucket,
s3_access_key_id = Sys.getenv("B2_S3_ACCESS_KEY"),
s3_secret_access_key = Sys.getenv("B2_S3_SECRET_KEY")
)
for (minor in r_minors) {
try(
bincraft::upload_package_index(
codename = codename,
r_minor = minor,
s3_endpoint = endpoint,
s3_region = region,
s3_bucket = bucket,
s3_access_key_id = Sys.getenv("B2_S3_ACCESS_KEY"),
s3_secret_access_key = Sys.getenv("B2_S3_SECRET_KEY")
),
silent = FALSE
)
}
message("Done. Verify with:")
message(sprintf(
" curl -sS https://cran.devxy.io/%s/%s/latest/src/contrib/PACKAGES | grep '^Built:' | sort | uniq -c",
arch,
codename
))