A manual pipeline creation instantiates every file in .crow/, and a declared variable default is applied even when the run never passed that variable. So a gate like target_arch, defaulting to amd64, matched its own amd64 matrix rows on any manual run of any pipeline. Triggering a weekly-audit-missing run for one slot started build-all-versions (including its Upload package indexes step) and process-updates across every row. #155 fixed the three pipelines that had no gate at all; these six had a gate whose default was permissive, which left them just as exposed. - add a 'none' option to each gate variable and default to it, so a manual run must name its target explicitly - record why the default must match nothing, next to the default itself Cron triggers are unaffected: they match on the cron name, not the variable.
110 lines
3.4 KiB
YAML
110 lines
3.4 KiB
YAML
### Manual repair of a slot whose PACKAGES index advertises a broken `Built`
|
|
### stamp (e.g. `Built: R 4.5.0; NA; ...`).
|
|
#
|
|
# uvr matches the stamp's platform triple plus R minor to decide binary vs
|
|
# source, so an unusable triple turns a whole slot source-only. See
|
|
# local/repair-built-stamp.R for why this patches PACKAGES.db in place instead
|
|
# of forcing a full reparse.
|
|
#
|
|
# Run with `dry_run: true` first: it reports how many entries are broken per
|
|
# slot and changes nothing. Pick the R version the slot should advertise, which
|
|
# is the R_VERSION its entry in .crow/process-updates.yaml uses.
|
|
#
|
|
# The gate variable is `repair_built_stamp`, not `target_arch`: `target_arch` is
|
|
# what build-all-versions and build-all-versions-install-deps gate on, so a
|
|
# manual run passing it would start a full rebuild alongside this repair. Every
|
|
# pipeline here gates on a variable named after itself for exactly that reason.
|
|
#
|
|
# crow pipeline create --branch main \
|
|
# --var repair_built_stamp=arm64 --var OS=alpine --var OS_VERSION=3.22 \
|
|
# --var R_VERSION=4.5.3 --var dry_run=true devxy/build-cran-binaries
|
|
variables:
|
|
# Gates this pipeline. A manual pipeline creation instantiates every file in
|
|
# .crow/, and a declared default is applied even when the run never passed
|
|
# this variable, so the default must be a value that matches no matrix row.
|
|
repair_built_stamp:
|
|
description: 'Architecture of the slot to repair, or "none" to run nothing.'
|
|
options:
|
|
- none
|
|
- amd64
|
|
- arm64
|
|
default: none
|
|
OS:
|
|
description: 'Base OS image name.'
|
|
options:
|
|
- alpine
|
|
- redhat
|
|
- ubuntu
|
|
default: alpine
|
|
OS_VERSION:
|
|
description: 'OS image tag. Must match OS (alpine: 3.22/3.23/3.24; redhat: 8/9/10; ubuntu: jammy/noble/resolute).'
|
|
options:
|
|
- '3.22'
|
|
- '3.23'
|
|
- '3.24'
|
|
- '8'
|
|
- '9'
|
|
- '10'
|
|
- 'jammy'
|
|
- 'noble'
|
|
- 'resolute'
|
|
default: '3.22'
|
|
R_VERSION:
|
|
description: 'R version whose stamp the slot should advertise.'
|
|
options:
|
|
- 4.5.3
|
|
- 4.4.3
|
|
default: 4.5.3
|
|
dry_run:
|
|
description: 'Report what would change without writing anything.'
|
|
options:
|
|
- 'true'
|
|
- 'false'
|
|
default: 'true'
|
|
|
|
when:
|
|
- event: manual
|
|
evaluate: 'repair_built_stamp == "${ARCH}"'
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
platform: linux/${ARCH}
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- ARCH: amd64
|
|
- ARCH: arm64
|
|
|
|
steps:
|
|
- name: 'Repair Built stamp'
|
|
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
|
|
pull: true
|
|
environment:
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GIT_USER: pat-s
|
|
commands:
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
|
|
- |
|
|
if [ "$dry_run" = "false" ]; then
|
|
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH" --apply
|
|
else
|
|
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH"
|
|
fi
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 2Gi
|
|
cpu: 1000m
|
|
limits:
|
|
memory: 8Gi
|
|
cpu: 2000m
|