Some checks failed
ci/crow/manual/weekly-audit-missing/6 Pipeline was successful
ci/crow/manual/weekly-audit-missing/5 Pipeline was successful
ci/crow/manual/weekly-rebuild-missing/5 Pipeline was canceled
ci/crow/manual/weekly-rebuild-missing/6 Pipeline was canceled
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
## Problem A manual `crow pipeline create` instantiates **every** file in `.crow/`, and a declared variable default is applied even when the run never passed that variable. A gate is therefore only a gate if its default matches nothing. #155 fixed the three pipelines that had no manual gate at all. It missed that a *permissive default* leaves a pipeline just as exposed. Demonstrated the expensive way: creating a pipeline with only ``` --var weekly_audit_missing=alpine-324-amd64 ``` also started `build-all-versions` — because its gate `target_arch` defaults to `amd64`, which matches its own amd64 matrix rows — and `process-updates` across every row, because that gate defaults to `all`. The run was killed before any `Upload package indexes` step produced output and both alpine324 indices were verified unchanged, but `build-all-versions` uploads binaries and rewrites indexes, so the next one might not be caught in time. Before: | pipeline | gate | default | fired on an unrelated manual run | | --- | --- | --- | --- | | `build-all-versions` | `target_arch` | `amd64` | amd64 rows — builds and uploads | | `build-all-versions-install-deps` | `target_arch` | `amd64` | amd64 rows | | `weekly-rebuild-missing` | `weekly_rebuild_missing` | `all` | every row | | `weekly-audit-missing` | `weekly_audit_missing` | `all` | every row | | `process-updates` | `process_cran_updates` | `all` | every row | | `repair-built-stamp` | `repair_built_stamp` | `arm64` | arm64 rows | `archive-missed-packages` was the one that behaved, because its gate variable is never declared and so matches nothing. That is the property this restores everywhere. ## What this changes Each of the six gets a `none` option on its gate variable and defaults to it, so a manual run has to name its target explicitly. The reason is recorded next to the default, where someone would go to change it. `none` is used rather than dropping the default so the expression always has a defined value to compare, instead of relying on undefined-variable semantics. Cron triggers are untouched — they match on the `cron:` name, not the variable. ## Verification `crow lint .crow/` reports all ten configs valid. Auditing every pipeline that accepts a manual event: ``` archive-missed-packages.yaml: gate=task default=<none> auto-apply-patches.yaml: gate=auto_apply_patches default='false' build-all-versions-install-deps.yaml gate=target_arch default=none build-all-versions.yaml: gate=target_arch default=none process-updates.yaml: gate=process_cran_updates default=none repair-built-stamp.yaml: gate=repair_built_stamp default=none trial-build-registry.yaml: gate=trial_build_registry default='false' weekly-audit-missing.yaml: gate=weekly_audit_missing default=none weekly-patch-proposals.yaml: gate=weekly_patch_proposals default='false' weekly-rebuild-missing.yaml: gate=weekly_rebuild_missing default=none ``` Every gate now defaults to something that matches no matrix row. Reviewed-on: #158
110 lines
3.4 KiB
YAML
110 lines
3.4 KiB
YAML
### Manual repair of a slot whose PACKAGES index advertises a broken `Built`
|
|
### stamp (e.g. `Built: R 4.5.0; NA; ...`).
|
|
#
|
|
# uvr matches the stamp's platform triple plus R minor to decide binary vs
|
|
# source, so an unusable triple turns a whole slot source-only. See
|
|
# local/repair-built-stamp.R for why this patches PACKAGES.db in place instead
|
|
# of forcing a full reparse.
|
|
#
|
|
# Run with `dry_run: true` first: it reports how many entries are broken per
|
|
# slot and changes nothing. Pick the R version the slot should advertise, which
|
|
# is the R_VERSION its entry in .crow/process-updates.yaml uses.
|
|
#
|
|
# The gate variable is `repair_built_stamp`, not `target_arch`: `target_arch` is
|
|
# what build-all-versions and build-all-versions-install-deps gate on, so a
|
|
# manual run passing it would start a full rebuild alongside this repair. Every
|
|
# pipeline here gates on a variable named after itself for exactly that reason.
|
|
#
|
|
# crow pipeline create --branch main \
|
|
# --var repair_built_stamp=arm64 --var OS=alpine --var OS_VERSION=3.22 \
|
|
# --var R_VERSION=4.5.3 --var dry_run=true devxy/build-cran-binaries
|
|
variables:
|
|
# Gates this pipeline. A manual pipeline creation instantiates every file in
|
|
# .crow/, and a declared default is applied even when the run never passed
|
|
# this variable, so the default must be a value that matches no matrix row.
|
|
repair_built_stamp:
|
|
description: 'Architecture of the slot to repair, or "none" to run nothing.'
|
|
options:
|
|
- none
|
|
- amd64
|
|
- arm64
|
|
default: none
|
|
OS:
|
|
description: 'Base OS image name.'
|
|
options:
|
|
- alpine
|
|
- redhat
|
|
- ubuntu
|
|
default: alpine
|
|
OS_VERSION:
|
|
description: 'OS image tag. Must match OS (alpine: 3.22/3.23/3.24; redhat: 8/9/10; ubuntu: jammy/noble/resolute).'
|
|
options:
|
|
- '3.22'
|
|
- '3.23'
|
|
- '3.24'
|
|
- '8'
|
|
- '9'
|
|
- '10'
|
|
- 'jammy'
|
|
- 'noble'
|
|
- 'resolute'
|
|
default: '3.22'
|
|
R_VERSION:
|
|
description: 'R version whose stamp the slot should advertise.'
|
|
options:
|
|
- 4.5.3
|
|
- 4.4.3
|
|
default: 4.5.3
|
|
dry_run:
|
|
description: 'Report what would change without writing anything.'
|
|
options:
|
|
- 'true'
|
|
- 'false'
|
|
default: 'true'
|
|
|
|
when:
|
|
- event: manual
|
|
evaluate: 'repair_built_stamp == "${ARCH}"'
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
platform: linux/${ARCH}
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- ARCH: amd64
|
|
- ARCH: arm64
|
|
|
|
steps:
|
|
- name: 'Repair Built stamp'
|
|
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
|
|
pull: true
|
|
environment:
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GIT_USER: pat-s
|
|
commands:
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
|
|
- |
|
|
if [ "$dry_run" = "false" ]; then
|
|
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH" --apply
|
|
else
|
|
/opt/R/$R_VERSION/bin/Rscript local/repair-built-stamp.R "$ARCH"
|
|
fi
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 2Gi
|
|
cpu: 1000m
|
|
limits:
|
|
memory: 8Gi
|
|
cpu: 2000m
|