Some checks failed
ci/crow/manual/weekly-audit-missing/6 Pipeline was successful
ci/crow/manual/weekly-audit-missing/5 Pipeline was successful
ci/crow/manual/weekly-rebuild-missing/5 Pipeline was canceled
ci/crow/manual/weekly-rebuild-missing/6 Pipeline was canceled
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
## Problem A manual `crow pipeline create` instantiates **every** file in `.crow/`, and a declared variable default is applied even when the run never passed that variable. A gate is therefore only a gate if its default matches nothing. #155 fixed the three pipelines that had no manual gate at all. It missed that a *permissive default* leaves a pipeline just as exposed. Demonstrated the expensive way: creating a pipeline with only ``` --var weekly_audit_missing=alpine-324-amd64 ``` also started `build-all-versions` — because its gate `target_arch` defaults to `amd64`, which matches its own amd64 matrix rows — and `process-updates` across every row, because that gate defaults to `all`. The run was killed before any `Upload package indexes` step produced output and both alpine324 indices were verified unchanged, but `build-all-versions` uploads binaries and rewrites indexes, so the next one might not be caught in time. Before: | pipeline | gate | default | fired on an unrelated manual run | | --- | --- | --- | --- | | `build-all-versions` | `target_arch` | `amd64` | amd64 rows — builds and uploads | | `build-all-versions-install-deps` | `target_arch` | `amd64` | amd64 rows | | `weekly-rebuild-missing` | `weekly_rebuild_missing` | `all` | every row | | `weekly-audit-missing` | `weekly_audit_missing` | `all` | every row | | `process-updates` | `process_cran_updates` | `all` | every row | | `repair-built-stamp` | `repair_built_stamp` | `arm64` | arm64 rows | `archive-missed-packages` was the one that behaved, because its gate variable is never declared and so matches nothing. That is the property this restores everywhere. ## What this changes Each of the six gets a `none` option on its gate variable and defaults to it, so a manual run has to name its target explicitly. The reason is recorded next to the default, where someone would go to change it. `none` is used rather than dropping the default so the expression always has a defined value to compare, instead of relying on undefined-variable semantics. Cron triggers are untouched — they match on the `cron:` name, not the variable. ## Verification `crow lint .crow/` reports all ten configs valid. Auditing every pipeline that accepts a manual event: ``` archive-missed-packages.yaml: gate=task default=<none> auto-apply-patches.yaml: gate=auto_apply_patches default='false' build-all-versions-install-deps.yaml gate=target_arch default=none build-all-versions.yaml: gate=target_arch default=none process-updates.yaml: gate=process_cran_updates default=none repair-built-stamp.yaml: gate=repair_built_stamp default=none trial-build-registry.yaml: gate=trial_build_registry default='false' weekly-audit-missing.yaml: gate=weekly_audit_missing default=none weekly-patch-proposals.yaml: gate=weekly_patch_proposals default='false' weekly-rebuild-missing.yaml: gate=weekly_rebuild_missing default=none ``` Every gate now defaults to something that matches no matrix row. Reviewed-on: #158
174 lines
6.2 KiB
YAML
174 lines
6.2 KiB
YAML
# Consolidated weekly-rebuild-missing pipeline (all platforms, both arches).
|
|
# One matrix row per OS/arch replaces the former per-platform files.
|
|
# Routing is preserved 1:1:
|
|
# - cron: each existing `weekly-rebuild-missing-<os>-<arch>` cron fires only
|
|
# its matching matrix row (via the per-row `cron:` name filter).
|
|
# - manual: `weekly_rebuild_missing` dropdown, default "all" (matches the
|
|
# previous bare manual trigger that ran every os/arch); pick a
|
|
# single <os>-<arch> to run just one.
|
|
# Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64).
|
|
variables:
|
|
# Gates this pipeline. A manual pipeline creation instantiates every file in
|
|
# .crow/, and a declared default is applied even when the run never passed
|
|
# this variable, so the default must be a value that matches no matrix row.
|
|
weekly_rebuild_missing:
|
|
description: "Manual run target: a specific <os>-<arch>, 'all' for every os/arch, or 'none' to run nothing."
|
|
options:
|
|
- none
|
|
- all
|
|
- alpine-322-amd64
|
|
- alpine-322-arm64
|
|
- alpine-323-amd64
|
|
- alpine-323-arm64
|
|
- alpine-324-amd64
|
|
- alpine-324-arm64
|
|
- redhat-8-amd64
|
|
- redhat-8-arm64
|
|
- redhat-9-amd64
|
|
- redhat-9-arm64
|
|
- redhat-10-amd64
|
|
- redhat-10-arm64
|
|
- ubuntu-2204-amd64
|
|
- ubuntu-2204-arm64
|
|
- ubuntu-2404-amd64
|
|
- ubuntu-2404-arm64
|
|
- ubuntu-2604-amd64
|
|
- ubuntu-2604-arm64
|
|
default: none
|
|
|
|
when:
|
|
- event: cron
|
|
cron: weekly-rebuild-missing-${OS}-${ARCH}
|
|
- event: manual
|
|
evaluate: 'weekly_rebuild_missing == "all" || weekly_rebuild_missing == "${OS}-${ARCH}"'
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- OS: alpine-322
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.22
|
|
- OS: alpine-322
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.22
|
|
- OS: alpine-323
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.23
|
|
- OS: alpine-323
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.23
|
|
- OS: alpine-324
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-324
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: redhat-8
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:8
|
|
- OS: redhat-8
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:8
|
|
- OS: redhat-9
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:9
|
|
- OS: redhat-9
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:9
|
|
- OS: redhat-10
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: redhat:10
|
|
- OS: redhat-10
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: redhat:10
|
|
- OS: ubuntu-2204
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:jammy
|
|
- OS: ubuntu-2204
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:jammy
|
|
- OS: ubuntu-2404
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:noble
|
|
- OS: ubuntu-2404
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:noble
|
|
- OS: ubuntu-2604
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:resolute
|
|
- OS: ubuntu-2604
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:resolute
|
|
|
|
steps:
|
|
- name: 'Rebuild missing binaries'
|
|
image: reg.devxy.io/rpkgs/build-env-${IMG}
|
|
pull: true
|
|
environment:
|
|
OTEL_R_TRACES_EXPORTER: none
|
|
OTEL_R_LOGS_EXPORTER: none
|
|
OTEL_R_METRICS_EXPORTER: none
|
|
RED_HAT_DEV_PW:
|
|
from_secret: RED_HAT_DEV_PW
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
PGPASS:
|
|
from_secret: PGPASS
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GITHUB_PAT:
|
|
from_secret: GITHUB_PAT
|
|
FORGEJO_TOKEN:
|
|
from_secret: FORGEJO_TOKEN
|
|
GIT_USER: pat-s
|
|
UVR_CACHE_DIR: /mnt/cache/uvr/cache
|
|
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
|
|
R_LIBS_USER: /mnt/cache/R-pkgs
|
|
R_VERSION: ${R_VERSION}
|
|
CCACHE_DIR: /mnt/cache/ccache
|
|
PLATFORM: ${OS}
|
|
ARCH: ${ARCH}
|
|
NCPUS: 2
|
|
commands:
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
|
|
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
|
|
- XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run); XVFB_ARGS=""; if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi
|
|
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'source("local/fetch-rebuild-packages-from-issue.R")'
|
|
- $XVFB $XVFB_ARGS -- /opt/R/$R_VERSION/bin/R -q -e "sink(stdout(), type = 'message'); options(crayon.enabled = TRUE, Ncpus = $NCPUS, future.globals.onReference = NULL); pkgs <- readLines('/tmp/rebuild_pkgs.txt'); if (length(pkgs) == 0) { cat('Nothing to rebuild\n'); q('no') }; excluded <- jsonlite::fromJSON('local/excluded-packages.json')[['package']]; pkgs <- setdiff(pkgs, excluded); cat(sprintf('Rebuilding %d packages\n', length(pkgs))); n <- length(pkgs); for (i in seq_along(pkgs)) { x <- pkgs[i]; cat(sprintf('[%d/%d] %s\n', i, n, x)); tryCatch(bincraft::build_binary_package(x, tag_limit = 1L, patches = 'local/patches', s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'), metadata_db_host = 'r-binaries.devxy.io', metadata_db_name = 'build_metadata', metadata_db_table = 'single_builds', metadata_db_user = 'rpkgs', metadata_db_password = Sys.getenv('PGPASS'), metadata_db_sslmode = 'require', metadata_db_port = 15432, archive = TRUE, upload = TRUE, store_build_metadata = TRUE), error = function(e) cat(sprintf('ERROR building %s - %s\n', x, conditionMessage(e)))) }" 2>&1
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 5Gi
|
|
cpu: 3000m
|
|
limits:
|
|
memory: 18Gi
|
|
cpu: 3000m
|