Repository navigation
Make a build that installs yesterday's packages fail - #7
Merged
Merged
Conversation
The forum layer rebuilt on 2026-09-26 carried inithooks 2.3.6+keel1, confconsole 2.2.3+keel1 and keel 0.1.0 after 2.3.6+keel4, 2.2.3+keel2 and 0.2.1 had been published, and every step of the build succeeded. Two causes, both fixed here. The archive the chroot read was the copy a build from that morning had left in the bootstrap: fab stamps the bootstrap target, "make clean" failed on a busy deck, the stamps survived and the copy with them. And the recipe asserted a literal "+keel1", which the stale packages satisfied. bin/keel-archive-check compares the package index copied into a build tree with the index of the live archive and stops the build when they differ. The Makefile runs it in bootstrap/post, right after the copy is made, and again in root.patched/pre, which runs on every build and so catches a bootstrap this build did not make. conf.d/zz-project-packages replaces the literal. For inithooks, confconsole and keel it checks that the archive offers exactly one version, that apt's candidate is that version, that the version is served by the project archive and not by an upstream source, and that the installed package is that candidate and is configured. It then removes the build time package source, which conf.d/main used to do. Nothing names a version, so a rebuild after a publication either carries the new versions or fails. Both scripts run for real in the tests against scratch trees with dpkg, dpkg-query and apt-cache as PATH stubs: 21 tests, 100 percent of both files under kcov, and they join the measured set in tests/coverage.sh.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The forum layer rebuilt on 2026-09-26 carried inithooks 2.3.6+keel1,
confconsole 2.2.3+keel1 and keel 0.1.0 after 2.3.6+keel4, 2.2.3+keel2 and
0.2.1 had been published to the staging archive. Every step of the build
succeeded and nothing in the recipe objected.
Why it passed
The archive the chroot read was the copy a build from that morning had left
in the bootstrap. fab stamps the
bootstraptarget,make cleanfailed on abusy deck (
rmdir: failed to remove build/root.patched: Device or resource busy), the stamps survived and the copy with them, so onlyroot.patchedwas rebuilt and
apt-get install --only-upgradefound nothing newer thanwhat was already installed.
The recipe's own guard was
grep -c '+keel1$', a literal that the stalepackages satisfied exactly.
What this changes
bin/keel-archive-checkcompares the package index copied into a build treewith the index of the live archive and stops the build when they differ. The
Makefile calls it in
bootstrap/post, right after the copy is made, andagain in
root.patched/pre, which runs on every build and so catches abootstrap that this build did not make.
conf.d/zz-project-packagesreplaces the literal. For each of inithooks,confconsole and keel it asserts that
source, so the package is a project build, and
install ok installed.It then removes the build time package source, which
conf.d/mainused todo. No version is written down anywhere, so a rebuild made after a
publication either carries the newly published versions or fails.
Tests
Both scripts run for real against scratch trees, with
dpkg,dpkg-queryand
apt-cacheas PATH stubs driven by fixtures: 21 new tests, no chroot, noapt, no root. Coverage of the measured files, threshold 95:
Test plan:
tests/coverage.shlocally, 107 tests, every measured file at or abovethe threshold
shellcheck -S warningclean on both new scriptstemplate (
bootstrap/postafter the copy,root.patched/prebeforethe conf scripts)
inithooks 2.3.6+keel4, confconsole 2.2.3+keel2 and keel 0.2.1
appliance / build-and-booton the rebuilt, published layer