On Sat, Sep 19, 2026 at 12:56 AM Reginald Beardsley via openindiana-discuss <[email protected]> wrote: > > The significant issue is that such a trivially identifiable fault should make > it to publication in an OI repository. That should not happen. > My concern is preventing such things from happening by automating > verification the packages link. Back in the day one job required that my > install packages worked flawlessly. They always did. This is not hard work > and I am willing to do it, though I need to get on the oi-dev list again to > discuss that.
So the problem is not that broken new packages are published, but that (due to large parts of the FOSS world not taking backwards compatibility seriously) an update breaks an existing package. It's mostly manageable to do that within a single repository; it gets much harder if you're attempting to support any 3rd-party packages. > The fix is simple. After doing a fresh install from a release candidate, a > script scans all the executables with ldd(1) and rejects any which have link > failures. A very modest Bourne and awk script. It's both more complicated and simpler than that. You need `ldd -urv` to verify all the symbols. And there's a whole set of things that are plugins or accessed via dlopen that aren't caught by that process. But you don't need to scan the whole system, only those packages that list the new package as a dependency (assuming the package dependency information is accurate). The simplest way, and the brute force way, is to simply force a rebuild of all consumers. In Tribblix I have a slightly more sophisticated way. For any shared library I build, I check 2 things against the previous version - first, that the SONAME hasn't changed (if it has, then that's an obvious link failure, but can be addressed in some limited cases by shipping both versions of the library); then with nm I check the list of symbols and see if any symbols have been removed - if so, then I might need to rebuild, but only if something that depends on that library actually uses the missing symbol, so you have to check that. In the end you get a list of packages that need to be rebuilt (in any non-trivial case these tend to get batched up on a release boundary). > I am simply saying that for OI to survive it must do better than it is doing. To be honest, these problems afflict the BSDs and many Linux distributions too, although with much larger user populations they tend to get caught much more quickly. -- -Peter Tribble https://www.petertribble.co.uk/ - https://ptribble.blogspot.com/ _______________________________________________ openindiana-discuss mailing list [email protected] https://openindiana.org/mailman/listinfo/openindiana-discuss
