Skip to content

Record the commit a package was built from, and document the build caches - #3

Merged
Jertlok merged 2 commits into
mainfrom
build/provenance-and-cache-docs
Sep 16, 2026
Merged

Jertlok merged 2 commits into
mainfrom
build/provenance-and-cache-docs

Conversation

@Jertlok

@Jertlok Jertlok commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Two things around making builds fast and their output trustworthy.

Every apk pmbootstrap has ever built says commit = -dirty. abuild takes
the commit and SOURCE_DATE_EPOCH from git in $startdir, which here is the
copy of the aport inside the chroot; the .git link put there for this makes
pmaports look like it was moved to the build directory, and a pmaports git
worktree (what the porthole workspace uses) breaks it a second way. So the
apk does not say what it was built from, and its date is the time of the copy,
which makes the build non-reproducible. pmbootstrap now runs abuild's own
three git commands in the aport's checkout and passes the answers in.
Verified: hello-world built twice is byte-identical as an apk, and names the
commit that last touched main/hello-world.

Docs. docs/build_caches.md is new: which cache directory holds what,
which chroot's cache a crossdirect / QEMU-only / cross-native build writes to
(they are not all the target's), how to point two work directories at one
cache -- measured: 268 of 274 compiles served across work directories, 2m17s
against 5m00s cold -- and what CI should restore, with the two things that
silently make a restored cache useless: the chroot's uid 12345 owning it, and
a 5G per-arch ccache against a 10G cache budget. docs/cross_compiling.md
gets what crossdirect 5.3.1-r6 (porthole-dev pmaports, separate PR) now links
natively and what still has to go through QEMU.

Checks: pytest (the whole suite, test_bootimg needs mount privileges this
container does not have), ruff 0.15.22 check and format, mypy, codespell,
vermin, shellcheck, shfmt and markdownlint all pass.

@Jertlok
Jertlok force-pushed the build/provenance-and-cache-docs branch 2 times, most recently from 7da4a5b to 39a63aa Compare September 16, 2026 06:26
abuild puts the last commit that touched an aport in the apk's .PKGINFO, and
uses that commit's date as SOURCE_DATE_EPOCH so a rebuild is reproducible. It
runs git in $startdir, which under pmbootstrap is the copy of the aport in the
chroot, and link_to_git_dir() points that copy's .git at pmaports so it can:
but then the APKBUILD is not the one git knows at that path ("main/foo/APKBUILD"
against "APKBUILD"), so git_last_commit() finds nothing, git_dirty() sees a tree
full of changes, and the aport being a git worktree -- which pmaports is in the
porthole workspace -- breaks it a second way, since the .git file it links to
names a path that does not exist in the chroot.

Every package pmbootstrap has ever built therefore says

	commit = -dirty

and falls back to the mtime of the copied APKBUILD, i.e. the time of the copy,
as its date: the build is not reproducible and the apk does not say what it was
built from.

Ask the aport's own checkout instead, with the same three git commands abuild
would run, and pass ABUILD_LAST_COMMIT and SOURCE_DATE_EPOCH in the build
environment. A dirty aport keeps abuild's meaning -- "<commit>-dirty" and no
date from git -- and an aport outside a git checkout is left to abuild.

Verified: hello-world built twice in a row is byte-identical as an apk, and
its .PKGINFO names the commit that last touched main/hello-world. Before, the
two apks differed and both said "-dirty".

Assisted-by: Claude
Signed-off-by: Giuseppe Maggio <jertlok@proton.me>
Two things were undocumented. crossdirect 5.3.1-r6 (porthole-dev pmaports)
runs GCC's link steps natively, including lto-wrapper and lto1, and leaves
qemu only what has to answer for the target's GCC; cross_compiling.md still
said that everything but the compiler goes through qemu.

And nothing described the caches at all: which directory holds what, that a
crossdirect build and a QEMU-only build of the same package write to the same
cache but cannot share entries, how to point two work directories at one
cache (measured: 268 of 274 compiles served across work directories), and
what CI has to restore, with the two things that silently make a restored
cache useless -- the chroot's uid 12345 owning it, and a 5G per-arch limit
against a 10G cache budget.

Assisted-by: Claude
Signed-off-by: Giuseppe Maggio <jertlok@proton.me>
@Jertlok
Jertlok force-pushed the build/provenance-and-cache-docs branch from 39a63aa to 86b311e Compare September 16, 2026 06:37
@Jertlok
Jertlok merged commit 300fc4c into main Sep 16, 2026
4 checks passed
@Jertlok
Jertlok deleted the build/provenance-and-cache-docs branch September 16, 2026 07:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant