Update stacked: 9 packages - #577
Conversation
…ana-cli
The 12.4.3 -> 13.1.2 bump in this bundle fails to build on BOTH arches:
+ install -m 755 bin/grafana-server /build/output/usr/bin/grafana-server
install: cannot stat 'bin/grafana-server': No such file or directory
Upstream removed them. Verified by listing both tarballs:
12.4.3 bin/grafana 462,138,731
bin/grafana-server 2,557,169
bin/grafana-cli 2,557,169
13.1.2 bin/grafana 511,622,560 <- the only bin
The two 12.x extras are byte-identical in SIZE — the same forwarder shipped
twice — i.e. they were already shims for the `grafana server` / `grafana cli`
subcommands, long deprecated. Grafana 13 finished the job.
So this is not a packaging error, and not a bad sha: upstream changed which
binaries the artifact ships. A version check cannot see that; only a build can.
Dropped rather than re-created as local shims: nothing else in pkgs referenced
either name (grepped *.ncl/*.sh/*.toml — the only hits were grafana's own
build.sh and its outputs block, both fixed here).
## Tests
The package had NONE. Added two, because "upstream changed which binaries the
tarball ships" is exactly the class that hid here and the class that will
recur:
- smoketest — `grafana --version`
- subcommands_replace_the_dropped_bins — asserts `grafana server --help` and
`grafana cli --help` both work, so "we dropped two bins" can never quietly
become "we dropped the functionality"
Mutation-verified: pointing the second test at a nonexistent subcommand turns
the suite red (`standalone tests...Fail`), so it can fail for the reason it
exists.
Built and checked on both the fixed and mutated trees: 15/15 Pass.
|
Fixed the grafana build failure in Not a packaging error and not a bad sha — upstream changed what the tarball ships. Listed both: The two 12.x extras are byte-identical in size — the same forwarder shipped twice — i.e. they were already shims for the Dropped rather than re-created as local shims — nothing else in pkgs referenced either name (grepped Also added tests, because the package had none. This is the "a version bump is not a build-input bump" shape — no version check can see that a tarball's binary set changed, only a build can. So:
Mutation-verified: pointing the second test at a nonexistent subcommand turns the suite red, so it fails for the reason it exists. Built and checked in a clean session: 15/15 Pass. |
Update base-soup (9 packages)
Note
These packages declare
replace_on_cyclein their build.ncl, sothey participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.
Warning
1 requested member did NOT ship — each needs separate follow-up.
A member is dropped when it fails to update, has its gs:// mirror
withheld by the scan gate, or is peeled to keep the shipped set a
closed dependency closure (a survivor built against a dropped member's
old version would be a broken closure).
atuin18.17.118.19.0Note
Build risk — 3 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.
mesachromium-bin,chromium-headless-shell-binuvdiffoscopeSummary
26.1.626.2.0override:mesa:operator-pinned2026.7.22026.7.3github:cloudflare/cloudflared:operator-pinned0.21.80.21.9github:google/go-containerregistry:operator-pinned0.12.10.12.2github:astral-sh/uv:operator-pinned12.4.313.1.2github:grafana/grafana:operator-pinned0.116.00.116.1github:anchore/grype:operator-pinned3.255.03.256.0github:pulumi/pulumi:operator-pinned9.2.09019.2.0914github:vim/vim:tag:operator-pinned0.22.10.23.1github:getzola/zola:operator-pinnedPer-package details
mesa 26.1.6 → 26.2.05296b88a0f1e012e...→efd4bb08cdb7c365...gs://minimal-staging-archives/mesa-26.1.6.tar.xz→gs://minimal-staging-archives/mesa-26.2.0.tar.xzcloudflared 2026.7.2 → 2026.7.37c437dcf6c2b2efb...→8e452b1630064f59...https://github.com/cloudflare/cloudflared/archive/refs/tags/2026.7.2.tar.gz→https://github.com/cloudflare/cloudflared/archive/refs/tags/2026.7.3.tar.gzApache-2.0(source: GitHub + tarball)crane 0.21.8 → 0.21.929a1b525881f89bf...→6d8bce869afcc485...https://github.com/google/go-containerregistry/archive/refs/tags/v0.21.8.tar.gz→https://github.com/google/go-containerregistry/archive/refs/tags/v0.21.9.tar.gzApache-2.0(source: GitHub + tarball)uv 0.12.1 → 0.12.24e87a6c0e5feddb5...→62e876d5ed5494f4...gs://minimal-staging-archives/uv-0.12.1.tar.gz→gs://minimal-staging-archives/uv-0.12.2.tar.gzMIT OR Apache-2.0(source: GitHub + tarball)grafana 12.4.3 → 13.1.264707f35d54a5441...→2215a38a59b573f1...https://dl.grafana.com/oss/release/grafana-12.4.3.linux-amd64.tar.gz→https://dl.grafana.com/oss/release/grafana-13.1.2.linux-amd64.tar.gzAGPL-3.0-only(source: GitHub + tarball)grype 0.116.0 → 0.116.15e8aa8cf1ae21e46...→e64bd796bc93092a...gs://minimal-staging-archives/anchore/grype/v0.116.0.tar.gz→gs://minimal-staging-archives/anchore/grype/v0.116.1.tar.gzApache-2.0(source: GitHub + tarball)pulumi 3.255.0 → 3.256.0c0ed8c10910d73d4...→43887337b91f4d61...gs://minimal-staging-archives/pulumi/pulumi/v3.255.0.tar.gz→gs://minimal-staging-archives/pulumi/pulumi/v3.256.0.tar.gzApache-2.0(source: GitHub + tarball)vim 9.2.0901 → 9.2.091497389396da7de9bb...→94f44ff0d08ceb71...gs://minimal-staging-archives/vim-9.2.0901.tar.gz→gs://minimal-staging-archives/vim-9.2.0914.tar.gzVim(source: GitHub + tarball)zola 0.22.1 → 0.23.10f59479e05bce79e...→331240b037bbef0a...gs://minimal-staging-archives/getzola/zola/v0.22.1.tar.gz→gs://minimal-staging-archives/getzola/zola/v0.23.1.tar.gzEUPL-1.2EUPL-1.2, tarball says(EUPL-1.2 AND MIT)Created by pkgmgr