Skip to content

Update stacked: 9 packages - #577

Merged
twitchyliquid64 merged 10 commits into
mainfrom
update-stacked-2026-08-06-1105478d
Aug 6, 2026
Merged

Update stacked: 9 packages#577
twitchyliquid64 merged 10 commits into
mainfrom
update-stacked-2026-08-06-1105478d

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update base-soup (9 packages)

Note

These packages declare replace_on_cycle in their build.ncl, so
they participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.

Warning

1 requested member did NOT ship — each needs separate follow-up.
A member is dropped when it fails to update, has its gs:// mirror
withheld by the scan gate, or is peeled to keep the shipped set a
closed dependency closure (a survivor built against a dropped member's
old version would be a broken closure).

Package Old Target Why
atuin 18.17.1 18.19.0 gs:// mirror withheld (pkgscan-critical)

Pkgscan: clean across all bundle members — diffs against prior versions surfaced no newly-introduced suspicious patterns.

Note

Build risk — 3 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.

Bundle member Dependents
mesa 2 — chromium-bin, chromium-headless-shell-bin
uv 1 — diffoscope

Summary

Package Old New Source
mesa 26.1.6 26.2.0 override:mesa:operator-pinned
cloudflared 2026.7.2 2026.7.3 github:cloudflare/cloudflared:operator-pinned
crane 0.21.8 0.21.9 github:google/go-containerregistry:operator-pinned
uv 0.12.1 0.12.2 github:astral-sh/uv:operator-pinned
grafana 12.4.3 13.1.2 github:grafana/grafana:operator-pinned
grype 0.116.0 0.116.1 github:anchore/grype:operator-pinned
pulumi 3.255.0 3.256.0 github:pulumi/pulumi:operator-pinned
vim 9.2.0901 9.2.0914 github:vim/vim:tag:operator-pinned
zola 0.22.1 0.23.1 github:getzola/zola:operator-pinned

Per-package details

mesa 26.1.6 → 26.2.0
  • SHA256: 5296b88a0f1e012e...efd4bb08cdb7c365...
  • Size: 77.8 MB → 68.5 MB
  • Source: gs://minimal-staging-archives/mesa-26.1.6.tar.xzgs://minimal-staging-archives/mesa-26.2.0.tar.xz
  • Released: unknown (non-GitHub source or tag-only fallback)
cloudflared 2026.7.2 → 2026.7.3
  • SHA256: 7c437dcf6c2b2efb...8e452b1630064f59...
  • Size: 6.8 MB
  • Source: https://github.com/cloudflare/cloudflared/archive/refs/tags/2026.7.2.tar.gzhttps://github.com/cloudflare/cloudflared/archive/refs/tags/2026.7.3.tar.gz
  • Released: 14 days ago (2026-07-23)
  • License: Apache-2.0 (source: GitHub + tarball)
crane 0.21.8 → 0.21.9
  • SHA256: 29a1b525881f89bf...6d8bce869afcc485...
  • Size: 4.7 MB
  • Source: https://github.com/google/go-containerregistry/archive/refs/tags/v0.21.8.tar.gzhttps://github.com/google/go-containerregistry/archive/refs/tags/v0.21.9.tar.gz
  • Released: 19 hours ago (2026-08-05)
  • License: Apache-2.0 (source: GitHub + tarball)
uv 0.12.1 → 0.12.2
  • SHA256: 4e87a6c0e5feddb5...62e876d5ed5494f4...
  • Size: 7.2 MB → 7.3 MB
  • Source: gs://minimal-staging-archives/uv-0.12.1.tar.gzgs://minimal-staging-archives/uv-0.12.2.tar.gz
  • Released: 21 hours ago (2026-08-05)
  • License: MIT OR Apache-2.0 (source: GitHub + tarball)
grafana 12.4.3 → 13.1.2
  • SHA256: 64707f35d54a5441...2215a38a59b573f1...
  • Size: 363.4 MB
  • Source: https://dl.grafana.com/oss/release/grafana-12.4.3.linux-amd64.tar.gzhttps://dl.grafana.com/oss/release/grafana-13.1.2.linux-amd64.tar.gz
  • Released: 2 days ago (2026-08-04)
  • License: AGPL-3.0-only (source: GitHub + tarball)
grype 0.116.0 → 0.116.1
  • SHA256: 5e8aa8cf1ae21e46...e64bd796bc93092a...
  • Size: 2.0 MB → 2.0 MB
  • Source: gs://minimal-staging-archives/anchore/grype/v0.116.0.tar.gzgs://minimal-staging-archives/anchore/grype/v0.116.1.tar.gz
  • Released: 8 days ago (2026-07-28)
  • License: Apache-2.0 (source: GitHub + tarball)
pulumi 3.255.0 → 3.256.0
  • SHA256: c0ed8c10910d73d4...43887337b91f4d61...
  • Size: 20.0 MB → 20.1 MB
  • Source: gs://minimal-staging-archives/pulumi/pulumi/v3.255.0.tar.gzgs://minimal-staging-archives/pulumi/pulumi/v3.256.0.tar.gz
  • Released: 1 days ago (2026-08-04)
  • License: Apache-2.0 (source: GitHub + tarball)
vim 9.2.0901 → 9.2.0914
  • SHA256: 97389396da7de9bb...94f44ff0d08ceb71...
  • Size: 20.0 MB → 20.1 MB
  • Source: gs://minimal-staging-archives/vim-9.2.0901.tar.gzgs://minimal-staging-archives/vim-9.2.0914.tar.gz
  • Released: 21 hours ago (2026-08-05)
  • License: Vim (source: GitHub + tarball)
zola 0.22.1 → 0.23.1
  • SHA256: 0f59479e05bce79e...331240b037bbef0a...
  • Size: 47.5 MB → 52.3 MB
  • Source: gs://minimal-staging-archives/getzola/zola/v0.22.1.tar.gzgs://minimal-staging-archives/getzola/zola/v0.23.1.tar.gz
  • Released: 1 days ago (2026-08-05)
  • License: EUPL-1.2 ⚠️ GitHub says EUPL-1.2, tarball says (EUPL-1.2 AND MIT)

Created by pkgmgr

gominimal-pkgmgr-mgr Bot and others added 10 commits August 6, 2026 16:37
…ana-cli

The 12.4.3 -> 13.1.2 bump in this bundle fails to build on BOTH arches:

    + install -m 755 bin/grafana-server /build/output/usr/bin/grafana-server
    install: cannot stat 'bin/grafana-server': No such file or directory

Upstream removed them. Verified by listing both tarballs:

    12.4.3  bin/grafana         462,138,731
            bin/grafana-server    2,557,169
            bin/grafana-cli       2,557,169
    13.1.2  bin/grafana         511,622,560     <- the only bin

The two 12.x extras are byte-identical in SIZE — the same forwarder shipped
twice — i.e. they were already shims for the `grafana server` / `grafana cli`
subcommands, long deprecated. Grafana 13 finished the job.

So this is not a packaging error, and not a bad sha: upstream changed which
binaries the artifact ships. A version check cannot see that; only a build can.

Dropped rather than re-created as local shims: nothing else in pkgs referenced
either name (grepped *.ncl/*.sh/*.toml — the only hits were grafana's own
build.sh and its outputs block, both fixed here).

## Tests

The package had NONE. Added two, because "upstream changed which binaries the
tarball ships" is exactly the class that hid here and the class that will
recur:

  - smoketest — `grafana --version`
  - subcommands_replace_the_dropped_bins — asserts `grafana server --help` and
    `grafana cli --help` both work, so "we dropped two bins" can never quietly
    become "we dropped the functionality"

Mutation-verified: pointing the second test at a nonexistent subcommand turns
the suite red (`standalone tests...Fail`), so it can fail for the reason it
exists.

Built and checked on both the fixed and mutated trees: 15/15 Pass.
@bryan-minimal

Copy link
Copy Markdown
Member

Fixed the grafana build failure in 0bcd2e5.

Not a packaging error and not a bad sha — upstream changed what the tarball ships. Listed both:

12.4.3   bin/grafana         462,138,731
         bin/grafana-server    2,557,169
         bin/grafana-cli       2,557,169
13.1.2   bin/grafana         511,622,560     <- the only bin

The two 12.x extras are byte-identical in size — the same forwarder shipped twice — i.e. they were already shims for the grafana server / grafana cli subcommands, deprecated for several majors. Grafana 13 finished the job, and our build.sh installed them unconditionally:

install: cannot stat 'bin/grafana-server': No such file or directory

Dropped rather than re-created as local shims — nothing else in pkgs referenced either name (grepped *.ncl/*.sh/*.toml; the only hits were grafana's own build.sh and outputs block, both fixed).

Also added tests, because the package had none. This is the "a version bump is not a build-input bump" shape — no version check can see that a tarball's binary set changed, only a build can. So:

  • smoketestgrafana --version
  • subcommands_replace_the_dropped_bins — asserts grafana server --help and grafana cli --help both work, so "we dropped two bins" can't quietly become "we dropped the functionality"

Mutation-verified: pointing the second test at a nonexistent subcommand turns the suite red, so it fails for the reason it exists.

Built and checked in a clean session: 15/15 Pass.

@twitchyliquid64
twitchyliquid64 added this pull request to the merge queue Aug 6, 2026
Merged via the queue into main with commit 8ebad2a Aug 6, 2026
6 of 15 checks passed
@twitchyliquid64
twitchyliquid64 deleted the update-stacked-2026-08-06-1105478d branch August 6, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants