Skip to content

chore: migrate linglong packaging to declarative buildext apt deps - #408

Merged
deepin-bot[bot] merged 1 commit into
linuxdeepin:masterfrom
add-uos:task-linglong-buildext-migration
Sep 29, 2026
Merged

deepin-bot[bot] merged 1 commit into
linuxdeepin:masterfrom
add-uos:task-linglong-buildext-migration

Conversation

@add-uos

@add-uos add-uos commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

变更说明

将 linglong 打包从手动依赖处理迁移为声明式 buildext.apt(build_depends + depends),删除 build: 中的手动 apt --download-only、install_dep、deploy_dep 与 .install 生成逻辑。

依赖分类依据(对照 base/runtime 层 packages.list 逐一核对)

  • build_depends(14):cargo/rustc(构建容器缺失,必须声明)、pandoc(构建期取 /usr/share/pandoc 数据目录)、pkg-config 探测的第三方开发库(libdjvulibre/libgxps/cairo/glib/freetype/jpeg/chardet/lcms2/openjp2/jbig2dec、libicu——vendored pdfium 直接包含 <unicode/uchar.h>)。
  • depends(4):pandoc、libdjvulibre21、libgxps2、libchardet1——base 与 runtime 均不提供、必须随包分发(libyaml-0-2/liblua5.3-0 经 apt 闭包自动解析)。
  • 不再捆绑 libqt6waylandclient6:改为经 CMAKE_PREFIX_PATH=/runtime 使用 runtime 层自带的全套 Qt/DTK 开发包,构建期与运行期同一套 Qt,从根上消除 apt Qt 与 runtime waylandclient 私有 ABI 混用导致的链接失败(原注释记录的问题)。
  • 剔除冗余:libspectre-dev、libgtest-dev 无任何探测点;libjbig2dec0 运行库由 base 提供(depends 对 base 已有包为无效 no-op)。

特殊处理

  • pandoc 数据目录:buildext 合并产物时仅收集 bin/sbin/lib,share/ 会被丢弃,故在构建期从 /usr/share/pandoc 显式复制随包分发(reader 以 --data-dir=${prefix}/share/pandoc/data 调用)。

自测

  • ll-builder build(1.14.0)完整构建成功(exit=0)
  • 产物经运行容器验证:pandoc 2.17.1.1 + 数据目录转换测试通过;libdjvulibre.so.21 / libgxps.so.2 / libchardet.so.1 / libyaml / liblua / librofd_ffi 随包就位
  • deepin-reader 与 htmltopdf 的 ldd 无缺失库

Summary by Sourcery

Migrate Linglong packaging to declarative dependency management and streamline the build artifact flow.

Enhancements:

  • Migrate Linglong dependency packaging to declarative buildext.apt build and runtime dependency declarations.
  • Use the runtime-provided Qt/DTK stack for consistent build and runtime linkage instead of bundling a separate Qt Wayland library.
  • Preserve pandoc data files in the package while simplifying dependency and artifact collection.

Chores:

  • Remove manual apt downloads, dependency installation/deployment, and generated install-file handling from the build process.

Replace manual apt download, install_dep, deploy_dep and .install
generation with buildext.apt build_depends/depends declarations.

以声明式 buildext.apt 替代手动 apt 下载、install_dep/deploy_dep 与
.install 生成逻辑,构建期与运行期统一使用 runtime 层的 Qt。

Log: 迁移 linglong 打包依赖为声明式 buildext.apt
Influence: 构建依赖与随包依赖改为 buildext 声明;Qt/DTK 改用 runtime 层
提供,不再捆绑 libqt6waylandclient6;pandoc 数据目录改为构建期显式复制;
已通过 ll-builder build 与运行容器 ldd/pandoc 自测验证。
@github-actions

Copy link
Copy Markdown
  • 检测到敏感词export变动
详情
    {
    "export": {
        "linglong.yaml": {
            "a": [
                "  export PATH=\"$PREFIX/bin:$PATH\""
            ],
            "b": [
                "  export PKG_CONFIG_PATH=\"${PREFIX}/lib/${TRIPLET}/pkgconfig:/usr/lib/${TRIPLET}/pkgconfig:/usr/share/pkgconfig${PKG_CONFIG_PATH:+:$PKG_CONFIG_PATH}\""
            ]
        }
    }
}

@sourcery-ai

sourcery-ai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Reviewer's Guide

The PR converts linglong packaging to declarative buildext.apt build and runtime dependencies, removes fragile manual apt/deploy/.install handling, uses the runtime Qt/DTK stack consistently, and explicitly preserves pandoc’s share data that buildext does not merge.

Sequence diagram for declarative build and runtime dependency assembly

sequenceDiagram
    participant Builder
    participant BuildextApt
    participant Runtime
    participant BuildScript
    participant Package

    Builder->>BuildextApt: Install build_depends
    BuildextApt-->>BuildScript: cargo, rustc, pandoc, development libraries
    Runtime->>BuildScript: Provide Qt/DTK through /runtime
    BuildScript->>BuildScript: cargo build --release -p rofd-ffi
    BuildScript->>BuildScript: cmake .. with CMAKE_PREFIX_PATH=${PREFIX}#59;/runtime
    BuildScript->>BuildScript: Copy /usr/share/pandoc to ${PREFIX}/share/pandoc
    BuildScript-->>Package: Install application and rofd artifacts
    BuildextApt->>Package: Merge depends bin/sbin/lib closure
    Package-->>Builder: Declarative package output
Loading

Flow diagram for pandoc data preservation during packaging

flowchart TD
    PandocDependency[Declare pandoc in buildext.apt.depends]
    PandocBinary[Merge pandoc bin/lib files]
    CheckData{ /usr/share/pandoc/data exists? }
    CopyData["cp -a /usr/share/pandoc ${PREFIX}/share/pandoc"]
    Fail[Exit with error]
    Package[Package pandoc with share data]

    PandocDependency --> PandocBinary
    PandocBinary --> CheckData
    CheckData -->|yes| CopyData
    CheckData -->|no| Fail
    CopyData --> Package
Loading

File-Level Changes

Change Details Files
Migrated dependency acquisition and packaging from imperative build-script logic to declarative buildext.apt metadata.
  • Declared 14 build-time packages for Rust tooling, pandoc data, and required development libraries.
  • Declared four runtime packages, relying on apt dependency closure for transitive libraries.
  • Removed manual apt downloads, dependency extraction, linker-cache handling, and generated .install entries.
linglong.yaml
Aligned Qt/DTK build and link resolution with the runtime layer instead of bundling a conflicting Qt Wayland library.
  • Removed libqt6waylandclient6 and other runtime-provided Qt/DTK packages from manual packaging.
  • Added /runtime to CMAKE_PREFIX_PATH and runtime library paths.
  • Preserved explicit pkg-config visibility for /usr, runtime/package-prefix locations.
linglong.yaml
Added explicit handling for pandoc resources that are not collected by buildext dependency merging.
  • Copied /usr/share/pandoc into the package during the build.
  • Added a layout check for the expected pandoc data directory.
  • Removed manual .install generation for pandoc and application assets.
linglong.yaml
Simplified the build flow while retaining source-built rofd installation.
  • Kept Cargo-based rofd compilation and manual installation of its versioned library, symlinks, and header.
  • Removed deploy_dep-based runtime dependency discovery and explicit bundling of libraries supplied by base/runtime layers.
  • Updated CMake linker search paths for both the package prefix and runtime libraries.
linglong.yaml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@deepin-ci-robot

Copy link
Copy Markdown

deepin pr auto review

🤖 AI 代码审查报告

总体评分: 99 分 (通过阈值: 70分)

Pass


📊 总体评价

项目 结果
审查结论 代码审查通过
评分详情 本次变更将 linglong 打包从手动依赖处理迁移为声明式 buildext.apt 依赖管理,代码结构清晰,注释详尽,无安全漏洞。新增了 pandoc 数据目录的错误检查机制,提升了构建健壮性。仅有少量 shell 变量引用未加引号的轻微问题。

🔍 详细分析

1. 语法逻辑 ✓ (25/25)

评价: 语法正确,逻辑清晰 ✓

潜在问题:
✅ 未发现明显问题

分析说明:

  • YAML 语法正确,结构完整
  • build 段内嵌 bash 脚本语法正确
  • 逻辑流程清晰:构建 rofd → 复制 pandoc 数据目录 → CMake 构建主工程
  • 新增了 /usr/share/pandoc/data 目录存在性检查,缺失时 exit 1 退出,错误处理完善
  • PKG_CONFIG_PATH 的 bash 参数展开 ${PKG_CONFIG_PATH:+:$PKG_CONFIG_PATH} 语法正确

2. 代码质量 ✓ (24/25)

评价: 代码结构清晰,注释完整 ✓

潜在问题:

  1. linglong.yaml 第 49-50 行(新增代码):mkdir -p ${PREFIX}/share 和 cp -a /usr/share/pandoc ${PREFIX}/share/pandoc 中 ${PREFIX} 变量未加双引号。虽然 Linglong 构建环境中 PREFIX 路径不含空格,但未引用变量不符合 shell 最佳实践。

建议:

  • 建议对新新增的 shell 命令中的变量引用添加双引号,如 "${PREFIX}" 以符合 shell 编程最佳实践

分析说明:

  • 注释非常详尽,对依赖分类(build_depends vs depends)有清晰的依据说明
  • 使用 ==== 分节标题(rofd 构建、pandoc 数据目录、主工程 CMake)提升可读性
  • 剔除了冗余依赖(libspectre-dev、libgtest-dev),体现了良好的代码维护意识
  • 声明式依赖管理比手动 apt 操作更易于维护

3. 代码性能 ✓ (20/20)

评价: 性能良好,资源使用合理 ✓

潜在问题:
✅ 未发现明显问题

分析说明:

  • 声明式 buildext.apt 依赖管理比手动 apt --download-only + install_dep 更高效
  • make -j$(nproc) 使用并行构建,充分利用多核
  • 移除了不必要的 ldconfig 缓存刷新操作
  • 移除了手动 .install 文件生成逻辑,减少 I/O 操作

4. 代码安全 ✓ (30/30)

评价: 存在0个安全漏洞 ✓

🔐 发现 0 个安全漏洞

安全漏洞详情:
✅ 未发现安全漏洞

漏洞对比统计:新增漏洞 0 个,减少漏洞 0 个,持平 0 个

分析说明:

  • 无硬编码密钥或敏感信息
  • 无命令注入风险(所有路径来自构建环境变量,非用户输入)
  • PKG_CONFIG_PATH 构造安全,使用参数展开正确处理空值
  • CMAKE_PREFIX_PATH="${PREFIX};/runtime" 使用分号分隔,符合 CMake 规范
  • rpath-link 标志正确包含 runtime 路径,无路径遍历风险

💡 改进建议代码示例

# 建议将未加引号的变量改为加引号形式

# 修改前:
mkdir -p ${PREFIX}/share
cp -a /usr/share/pandoc ${PREFIX}/share/pandoc

# 修改后:
mkdir -p "${PREFIX}/share"
cp -a /usr/share/pandoc "${PREFIX}/share/pandoc"

📋 审查信息

项目 内容
平台 GitHub PR
项目 linuxdeepin/deepin-reader
PR 编号 #408
PR 标题 chore: migrate linglong packaging to declarative buildext apt deps
修改文件 linglong.yaml (1 file, +57/-71)
分析模式 全量分析(GitHub PR)
OCR 状态 跳过(代码克隆失败)
SAST 状态 无数据

本报告由 AI 代码审查工具自动生成

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: add-uos, lzwind

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@add-uos

add-uos commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

/forcemerge

@deepin-bot

deepin-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

This pr force merged! (status: unstable)

@deepin-bot
deepin-bot Bot merged commit 1ad0608 into linuxdeepin:master Sep 29, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants