rdmbair15m5-changelog-20260916-1318-updateroo-intel-source-build-guard
rdmbair15m5-changelog-20260916-1318-updateroo-intel-source-build-guard
Implemented safety guard against unattended multi-hour source builds on Intel hosts (TASK-20260901-09) in updateRoo, added compile duration estimation, CLI flags, keychain-aware release packaging, and verified 332/332 tests passing.
1. Scope & Hosts Touched
- Hosts:
rdmbair15m5(local agent),rdmsm4x(canonical repository root and issues authority). - Repositories Touched:
rdmsm4x:~/dev/apps/updateRoo(commit38601da)rdmsm4x:~/dev/issues(commit67de4d8)
- Ticket Addressed & Resolved:
TASK-20260901-09: updateRoo: guard against unattended multi-hour source builds on Intel hosts.
2. Changes Implemented & Verifications
A. updateRoo Intel Unattended Safety Guard & Time Estimators
- Problem: On Intel Macs (
x86_64, Tier 3 in Homebrew), packages that have lost bottles automatically fall back to source compilation with no warning. Unattended runs (such asdev_updateor updateRoo automated passes) could hang for hours compiling toolchains (e.g.openssl@3dragging 28 dependents, orllvm/gcc/qt). - Remediation:
UpdateOptionsModel: Addedpublic var allowIntelSourceBuilds: Bool(defaulting tofalse) to ensure unattended runs fail-safe by default.- Compile Duration Heuristics
(
HomebrewIntelBottleAudit): AddedestimatedCompileDuration(for:dependentCount:)classifying packages into duration tiers:- Heavy toolchains (
llvm,gcc,qt,rust,webkit,boost,clang):2 to 6+ hours - Runtime libraries (
openssl,python,node,ruby,ffmpeg,imagemagick,icu4c,glib):15 to 45 minutes - CLI tools / utilities:
2 to 15 minutes - High cascade warnings when dependents >= 10.
- Updated
diagnostics(for:)to include estimated compile duration.
- Heavy toolchains (
HomebrewScanner.applyUpdatesDeferral Logic:- Audits unbottled packages on native Intel hosts via
HomebrewIntelBottleAudit. - When
!options.allowIntelSourceBuilds: filters out source-only packages frombrew upgradeargs, logs explicit deferral notices with duration estimates, and safely upgrades only bottled packages. - If all requested formulae require source compilation, skips the build step cleanly and outputs a safety deferral notice.
- When
options.allowIntelSourceBuilds == true: proceeds with source compilation under an extended 6-hour timeout (21600s).
- Audits unbottled packages on native Intel hosts via
- CLI Support (
updateroo upgrade): Added--allow-source-builds/--allow-intel-source-buildsoptions toCLIMain.swift. - Keychain-Aware Signing (
build.sh): Updatedbuild.shto explicitly pass--keychain ~/Library/Keychains/fleet-signing.keychain-dbwhen present, preventingerrSecInternalComponentin non-interactive SSH sessions.
B. Empirical Verification Evidence
- Unit & Integration Tests: Executed
swift testonrdmsm4x-> exit code 0; 332 tests in 33 suites passed in 100.05s with 0 failures:HomebrewIntelBottleAuditTests: 12/12 passed in 0.002s (includingtestEstimatedCompileDurationandtestDiagnosticsIncludeEstimatedDuration).HomebrewScannerTests: 5/5 passed in 3.17s (includingtestUpdateOptionsDefaultDisallowsIntelSourceBuildsandtestUpdateOptionsAllowIntelSourceBuildsOverride).
- Universal2 Packaging & Code Signing:
swift build -c release --arch arm64 --arch x86_64-> exit code 0.lipo -archsverified Universal2 (x86_64 arm64) for:updateRoo.app/Contents/MacOS/updateRoodist/updateroodist/updateRoobar
- Strict codesigning pass
(
codesign --verify --deep --strict) -> exit code 0,TeamIdentifier=ZU2882L4HT.
C. Issue Tracking & Fleet State
- Resolved
TASK-20260901-09onrdmsm4x. - Synchronized
issuesrepository tofleet(git.ecs0.net:git/dev/issues.git) andbackup(github.com/richhdoty/rdmsm4x-dev-issues.git). - Reindexed tickets -> 1,027 tickets indexed in
index.sqliteand HTML dashboards regenerated.
3. Outstanding Owner Actions
- None.