diff --git a/.github/workflows/build-linux-buildenv.yaml b/.github/workflows/build-linux-buildenv.yaml index 79ef441d11..1db920990a 100644 --- a/.github/workflows/build-linux-buildenv.yaml +++ b/.github/workflows/build-linux-buildenv.yaml @@ -24,7 +24,7 @@ jobs: run: | set -eux release=$(sed -nE -e '/FROM/s,.*:(.*),\1,gp' Dockerfile) - freeze_date=$(sed -nE '/nd_freeze/s,.* (20[0-9]*).*,\1,gp' Dockerfile) + freeze_date=$(sed -nE 's,^ARG DEBIAN_SNAPSHOT=(20[0-9]{6}).*,\1,p' Dockerfile) commit=$(git rev-parse --short=4 HEAD) docker build \ -t "datalad/buildenv-git-annex:latest" \ diff --git a/.github/workflows/tools/containers/buildenv-git-annex/Dockerfile b/.github/workflows/tools/containers/buildenv-git-annex/Dockerfile index 455c0ca48c..5ce5628d56 100644 --- a/.github/workflows/tools/containers/buildenv-git-annex/Dockerfile +++ b/.github/workflows/tools/containers/buildenv-git-annex/Dockerfile @@ -8,22 +8,33 @@ RUN echo 'Acquire::http::Dl-Limit "200";' >| /etc/apt/apt.conf.d/20snapshots \ && echo 'Acquire::https::Dl-Limit "200";' >> /etc/apt/apt.conf.d/20snapshots \ && echo 'Acquire::Retries "10";' >> /etc/apt/apt.conf.d/20snapshots -# Notes: -# - in APT for NeuroDebian we have #deb-src for debian-devel, so we need to change -# that too. -# - APT specification switched away from .list to .sources format in bookworm. -# nd_freeze works on policy output so works fine but does not disable old source -# file, so we are moving it to .disabled "manually" here if we do not detect -# use of snapshot url there (we might implement support that way). -# Remove after https://github.com/neurodebian/neurodebian/issues/90 is fixed/released -# for the used date of nd_freeze. -# - Originally used neurodebian, now switched to debian based for trixie +# Pin APT to a snapshot.debian.org timestamp by writing the deb822 sources +# directly, instead of via nd_freeze. nd_freeze scrapes snapshot.debian.org +# with a raw HTTP/1.1 socket read that has no timeout, and a build once hung +# there silently until the 6h job limit. snapshot.debian.org serves the most +# recent snapshot at or before the given timestamp. deb-src is needed for +# `apt-get build-dep`. The Release files on snapshots are past their +# Valid-Until, hence Check-Valid-Until=false. +# NB: the build-linux-buildenv workflow parses DEBIAN_SNAPSHOT for image tags. +ARG DEBIAN_SNAPSHOT=20260924T000000Z RUN set -ex; \ - apt update; \ - apt install neurodebian-freeze; \ - nd_freeze 20260425; \ - f=/etc/apt/sources.list.d/debian.sources; if [ -e "$f" ] && ! grep -q "^URIs:.*snapshot\." "$f"; then mv "$f" "$f.disabled"; fi; \ - sed -i -e 's,\(^deb\) \(.*\),\1 \2\ndeb-src \2,g' /etc/apt/sources.list.d/*.list; \ + echo 'Acquire::Check-Valid-Until "false";' >| /etc/apt/apt.conf.d/10no-check-valid-until; \ + echo 'Acquire::http::Timeout "120";' >> /etc/apt/apt.conf.d/20snapshots; \ + rm -f /etc/apt/sources.list /etc/apt/sources.list.d/*; \ + printf '%s\n' \ + 'Types: deb deb-src' \ + "URIs: http://snapshot.debian.org/archive/debian/${DEBIAN_SNAPSHOT}" \ + 'Suites: forky forky-updates' \ + 'Components: main' \ + 'Signed-By: /usr/share/keyrings/debian-archive-keyring.pgp' \ + '' \ + 'Types: deb deb-src' \ + "URIs: http://snapshot.debian.org/archive/debian-security/${DEBIAN_SNAPSHOT}" \ + 'Suites: forky-security' \ + 'Components: main' \ + 'Signed-By: /usr/share/keyrings/debian-archive-keyring.pgp' \ + >| /etc/apt/sources.list.d/debian-snapshot.sources; \ + cat /etc/apt/sources.list.d/debian-snapshot.sources; \ apt-get update -qq; \ export DEBIAN_FRONTEND=noninteractive; \ apt-get build-dep -y -q git-annex; \ @@ -33,3 +44,27 @@ RUN set -ex; \ apt-get install -y vim wget strace time ncdu gnupg curl procps datalad pigz less tree; \ apt-get clean; \ rm -rf /var/lib/apt/lists/* + +# git-annex's OsPath build flag (Default: True, but automatic, so ./Setup +# configure silently drops it when a dependency is missing) needs +# file-io >= 0.2.0 since 10.20260213. GHC 9.10 here already provides +# filepath >= 1.5.2, os-string >= 2.0 and directory >= 1.3.8.3, but Debian +# ships only libghc-file-io-dev 0.1.5, so without this builds lack OsPath +# (and with it the fixes e.g. for rename handling on BeeGFS: +# https://git-annex.branchable.com/bugs/35_failed_tests_on_beegfs/). +# file-io only needs GHC boot packages, so register it into the global +# package db. Drop once Debian provides libghc-file-io-dev (>= 0.2.0). +ARG FILE_IO_VERSION=0.2.0 +ARG FILE_IO_SHA256=8e75f8905d7c9f114e6164779e7a19ff0e2968015ecf686934e38250575dabe7 +RUN set -ex; \ + cd /tmp; \ + curl -fsSL -o file-io.tar.gz "https://hackage.haskell.org/package/file-io-${FILE_IO_VERSION}/file-io-${FILE_IO_VERSION}.tar.gz"; \ + echo "${FILE_IO_SHA256} file-io.tar.gz" | sha256sum -c -; \ + tar xzf file-io.tar.gz; \ + cd "file-io-${FILE_IO_VERSION}"; \ + printf 'import Distribution.Simple\nmain = defaultMain\n' > Setup.hs; \ + runghc Setup.hs configure --global --prefix=/usr/local; \ + runghc Setup.hs build; \ + runghc Setup.hs install; \ + ghc-pkg field file-io version; \ + cd /; rm -rf /tmp/file-io*