Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/build-linux-buildenv.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
run: |
set -eux
release=$(sed -nE -e '/FROM/s,.*:(.*),\1,gp' Dockerfile)
freeze_date=$(sed -nE '/nd_freeze/s,.* (20[0-9]*).*,\1,gp' Dockerfile)
freeze_date=$(sed -nE 's,^ARG DEBIAN_SNAPSHOT=(20[0-9]{6}).*,\1,p' Dockerfile)
commit=$(git rev-parse --short=4 HEAD)
docker build \
-t "datalad/buildenv-git-annex:latest" \
Expand Down
65 changes: 50 additions & 15 deletions .github/workflows/tools/containers/buildenv-git-annex/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -8,22 +8,33 @@ RUN echo 'Acquire::http::Dl-Limit "200";' >| /etc/apt/apt.conf.d/20snapshots \
&& echo 'Acquire::https::Dl-Limit "200";' >> /etc/apt/apt.conf.d/20snapshots \
&& echo 'Acquire::Retries "10";' >> /etc/apt/apt.conf.d/20snapshots

# Notes:
# - in APT for NeuroDebian we have #deb-src for debian-devel, so we need to change
# that too.
# - APT specification switched away from .list to .sources format in bookworm.
# nd_freeze works on policy output so works fine but does not disable old source
# file, so we are moving it to .disabled "manually" here if we do not detect
# use of snapshot url there (we might implement support that way).
# Remove after https://github.com/neurodebian/neurodebian/issues/90 is fixed/released
# for the used date of nd_freeze.
# - Originally used neurodebian, now switched to debian based for trixie
# Pin APT to a snapshot.debian.org timestamp by writing the deb822 sources
# directly, instead of via nd_freeze. nd_freeze scrapes snapshot.debian.org
# with a raw HTTP/1.1 socket read that has no timeout, and a build once hung
# there silently until the 6h job limit. snapshot.debian.org serves the most
# recent snapshot at or before the given timestamp. deb-src is needed for
# `apt-get build-dep`. The Release files on snapshots are past their
# Valid-Until, hence Check-Valid-Until=false.
# NB: the build-linux-buildenv workflow parses DEBIAN_SNAPSHOT for image tags.
ARG DEBIAN_SNAPSHOT=20260924T000000Z
RUN set -ex; \
apt update; \
apt install neurodebian-freeze; \
nd_freeze 20260425; \
f=/etc/apt/sources.list.d/debian.sources; if [ -e "$f" ] && ! grep -q "^URIs:.*snapshot\." "$f"; then mv "$f" "$f.disabled"; fi; \
sed -i -e 's,\(^deb\) \(.*\),\1 \2\ndeb-src \2,g' /etc/apt/sources.list.d/*.list; \
echo 'Acquire::Check-Valid-Until "false";' >| /etc/apt/apt.conf.d/10no-check-valid-until; \
echo 'Acquire::http::Timeout "120";' >> /etc/apt/apt.conf.d/20snapshots; \
rm -f /etc/apt/sources.list /etc/apt/sources.list.d/*; \
printf '%s\n' \
'Types: deb deb-src' \
"URIs: http://snapshot.debian.org/archive/debian/${DEBIAN_SNAPSHOT}" \
'Suites: forky forky-updates' \
'Components: main' \
'Signed-By: /usr/share/keyrings/debian-archive-keyring.pgp' \
'' \
'Types: deb deb-src' \
"URIs: http://snapshot.debian.org/archive/debian-security/${DEBIAN_SNAPSHOT}" \
'Suites: forky-security' \
'Components: main' \
'Signed-By: /usr/share/keyrings/debian-archive-keyring.pgp' \
>| /etc/apt/sources.list.d/debian-snapshot.sources; \
cat /etc/apt/sources.list.d/debian-snapshot.sources; \
apt-get update -qq; \
export DEBIAN_FRONTEND=noninteractive; \
apt-get build-dep -y -q git-annex; \
Expand All @@ -33,3 +44,27 @@ RUN set -ex; \
apt-get install -y vim wget strace time ncdu gnupg curl procps datalad pigz less tree; \
apt-get clean; \
rm -rf /var/lib/apt/lists/*

# git-annex's OsPath build flag (Default: True, but automatic, so ./Setup
# configure silently drops it when a dependency is missing) needs
# file-io >= 0.2.0 since 10.20260213. GHC 9.10 here already provides
# filepath >= 1.5.2, os-string >= 2.0 and directory >= 1.3.8.3, but Debian
# ships only libghc-file-io-dev 0.1.5, so without this builds lack OsPath
# (and with it the fixes e.g. for rename handling on BeeGFS:
# https://git-annex.branchable.com/bugs/35_failed_tests_on_beegfs/).
# file-io only needs GHC boot packages, so register it into the global
# package db. Drop once Debian provides libghc-file-io-dev (>= 0.2.0).
ARG FILE_IO_VERSION=0.2.0
ARG FILE_IO_SHA256=8e75f8905d7c9f114e6164779e7a19ff0e2968015ecf686934e38250575dabe7
RUN set -ex; \
cd /tmp; \
curl -fsSL -o file-io.tar.gz "https://hackage.haskell.org/package/file-io-${FILE_IO_VERSION}/file-io-${FILE_IO_VERSION}.tar.gz"; \
echo "${FILE_IO_SHA256} file-io.tar.gz" | sha256sum -c -; \
tar xzf file-io.tar.gz; \
cd "file-io-${FILE_IO_VERSION}"; \
printf 'import Distribution.Simple\nmain = defaultMain\n' > Setup.hs; \
runghc Setup.hs configure --global --prefix=/usr/local; \
runghc Setup.hs build; \
runghc Setup.hs install; \
ghc-pkg field file-io version; \
cd /; rm -rf /tmp/file-io*
Loading