Repository navigation
ci: fix Linux build after Debian 11 EOL - #95
Merged
Merged
Conversation
Debian 11 left LTS on 2026-08-31. The bullseye-security suite is frozen and its pool is being pruned from deb.debian.org; the first CI run after that date fails with exit code 100: expired InRelease on update, or 404 on fetched packages. Keep the same debian:11-slim container and gcc 10 toolchain the release binaries are built with. Instead, point the base suite at archive.debian.org and pin bullseye-security to its last complete snapshot (2026-08-31); allow the expired Release files via Acquire::Check-Valid-Until. Verified in Docker: the apt step installs the same toolchain (gcc 10.2.1, cmake 3.18.4) and the build succeeds. Resolves: 94
The first CI runs showed snapshot.debian.org resetting connections under CI burst load (a single reset aborts the whole apt install), and its cloudflare mirror needs https, while debian:11-slim ships without ca-certificates. Install ca-certificates from the http archive first, then fetch the security suite from the cloudflare mirror of the same pinned snapshot, and retry transient apt failures with Acquire::Retries.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🖤
Purpose
The Linux job builds in
debian:11-slimand installs fromdeb.debian.org. Debian 11 left LTS on 2026-08-31; this repo has not run CI since (last completed run 2026-08-27, pre-EOL), so the next push or PR will fail onInstall dependenciesexactly like the other org repos already do. Evidence from a sibling: ReHLDS failing job.Resolves #94.
Approach
Keep the
debian:11-slimcontainer and its gcc 10 toolchain — the binaries must keep passingmetamod/version/glibc_test.sh(GLIBC ≤ 2.11, GLIBCXX ≤ 3.4.15, CXXABI ≤ 1.3.5), so bumping the base image is not an option without compat work. Only the apt sources change:bullseyeandbullseye-updates→archive.debian.orgbullseye-security→snapshot.debian.org, pinned to20260831T000000Z, the last snapshot with a complete pool (post-EOL snapshots record the pruned state)Acquire::Check-Valid-Until=falsefor the frozen Release filesOpen Questions and Pre-Merge TODOs
COMPAT_GLIBCbuild succeeds;glibc_test.shpasses on the artifact (all six org repos tested against the same sources layout).Learning
archive.debian.orgservesbullseye/bullseye-updates;bullseye-securityis not archived yet (checked 2026-09-17, newest suite there is buster)snapshot.debian.orgkeeps snapshots forever; post-EOL crawls mirror the pruned pool — hence the pre-EOL pin