threads / patch / 66489

patch, 8 partsci: some housekeeping and modernizations

Subject: [PATCH 0/8] ci: some housekeeping and modernizations

## tl;dr

10 messages between Oct 8, 2026 and Oct 8, 2026. Diffs are folded; open one to read it.

replies: 9people: 2as markdown or json

Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · lore
Hi,

this patch series is a result from the discussions in [1]. It fixes a couple of smaller issues in our CI and bumps jobs that use EOL Docker images to instead use supported ones.

Passing test runs can be found at [2] and [3] for GitLab and GitHub, respectively.

Note that I've also merged the Meson changes (ps/meson-improvements at ce4a600322 (gitlab-ci: fix hanging MSVC jobs, 2026-09-24)) in there so that GitLab passes, but those are not strictly required as a dependency.

Thanks!
Patrick

[1]: <20260906151137.GA328152@coredump.intra.peff.net> [2]: https://gitlab.com/gitlab-org/git/-/merge_requests/687 [3]: https://github.com/git/git/pull/2445

---
Patrick Steinhardt (8):
      t5004: skip SHA-1-only test in SHA-256 repository
      ci: fix "fedora-breaking-changes-meson" job
      ci: drop unused "linux-clang" logic
      ci: switch away from unsupported i386/ubuntu image
      ci: rename linux-TEST-vars job
      ci: switch away from EOL'd Ubuntu version in linux-exotic
      ci: drop now-dead Python 2 coverage
      ci: drop redundant linux-reftable job
 .github/workflows/main.yml      | 12 +++---------
 .gitlab-ci.yml                  | 12 +++---------
 ci/install-dependencies.sh      |  8 ++------
 ci/lib.sh                       | 13 ++-----------
 ci/run-build-and-tests.sh       | 10 +++-------
 t/t5004-archive-corner-cases.sh |  2 +-
 6 files changed, 14 insertions(+), 43 deletions(-)

--- base-commit: 8e383dedc6bbc4fd7bbb203512fbf2eafc151e04 change-id: 20261008-pks-ci-housekeeping-4cf7fac3b0df

Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 1/8] t5004: skip SHA-1-only test in SHA-256 repository

One of the tests in t5004 extracts a ZIP file that contains some objects larger than 4GB and then double-checks whether we can read and archive such an object. That test has a bunch of prerequities: it requires a 64 bit `long`, unzip with 64-bit support and it only runs when EXPENSIVE is enabled. Consequently, not a lot of jobs even exercise this.

One of the jobs that does run it though our Fedora-based job, as it ticks all the necessary boxes. But that job was silently broken: while the intent was to run on Fedora with breaking changes enabled, they are in fact disabled due to a typo.

We're about to fix that typo in the next commit, but this will also uncover that the above test case is broken when running in SHA-256 repositories. The extracted objects are SHA-1 objects, so extracting them into a SHA-256 repository is not going to yield anything good. So once we fix the Fedora-based job to enable breaking changes, which will make tests use SHA-256 by default, the test will break.

Fix this issue by adding the SHA1 prerequisite.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 t/t5004-archive-corner-cases.sh | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Show changes to t/t5004-archive-corner-cases.sh +1 −1
diff --git a/t/t5004-archive-corner-cases.sh b/t/t5004-archive-corner-cases.sh
index 768b0ff85d..c9c879cc5f 100755
--- a/t/t5004-archive-corner-cases.sh
+++ b/t/t5004-archive-corner-cases.sh
@@ -185,7 +185,7 @@ test_expect_success EXPENSIVE,UNZIP,UNZIP_ZIP64_SUPPORT \
 	"$GIT_UNZIP" -t many-big.zip
 '
 
-test_expect_success EXPENSIVE,LONG_IS_64BIT,UNZIP,UNZIP_ZIP64_SUPPORT,ZIPINFO \
+test_expect_success EXPENSIVE,LONG_IS_64BIT,UNZIP,UNZIP_ZIP64_SUPPORT,ZIPINFO,SHA1 \
 	'zip archive with files bigger than 4GB' '
 	# Pack created with:
 	#   dd if=/dev/zero of=file bs=1M count=4100 && git hash-object -w file
-- 
2.56.0.406.ga2d225a756.dirty
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 2/8] ci: fix "fedora-breaking-changes-meson" job

The "fedora-breaking-changes-meson" job exercises Git with breaking changes enabled on Fedora with Meson. There's a typo in our CI scripts though, which has the effect that the build does not enable breaking changes by accident.

Fix the typo.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 ci/run-build-and-tests.sh | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Show changes to ci/run-build-and-tests.sh +1 −1
diff --git a/ci/run-build-and-tests.sh b/ci/run-build-and-tests.sh
index 6a3b43b366..bc5058c917 100755
--- a/ci/run-build-and-tests.sh
+++ b/ci/run-build-and-tests.sh
@@ -18,7 +18,7 @@ almalinux-*|debian-*|fedora-*|linux-*)
 esac
 
 case "$jobname" in
-fedora-breaking-changes-musl|linux-breaking-changes)
+fedora-breaking-changes-meson|linux-breaking-changes)
 	export WITH_BREAKING_CHANGES=YesPlease
 	MESONFLAGS="$MESONFLAGS -Dbreaking_changes=true"
 	;;
-- 
2.56.0.406.ga2d225a756.dirty
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 3/8] ci: drop unused "linux-clang" logic

In d88d727143 (ci: drop linux-clang job, 2023-06-01) we have dropped the "linux-clang" job because another job already uses Clang anyway. But we forgot to also drop the logic in "ci/run-build-and-tests.sh", so we now have some unused logic in there.

Drop it.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 ci/run-build-and-tests.sh | 4 ----
 1 file changed, 4 deletions(-)
Show changes to ci/run-build-and-tests.sh +0 −4
diff --git a/ci/run-build-and-tests.sh b/ci/run-build-and-tests.sh
index bc5058c917..23e87cbbd6 100755
--- a/ci/run-build-and-tests.sh
+++ b/ci/run-build-and-tests.sh
@@ -37,10 +37,6 @@ linux-TEST-vars)
 	export GIT_TEST_CHECKOUT_WORKERS=2
 	export GIT_TEST_PACK_USE_BITMAP_BOUNDARY_TRAVERSAL=1
 	;;
-linux-clang)
-	export NO_RUST=UnfortunatelyYes
-	export GIT_TEST_DEFAULT_HASH=sha1
-	;;
 linux-sha256)
 	export GIT_TEST_DEFAULT_HASH=sha256
 	;;
-- 
2.56.0.406.ga2d225a756.dirty
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 4/8] ci: switch away from unsupported i386/ubuntu image

The linux32 job is used to exercise Git on a 32 bit platform. That job uses i386/ubuntu:20.04 though, and that version of Ubuntu is end of life nowadays. Furthermore, Ubuntu has dropped support for 32 bit entirely with the 20.04 release, so we cannot easily upgrade it to a more recent image anymore.

Switch the job over to use i386/debian instead. Note that starting with Debian 13, support for i386 has been reduced [1]. But Debian still releases 32 bit Docker images for the latest release nowadays, so we will have coverage until at least 2030.

[1]: https://www.debian.org/releases/trixie/release-notes/issues.en.html#i386-reduced-support
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 .github/workflows/main.yml | 3 +--
 .gitlab-ci.yml             | 3 +--
 ci/install-dependencies.sh | 6 +-----
 ci/lib.sh                  | 2 +-
 4 files changed, 4 insertions(+), 10 deletions(-)
Show changes to 4 files +4 −10

.github/workflows/main.yml, .gitlab-ci.yml, ci/install-dependencies.sh, ci/lib.sh

diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index b229739be8..6d1e37c8f1 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -431,9 +431,8 @@ jobs:
           cc: gcc
         - jobname: linux-musl-meson
           image: alpine:latest
-        # Supported until 2025-04-02.
         - jobname: linux32
-          image: i386/ubuntu:20.04
+          image: i386/debian:latest
         # A RHEL 8 compatible distro.  Supported until 2029-05-31.
         - jobname: almalinux-8
           image: almalinux:8
diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index 3f24835500..7d972f0c8b 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml
@@ -65,9 +65,8 @@ test:linux:
         CC: gcc
       - jobname: linux-musl-meson
         image: alpine:latest
-        # Supported until 2025-04-02.
       - jobname: linux32
-        image: i386/ubuntu:20.04
+        image: i386/debian:latest
       # A RHEL 8 compatible distro.  Supported until 2029-05-31.
       - jobname: almalinux-8
         image: almalinux:8
diff --git a/ci/install-dependencies.sh b/ci/install-dependencies.sh
index d57dce5663..8783b48951 100755
--- a/ci/install-dependencies.sh
+++ b/ci/install-dependencies.sh
@@ -39,7 +39,7 @@ fedora-*|almalinux-*)
 	dnf -yq update >/dev/null &&
 	dnf -yq install shadow-utils sudo make pkg-config gcc findutils diffutils perl python3 gawk gettext zlib-devel expat-devel openssl-devel curl-devel pcre2-devel $MESON_DEPS cargo >/dev/null
 	;;
-ubuntu-*|i386/ubuntu-*|debian-*)
+ubuntu-*|i386/debian-*|debian-*)
 	# Required so that apt doesn't wait for user input on certain packages.
 	export DEBIAN_FRONTEND=noninteractive
 
@@ -48,10 +48,6 @@ ubuntu-*|i386/ubuntu-*|debian-*)
 		SVN='libsvn-perl subversion'
 		LANGUAGES='language-pack-is'
 		;;
-	i386/ubuntu-*)
-		SVN=
-		LANGUAGES='language-pack-is'
-		;;
 	*)
 		SVN='libsvn-perl subversion'
 		LANGUAGES='locales-all'
diff --git a/ci/lib.sh b/ci/lib.sh
index c6ccbf8c17..d99e7b9da1 100755
--- a/ci/lib.sh
+++ b/ci/lib.sh
@@ -262,7 +262,7 @@ then
 		CI_OS_NAME=osx
 		JOBS=$(nproc)
 		;;
-	*,almalinux:*|*,alpine:*|*,debian:*|*,fedora:*|*,ubuntu:*|*,i386/ubuntu:*)
+	*,almalinux:*|*,alpine:*|*,debian:*|*,fedora:*|*,ubuntu:*|*,i386/debian:*)
 		CI_OS_NAME=linux
 		JOBS=$(nproc)
 		;;
-- 
2.56.0.406.ga2d225a756.dirty
Todd Zullinger· Oct 8, 2026, 15:03 UTC · re: Patrick Steinhardt · lore

Re: [PATCH 4/8] ci: switch away from unsupported i386/ubuntu image

Patrick Steinhardt wrote:
Show 5 quoted lines
> The linux32 job is used to exercise Git on a 32 bit platform. That job
> uses i386/ubuntu:20.04 though, and that version of Ubuntu is end of life
> nowadays. Furthermore, Ubuntu has dropped support for 32 bit entirely
> with the 20.04 release, so we cannot easily upgrade it to a more recent
> image anymore.

Should "with the 20.04 release" be 22.04 (or whatever release dropped i386)?

We've been using 20.04, so i386 support wasn't dropped there, I presume.

You could say "after the 20.04 release" perhaps, but that seems less useful. In that case, you avoid using a version at all, e.g. "dropped support ... entirely in subsequent releases" or something.

Cheers,
-- 
Todd
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 5/8] ci: rename linux-TEST-vars job

The "linux-TEST-vars" job exercises Git with a bunch of non-default options enabled. The name of that job makes you want to cry though due to the weird upper-casing and because it doesn't really tell you what it even intends to do.

Rename the job to "linux-exotic" instead.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 .github/workflows/main.yml | 2 +-
 .gitlab-ci.yml             | 2 +-
 ci/run-build-and-tests.sh  | 2 +-
 3 files changed, 3 insertions(+), 3 deletions(-)
Show changes to 3 files +3 −3

.github/workflows/main.yml, .gitlab-ci.yml, ci/run-build-and-tests.sh

diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index 6d1e37c8f1..d7a301ec98 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -408,7 +408,7 @@ jobs:
         - jobname: linux-reftable
           image: ubuntu:rolling
           cc: clang
-        - jobname: linux-TEST-vars
+        - jobname: linux-exotic
           image: ubuntu:20.04
           cc: gcc
           cc_package: gcc-8
diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index 7d972f0c8b..27a16ed086 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml
@@ -42,7 +42,7 @@ test:linux:
       - jobname: linux-reftable
         image: ubuntu:rolling
         CC: clang
-      - jobname: linux-TEST-vars
+      - jobname: linux-exotic
         image: ubuntu:20.04
         CC: gcc
         CC_PACKAGE: gcc-8
diff --git a/ci/run-build-and-tests.sh b/ci/run-build-and-tests.sh
index 23e87cbbd6..9381ff8893 100755
--- a/ci/run-build-and-tests.sh
+++ b/ci/run-build-and-tests.sh
@@ -22,7 +22,7 @@ fedora-breaking-changes-meson|linux-breaking-changes)
 	export WITH_BREAKING_CHANGES=YesPlease
 	MESONFLAGS="$MESONFLAGS -Dbreaking_changes=true"
 	;;
-linux-TEST-vars)
+linux-exotic)
 	export OPENSSL_SHA1_UNSAFE=YesPlease
 	export GIT_TEST_SPLIT_INDEX=yes
 	export GIT_TEST_FULL_IN_PACK_ARRAY=true
-- 
2.56.0.406.ga2d225a756.dirty
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 6/8] ci: switch away from EOL'd Ubuntu version in linux-exotic

The "linux-exotic" job still uses Ubuntu 20.04, which is end of life nowadays and starting to show some cracks. Switch it over to use the "latest" tag instead so that we don't have to constantly update it anymore.

Now arguably, this reduces test coverage for old versions of Ubuntu. But "latest" at least points to the most up-to-date LTS release of Ubuntu, compared to the "rolling" tag that uses the latest release regardless of the LTS status. So while "latest" and "rolling" are the same right now, that's not always the case.

Furthermore, we have other jobs that test with ancient versions of Linux, like for example the one that uses AlmaLinux 8 (2021, originally tracking RHEL 8 from 2019) or Debian 12 (2023).

Note that this also requires us to switch away from GCC 8, which is not supported by Ubuntu 26.04 anymore. Instead we simply use the default version of GCC.

Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 .github/workflows/main.yml | 4 +---
 .gitlab-ci.yml             | 4 +---
 2 files changed, 2 insertions(+), 6 deletions(-)
Show changes to 2 files +2 −6

.github/workflows/main.yml, .gitlab-ci.yml

diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index d7a301ec98..5b772dab55 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -409,9 +409,7 @@ jobs:
           image: ubuntu:rolling
           cc: clang
         - jobname: linux-exotic
-          image: ubuntu:20.04
-          cc: gcc
-          cc_package: gcc-8
+          image: ubuntu:latest
         - jobname: linux-breaking-changes
           cc: gcc
           image: ubuntu:rolling
diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index 27a16ed086..de40434ae3 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml
@@ -43,9 +43,7 @@ test:linux:
         image: ubuntu:rolling
         CC: clang
       - jobname: linux-exotic
-        image: ubuntu:20.04
-        CC: gcc
-        CC_PACKAGE: gcc-8
+        image: ubuntu:latest
       - jobname: linux-breaking-changes
         image: ubuntu:rolling
         CC: gcc
-- 
2.56.0.406.ga2d225a756.dirty
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 7/8] ci: drop now-dead Python 2 coverage

In the preceding commit we've dropped the last job that still used Ubuntu 20.04. We still had some conditional logic for that specific image that made us use Python 2 instead of Python 3, but this is dead code now.

We could of course exercise Python 2 in any of our other CI jobs. But it reached end of life in 2020 already, and none of the distros that we use have it packaged anymore. Furthermore, it seems like the world has finally adapted to Python 3. So it doesn't feel all that useful to still exercise it.

Drop the logic and instead use Python 3 unconditionally.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 ci/install-dependencies.sh |  2 +-
 ci/lib.sh                  | 11 +----------
 2 files changed, 2 insertions(+), 11 deletions(-)
Show changes to 2 files +2 −11

ci/install-dependencies.sh, ci/lib.sh

diff --git a/ci/install-dependencies.sh b/ci/install-dependencies.sh
index 8783b48951..4b1733ad15 100755
--- a/ci/install-dependencies.sh
+++ b/ci/install-dependencies.sh
@@ -61,7 +61,7 @@ ubuntu-*|i386/debian-*|debian-*)
 		tcl tk gettext zlib1g-dev perl-modules liberror-perl libauthen-sasl-perl \
 		libemail-valid-perl libio-pty-perl libio-socket-ssl-perl libnet-smtp-ssl-perl libdbd-sqlite3-perl libcgi-pm-perl \
 		libsecret-1-dev libpcre2-dev meson ninja-build pkg-config cargo \
-		${CC_PACKAGE:-${CC:-gcc}} $PYTHON_PACKAGE
+		${CC_PACKAGE:-${CC:-gcc}} python3
 
 	# Starting with Ubuntu 25.10, sudo can now be provided via either
 	# sudo(1) or sudo-rs(1), with the latter being the default. The problem
diff --git a/ci/lib.sh b/ci/lib.sh
index d99e7b9da1..3ec10488d4 100755
--- a/ci/lib.sh
+++ b/ci/lib.sh
@@ -335,16 +335,7 @@ esac
 
 case "$distro" in
 ubuntu-*)
-	# Python 2 is end of life, and Ubuntu 23.04 and newer don't actually
-	# have it anymore. We thus only test with Python 2 on older LTS
-	# releases.
-	if test "$distro" = "ubuntu-20.04"
-	then
-		PYTHON_PACKAGE=python2
-	else
-		PYTHON_PACKAGE=python3
-	fi
-	MAKEFLAGS="$MAKEFLAGS PYTHON_PATH=/usr/bin/$PYTHON_PACKAGE"
+	MAKEFLAGS="$MAKEFLAGS PYTHON_PATH=/usr/bin/python3"
 
 	export GIT_TEST_HTTPD=true
 
-- 
2.56.0.406.ga2d225a756.dirty
Patrick Steinhardt· Oct 8, 2026, 10:01 UTC · re: Patrick Steinhardt · lore

[PATCH 8/8] ci: drop redundant linux-reftable job

The "linux-reftable" job exercises Git with reftables as its default backend. But this job is arguably redundant because we already have the "linux-reftable-leaks" job that exercises reftables with the leak sanitizer enabled, and it is unlikely that we will catch any extra bugs with the leak sanitizer disabled.

Drop the job.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 .github/workflows/main.yml | 3 ---
 .gitlab-ci.yml             | 3 ---
 ci/run-build-and-tests.sh  | 2 +-
 3 files changed, 1 insertion(+), 7 deletions(-)
Show changes to 3 files +1 −7

.github/workflows/main.yml, .gitlab-ci.yml, ci/run-build-and-tests.sh

diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index 5b772dab55..4be3f2337d 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -405,9 +405,6 @@ jobs:
         - jobname: linux-sha256
           image: ubuntu:rolling
           cc: clang
-        - jobname: linux-reftable
-          image: ubuntu:rolling
-          cc: clang
         - jobname: linux-exotic
           image: ubuntu:latest
         - jobname: linux-breaking-changes
diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index de40434ae3..f0424bab5b 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml
@@ -39,9 +39,6 @@ test:linux:
       - jobname: linux-sha256
         image: ubuntu:rolling
         CC: clang
-      - jobname: linux-reftable
-        image: ubuntu:rolling
-        CC: clang
       - jobname: linux-exotic
         image: ubuntu:latest
       - jobname: linux-breaking-changes
diff --git a/ci/run-build-and-tests.sh b/ci/run-build-and-tests.sh
index 9381ff8893..df63e79319 100755
--- a/ci/run-build-and-tests.sh
+++ b/ci/run-build-and-tests.sh
@@ -40,7 +40,7 @@ linux-exotic)
 linux-sha256)
 	export GIT_TEST_DEFAULT_HASH=sha256
 	;;
-linux-reftable|linux-reftable-leaks|osx-reftable)
+linux-reftable-leaks|osx-reftable)
 	export GIT_TEST_DEFAULT_REF_STORAGE_FORMAT=reftable
 	;;
 
-- 
2.56.0.406.ga2d225a756.dirty

← back to recent threads