Repository navigation
V1 stable pg19 ci - #60
Merged
Merged
Conversation
Pin all third-party actions in the CI workflow to immutable full-length commit SHAs instead of mutable version tags, per GitHub's supply-chain security best practices. Floating tags (e.g. @v4) can be silently redirected to a different commit if a repository is compromised; a full SHA cannot be moved.
The platform's pg16 is built --with-llvm expecting LLVM 20, but the rockylinux:9 base image now ships LLVM 21, so the JIT bitcode step failed (llvm-lto not found) and the node containers exited. Build with with_llvm=no and out of the bind-mounted tree, and dump container logs on CI failure.
The pgedge CLI is deprecated (and only supports PostgreSQL 15-17), so the docker harness now compiles PostgreSQL from the latest REL_x_y tag of the requested major version, applies the Spock PG patches, and builds Spock from its latest vMAJOR.MINOR.PATCH release tag, following the spock repo's tests/docker approach. Everything installs into the same /home/pgedge/pgedge/pg$VER layout the CLI used, so the compose healthchecks and test suites are unchanged. The entrypoint replaces `pgedge setup` and the `pgedge spock ...` commands with initdb and the equivalent spock SQL calls. Because spock.sub_create connects to the provider synchronously, and every node restarts into its final foreground postgres at the end of its own setup, sub_create is retried until the peer is reachable, with an existence check so retries stay idempotent; otherwise a sub_create landing in a peer's stop/start window kills the node via ON_ERROR_STOP. The workflow resolves the exact PostgreSQL and Spock release tags on the runner and passes them as build args, with GitHub Actions docker layer caching scoped per PG version, so PostgreSQL and Spock are only recompiled when a new release is tagged or the Dockerfile changes. Verified green on PG 18 (3-node replication plus the javascript, junit, and python suites).
Spock's PG 19 support is merged on main but not yet in a release, so the PG 19 matrix entry builds Spock from the main branch, pinned to its tip SHA at run time so the docker layer cache is invalidated by every Spock merge. Drop the spock_ref override once a Spock release includes PG 19 support. Note the trade-off of tracking Spock main: a breaking change on Spock main can fail lolor's PG 19 job independently of the PR under test. The job is required anyway, since we are actively developing against PG 19 and want to see breakage early; if Spock main breaks, rerun after the fix lands or temporarily pin spock_ref to a known-good SHA. PostgreSQL itself has no stable REL_19_x tag yet, so tag resolution now falls back to the newest RC, then BETA, when a major has no stable minor release. Stable tags win automatically once REL_19_0 is cut. Verified green locally on 19beta1 with Spock main (3-node replication plus the javascript, junit, and python suites).
PG19 commit a5b35fcedb5 ("Remove PointerIsValid()") deleted the macro.
Replace Assert(PointerIsValid(obj_desc)) with Assert(obj_desc) in
lolor_inv_api.c, matching the same change upstream made in its inv_api.c
(from which this file is forked). Assert(obj_desc) compiles on all
supported branches, so no version guard is required.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Up to standards ✅🟢 Issues
|
| Category | Results |
|---|---|
| ErrorProne | 1 medium (1 false positive) |
🟢 Metrics 0 complexity · 0 duplication
Metric Results Complexity 0 Duplication 0
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
Backport the CI portions of 622152f; its sql/ and expected/ changes are left out. Cap the job at 45 minutes and the test wait at 25, dumping activity, locks and subscription status on timeout; a hung tester previously ran to the six hour ceiling and was cancelled rather than failed. Set output_plugin_libraries where supported, without which spock_output cannot decode and no subscription syncs, and bound the entrypoint's peer wait. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.