Repository navigation
ci: fix Linux build after Debian 11 EOL - #398
Merged
Merged
Conversation
Debian 11 left LTS on 2026-08-31. The bullseye-security suite is frozen and its pool is being pruned from deb.debian.org, so the apt step fails with exit code 100: expired InRelease on update, or 404 on fetched packages. Keep the same debian:11-slim container and gcc 10 toolchain: the release binaries must keep passing glibc_test.sh with the current baseline. Instead, point the base suite at archive.debian.org and pin bullseye-security to its last complete snapshot (2026-08-31); allow the expired Release files via Acquire::Check-Valid-Until. Verified in Docker: the apt step installs the same toolchain (gcc 10.2.1, cmake 3.18.4), the build succeeds, and glibc_test.sh passes on every artifact. Resolves: 397
The first CI runs showed snapshot.debian.org resetting connections under CI burst load (a single reset aborts the whole apt install), and its cloudflare mirror needs https, while debian:11-slim ships without ca-certificates. Install ca-certificates from the http archive first, then fetch the security suite from the cloudflare mirror of the same pinned snapshot, and retry transient apt failures with Acquire::Retries.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🖤
Purpose
Linux CI fails on the apt step (
Check dependencies): Debian 11 left LTS on 2026-08-31, thebullseye-securitysuite is frozen and its pool is being pruned fromdeb.debian.org— the frozen index listsdeb11u5/deb11u14versions whose .deb files are already gone, soapt-get install404s. Failing job: Linux, run 34832742423.Resolves #397.
Approach
Keep the
debian:11-slimcontainer and its gcc 10 toolchain — the binaries must keep passingreapi/version/glibc_test.sh(GLIBC ≤ 2.11, GLIBCXX ≤ 3.4.15, CXXABI ≤ 1.3.5), so bumping the base image is not an option without compat work. Only the apt sources change:bullseyeandbullseye-updates→archive.debian.orgbullseye-security→snapshot.debian.org, pinned to20260831T000000Z, the last snapshot with a complete pool (post-EOL snapshots record the pruned state)Acquire::Check-Valid-Until=falsefor the frozen Release filesOpen Questions and Pre-Merge TODOs
glibc_test.shpasses on every artifact (all six org repos tested against the same sources layout).Learning
archive.debian.orgservesbullseye/bullseye-updates;bullseye-securityis not archived yet (checked 2026-09-17, newest suite there is buster)snapshot.debian.orgkeeps snapshots forever; post-EOL crawls mirror the pruned pool — hence the pre-EOL pin