Skip to content

ci: fix Linux build after Debian 11 EOL - #398

Merged
Nord1cWarr1or merged 2 commits into
rehlds:masterfrom
Nord1cWarr1or:fix/ci-bullseye-eol
Sep 17, 2026
Merged

Nord1cWarr1or merged 2 commits into
rehlds:masterfrom
Nord1cWarr1or:fix/ci-bullseye-eol

Conversation

@Nord1cWarr1or

@Nord1cWarr1or Nord1cWarr1or commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

🖤

Purpose

Linux CI fails on the apt step (Check dependencies): Debian 11 left LTS on 2026-08-31, the bullseye-security suite is frozen and its pool is being pruned from deb.debian.org — the frozen index lists deb11u5/deb11u14 versions whose .deb files are already gone, so apt-get install 404s. Failing job: Linux, run 34832742423.

Resolves #397.

Approach

Keep the debian:11-slim container and its gcc 10 toolchain — the binaries must keep passing reapi/version/glibc_test.sh (GLIBC ≤ 2.11, GLIBCXX ≤ 3.4.15, CXXABI ≤ 1.3.5), so bumping the base image is not an option without compat work. Only the apt sources change:

  • bullseye and bullseye-updates → archive.debian.org
  • bullseye-security → snapshot.debian.org, pinned to 20260831T000000Z, the last snapshot with a complete pool (post-EOL snapshots record the pruned state)
  • Acquire::Check-Valid-Until=false for the frozen Release files

Open Questions and Pre-Merge TODOs

  • Verified in Docker: the exact CI step installs the same toolchain (gcc 10.2.1, cmake 3.18.4); the build succeeds; glibc_test.sh passes on every artifact (all six org repos tested against the same sources layout).
  • Green CI run on this PR.

Learning

  • Debian LTS calendar: https://wiki.debian.org/LTS (bullseye EOL 2026-08-31)
  • archive.debian.org serves bullseye/bullseye-updates; bullseye-security is not archived yet (checked 2026-09-17, newest suite there is buster)
  • snapshot.debian.org keeps snapshots forever; post-EOL crawls mirror the pruned pool — hence the pre-EOL pin

Debian 11 left LTS on 2026-08-31. The bullseye-security suite is
frozen and its pool is being pruned from deb.debian.org, so the
apt step fails with exit code 100: expired InRelease on update,
or 404 on fetched packages.

Keep the same debian:11-slim container and gcc 10 toolchain: the
release binaries must keep passing glibc_test.sh with the current
baseline. Instead, point the base suite at archive.debian.org and
pin bullseye-security to its last complete snapshot (2026-08-31);
allow the expired Release files via Acquire::Check-Valid-Until.

Verified in Docker: the apt step installs the same toolchain
(gcc 10.2.1, cmake 3.18.4), the build succeeds, and glibc_test.sh
passes on every artifact.

Resolves: 397
The first CI runs showed snapshot.debian.org resetting connections
under CI burst load (a single reset aborts the whole apt install),
and its cloudflare mirror needs https, while debian:11-slim ships
without ca-certificates.

Install ca-certificates from the http archive first, then fetch
the security suite from the cloudflare mirror of the same pinned
snapshot, and retry transient apt failures with Acquire::Retries.
@Nord1cWarr1or
Nord1cWarr1or merged commit ecbd427 into rehlds:master Sep 17, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: Linux build fails after Debian 11 (bullseye) end of LTS

1 participant