From d1a567f7e36d1103baffe60b7ca76543bfe590b5 Mon Sep 17 00:00:00 2001 From: TapTap Date: Tue, 15 Sep 2026 20:37:50 +0200 Subject: [PATCH] ci: pin fastsync-ci:v11 with rsync 3.4.1 + acl/attr for parity tests Add POSIX ACL/xattr tooling (acl, attr), zstd/lz4/xxhash dev libs and build rsync 3.4.1 from source so drop-in parity tests can run inside CI. Bump all workflow/agent image references v10 -> v11. --- .gitea/workflows/ci.yaml | 12 ++++++------ AGENTS.md | 15 ++++++++------- Dockerfile | 14 +++++++++++++- HANDOFF.md | 2 +- shell.nix | 2 +- 5 files changed, 29 insertions(+), 16 deletions(-) diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index bc08d57..464511c 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -9,7 +9,7 @@ on: jobs: lint: runs-on: ubuntu-latest - container: gitea.tap-tap.win/taptap/fastsync-ci:v10 + container: gitea.tap-tap.win/taptap/fastsync-ci:v11 steps: - name: Checkout uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 @@ -26,7 +26,7 @@ jobs: # suite) run on merge to dev/main, so PR CI stays well under ~3 minutes. build-and-test: runs-on: ubuntu-latest - container: gitea.tap-tap.win/taptap/fastsync-ci:v10 + container: gitea.tap-tap.win/taptap/fastsync-ci:v11 needs: lint steps: - name: Checkout @@ -51,7 +51,7 @@ jobs: sanitizers: runs-on: ubuntu-latest - container: gitea.tap-tap.win/taptap/fastsync-ci:v10 + container: gitea.tap-tap.win/taptap/fastsync-ci:v11 needs: lint if: github.event_name == 'push' strategy: @@ -72,7 +72,7 @@ jobs: fuzz-build: runs-on: ubuntu-latest - container: gitea.tap-tap.win/taptap/fastsync-ci:v10 + container: gitea.tap-tap.win/taptap/fastsync-ci:v11 needs: lint if: github.event_name == 'push' steps: @@ -94,7 +94,7 @@ jobs: coverage: runs-on: ubuntu-latest - container: gitea.tap-tap.win/taptap/fastsync-ci:v10 + container: gitea.tap-tap.win/taptap/fastsync-ci:v11 needs: lint if: github.event_name == 'push' steps: @@ -118,7 +118,7 @@ jobs: valgrind: runs-on: ubuntu-latest - container: gitea.tap-tap.win/taptap/fastsync-ci:v10 + container: gitea.tap-tap.win/taptap/fastsync-ci:v11 needs: lint if: github.event_name == 'push' steps: diff --git a/AGENTS.md b/AGENTS.md index abdb967..f25379b 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -4,18 +4,19 @@ FastSync is a high-performance file synchronization system written in C11. It su ## Dependency installation -**CI rule:** never add `apt-get install` / `pip install` steps to CI workflows — use the custom Docker image instead. The image is built from the repo-root `Dockerfile` and is the same image CI uses: `gitea.tap-tap.win/taptap/fastsync-ci:v10`. It contains the full toolchain: gcc/g++, CMake, libzstd-dev, libssl-dev, make, git, cppcheck, clang-format, python3 + pytest + pytest-xdist, openssh-client, and Node.js. +**CI rule:** never add `apt-get install` / `pip install` steps to CI workflows — use the custom Docker image instead. The image is built from the repo-root `Dockerfile` and is the same image CI uses: `gitea.tap-tap.win/taptap/fastsync-ci:v11`. It contains the full toolchain: gcc/g++, CMake, libzstd-dev, libssl-dev, make, git, cppcheck, clang-format, python3 + pytest + pytest-xdist, openssh-client, Node.js, plus `rsync` 3.4.1 (with zstd/xxhash/lz4), `acl` and `attr` (setfacl/getfacl, setfattr/getfattr) for drop-in parity tests. **Host rule:** for local development, use `nix-shell` (see `README.md`) which provides zstd, OpenSSL, CMake, and gcc. The Docker image can also be used locally for CI parity. ```bash # Use the prebuilt CI image directly (faster, guaranteed CI parity) -docker pull gitea.tap-tap.win/taptap/fastsync-ci:v10 -docker tag gitea.tap-tap.win/taptap/fastsync-ci:v10 fastsync-ci:local +docker pull gitea.tap-tap.win/taptap/fastsync-ci:v11 +docker tag gitea.tap-tap.win/taptap/fastsync-ci:v11 fastsync-ci:local # Or build the image from the repo-root Dockerfile -# (Note: the prebuilt :v10 image reflects the previous Dockerfile state; -# rebuild from source to pick up any newly added packages like lcov/valgrind.) +# (Note: the prebuilt :v11 image is built from the current Dockerfile and +# includes rsync 3.4.1 plus acl/attr; rebuild from source after changing +# the Dockerfile.) docker build -t fastsync-ci:local . # Build, run unit tests, and run integration tests inside the container @@ -66,14 +67,14 @@ When running the CI workflow via `tea` (the task execution agent), always set a ### If lint (clang-format) fails Run clang-format in the CI Docker image to match the exact CI version: ```bash -docker run --rm -v "$PWD:/workspace" -w /workspace gitea.tap-tap.win/taptap/fastsync-ci:v10 \ +docker run --rm -v "$PWD:/workspace" -w /workspace gitea.tap-tap.win/taptap/fastsync-ci:v11 \ sh -c 'find src/ tests/ -name "*.c" -o -name "*.h" | xargs clang-format -i' ``` ### If cppcheck fails Fix reported issues locally, then verify with: ```bash -docker run --rm -v "$PWD:/workspace" -w /workspace gitea.tap-tap.win/taptap/fastsync-ci:v10 \ +docker run --rm -v "$PWD:/workspace" -w /workspace gitea.tap-tap.win/taptap/fastsync-ci:v11 \ sh -c 'cppcheck --enable=warning,style,performance,portability --suppress=missingIncludeSystem --error-exitcode=1 --inline-suppr src/ tests/' ``` diff --git a/Dockerfile b/Dockerfile index 965384e..5f28e9f 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,8 +2,20 @@ FROM ubuntu:24.04 RUN apt-get update && apt-get install -y --no-install-recommends \ gcc g++ make libc6-dev cmake libzstd-dev libssl-dev git ca-certificates curl cppcheck clang-format \ python3 python3-pip python3-venv openssl openssh-client \ - lcov valgrind clang libclang-rt-18-dev && \ + lcov valgrind clang libclang-rt-18-dev \ + acl attr zlib1g-dev liblz4-dev libxxhash-dev && \ pip3 install --break-system-packages pytest pytest-xdist && \ curl -fsSL https://deb.nodesource.com/setup_20.x | bash - && \ apt-get install -y --no-install-recommends nodejs && \ rm -rf /var/lib/apt/lists/* + +# rsync is used as the reference implementation for drop-in parity tests. +# Ubuntu 24.04 ships 3.2.7, so build the pinned 3.4.1 reference from source. +ARG RSYNC_VERSION=3.4.1 +RUN curl -fsSL "https://download.samba.org/pub/rsync/src/rsync-${RSYNC_VERSION}.tar.gz" -o /tmp/rsync.tar.gz && \ + tar -xzf /tmp/rsync.tar.gz -C /tmp && \ + cd "/tmp/rsync-${RSYNC_VERSION}" && \ + ./configure --enable-zstd --enable-xxhash --enable-lz4 && \ + make -j"$(nproc)" && \ + make install && \ + rm -rf "/tmp/rsync-${RSYNC_VERSION}" /tmp/rsync.tar.gz diff --git a/HANDOFF.md b/HANDOFF.md index fcb251e..0f44ba7 100644 --- a/HANDOFF.md +++ b/HANDOFF.md @@ -54,7 +54,7 @@ FastSync is push-only; see `RSYNC_COMPAT.md#direction`. ## Key facts / commands -- CI image: `gitea.tap-tap.win/taptap/fastsync-ci:v10` (alias `fastsync-ci:local`). +- CI image: `gitea.tap-tap.win/taptap/fastsync-ci:v11` (alias `fastsync-ci:local`). - Build/test: `cmake -B build -S . -DSTRICT_WARNINGS=ON && cmake --build build -j$(nproc) && ./build/tests` then `python3 -m pytest tests/integration/ -n 4 --dist=load -m "not setpriv"`. - Dev shell: `nix-shell` (provides clang-format, cppcheck, pytest-xdist, openssh, diff --git a/shell.nix b/shell.nix index 93b731f..6d03b8d 100644 --- a/shell.nix +++ b/shell.nix @@ -54,6 +54,6 @@ pkgs.mkShell { echo "FastSync dev shell ready." echo " Build: cmake -B build -S . && cmake --build build -j\$(nproc)" echo " Unit: ./build/tests" - echo " CI parity: docker run --rm --user \"\$(id -u):\$(id -g)\" -v \"\$PWD:/workspace\" -w /workspace gitea.tap-tap.win/taptap/fastsync-ci:v10 ..." + echo " CI parity: docker run --rm --user \"\$(id -u):\$(id -g)\" -v \"\$PWD:/workspace\" -w /workspace gitea.tap-tap.win/taptap/fastsync-ci:v11 ..." ''; }