Skip to content

fix(ci): move Build workflow off the deprecated ubuntu-20.04 runner - #28

Open
Akshay-2007-1 wants to merge 8 commits into
mainfrom
fix-build-runner-ubuntu
Open

Akshay-2007-1 wants to merge 8 commits into
mainfrom
fix-build-runner-ubuntu

Conversation

@Akshay-2007-1

Copy link
Copy Markdown
Contributor

Summary

  • The Build workflow's runs-on: ubuntu-20.04 requests a GitHub-hosted runner image that's been deprecated and removed. The job sits queued forever with no runner ever picking it up.
  • Confirmed live: pushing the release-v0.3.0 tag queued a run that sat with an empty runner_name for 20+ minutes before being manually cancelled - and this workflow had zero prior successful runs in the repo's history to compare against.
  • Switches to ubuntu-22.04, still a currently-supported GitHub-hosted image.

Test plan

  • Re-run the workflow (workflow_dispatch on main, or re-push a release-*/dev-*/sling-* tag) and confirm a runner actually picks it up and the build completes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu

Akshay-2007-1 and others added 8 commits September 30, 2026 15:12
GitHub removed the Ubuntu 20.04 hosted runner image, so this job was
sitting queued forever with no runner ever picking it up (confirmed:
zero prior runs of this workflow existed, and the release-v0.3.0 tag
push got stuck queued for 20+ minutes with no runner_name assigned
until manually cancelled).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
actions/upload-artifact@v2 is hard-deprecated - GitHub auto-fails any
run using it before a single step executes. Bumps it and the
similarly ancient actions/checkout@v2 to v4.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
satackey/action-docker-layer-caching@v0.0.8 calls a GitHub Actions
cache API endpoint that's since been decommissioned ("Our services
aren't available right now"), failing every run before the build even
starts. It's purely a build-speed optimization, not required for
correctness - removing it rather than trying to replace it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
…control's Dockerfile

BuildKit mounts each RUN step's rootfs with nosuid, which breaks
`sudo` there ("effective uid is not 0") even though the Dockerfile
itself is unchanged - this only surfaced from the runs-on bump to a
runner image shipping a newer Docker Engine. Falls back to the legacy
builder, which doesn't impose this restriction.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
…uilding

Confirmed the nosuid failure isn't BuildKit-specific (same error with
DOCKER_BUILDKIT=0) - it's the runner's Docker host mounting RUN steps'
rootfs nosuid regardless of builder. sudo was never load-bearing here
anyway (build_control_panel.sh always runs the resulting image with
-u 0:0), so removing it is safe and sidesteps the host-level issue
entirely, without touching the upstream submodule repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
…ad of relying on sudo

Root cause, verified by comparison: the sibling debian-stretch-cross
image (Dockerfile.sling) uses the identical sudo pattern and builds
fine on this same runner, but debian-stretch-armel-cross's own
/usr/bin/sudo is missing its setuid bit - a defect specific to that
one base image, not a runner/host/BuildKit issue (previous two fix
attempts for those wrongly assumed causes didn't help, and confirmed
this image's default user genuinely isn't root either: a plain sed -i
on /etc/apt/sources.list without sudo fails with a real permission
error). Forcing USER root sidesteps sudo's broken setuid mechanism
entirely rather than depending on it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
… keys

apt refuses to install packages non-interactively once a repo's
Release-file signature has expired, which is the case for
archive.debian.org's Stretch suite (confirmed via the build log's GPG
warnings: both the Debian Archive Automatic Signing Key and the
Debian Stable Release Key are expired). Scoped narrowly to this one
install step, from this single archived/dead repository only.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu
…of hardcoding them

The hardcoded exclusion list assumed the CI host's mke2fs would either
recognize each feature name (and disable it) or never have heard of it
at all (making the exclusion a harmless no-op). Bumping the runner
image broke that assumption in a new way: its mke2fs (1.46.5) doesn't
recognize one of the five names, and an unrecognized name in the -O
list isn't a no-op - it makes mke2fs reject the whole option string as
invalid, aborting the build ("Invalid filesystem option set").

Replaces the hardcoded string with a real per-feature test against a
scratch file on this same host's mke2fs (the same binary guestfish's
appliance is built from), keeping only the names it actually accepts -
self-adapting to whatever e2fsprogs version happens to be installed,
rather than needing another hardcoded update next time it changes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UfpKt8WtJCGZHiETgDXmYu

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant