Skip to content

Add PostgreSQL 19 support (topn 2.7.1) and fix RPM matrix - #1213

Merged
ibrahim halatci (ihalatci) merged 4 commits into
redhat-topnfrom
ihalatci-pg19-redhat-topn
Aug 21, 2026
Merged

ibrahim halatci (ihalatci) merged 4 commits into
redhat-topnfrom
ihalatci-pg19-redhat-topn

Conversation

@ihalatci

Copy link
Copy Markdown
Contributor

Adds PostgreSQL 19 to the postgresql-topn RPM packaging, bumping to upstream v2.7.1, and repairs the currently-broken RPM matrix.

Changes

  • pkgvars — pkglatest 2.7.0.citus-1 -> 2.7.1.citus-1
  • postgres-matrix.yml — new entry 2.7.1: postgres_versions: [ 14, 15, 16, 17, 18, 19 ] (appended last; nightly reads version_matrix[-1])
  • topn.spec — Version 2.7.0.citus -> 2.7.1.citus, source archive v2.7.0.tar.gz -> v2.7.1.tar.gz, new %changelog entry
  • pg_exclude.yml — el/8: [19] and ol/8: [19] under release:
  • .github/workflows/build-package.yml — migrated off the retired secrets.GH_TOKEN PAT to actions/create-github-app-token@v3, matching all-citus

Why the matrix drops PG 11-13

This branch is currently red on MAIN_BRANCH and has been since 2026-02-11 — every RPM build since then has failed, on PG11, roughly two minutes in.

Root cause is 3b0fcfe ("remove pg 10-13 from image checks", 2026-01-24), which changed update_dockerfiles from pgversions='11 12 13 14 15 16 17 18' to '14 15 16 17 18'. The RPM path runs one container per PG version, so a matrix entry with no corresponding build image is a hard failure. The first redhat-topn build after that commit is the first failure — exact correlation.

redhat-hll hit the same wall and was narrowed at 2.19 ([11..17] -> [16, 17, 18]). redhat-topn never was. [14, 15, 16, 17, 18, 19] matches the current image set (pgversions='14 15 16 17 18 19' on the packaging-images branch) and the deb DEB_PG_SUPPORTED_VERSIONS.

The historical 2.7.0 entry is left untouched. The deb branch is unaffected — see that PR for why.

Why el/8 / ol/8 exclude PG19

PGDG does not publish PostgreSQL 19 for EL8; update_dockerfiles carries the same guard explicitly, so no almalinux-8-pg19 / oraclelinux-8-pg19 image exists. ol/8 needs its own key because citus_package.py's docker_image_names has no ol/8 entry — it falls through to oraclelinux-8, not almalinux-8.

Why the workflow change is in here

scripts/fetch_and_build_rpm writes Authorization: token ${GITHUB_TOKEN} into ~/.curlrc and resolves the upstream tag through the GitHub API. secrets.GH_TOKEN no longer exists, so that call returned 401 on a request that succeeds anonymously. MAIN_BRANCH still references the dead secret, so this fix has to land here for the branch to build at all.

Upstream tag note

v2.7.1 was originally signed with a key GitHub reported as unknown_key, which trips the signature gate in fetch_and_build_rpm. The tag has been re-signed with the established release key (4FB72F64B64E3FFC) and force-pushed upstream — same commit, same message, GitHub now reports verification=true, reason=valid. Local clones may need git fetch --tags --force.

Verification

Dry run on the feature branch: all 4 rpm platforms green (el/8, el/9, ol/8, ol/9) — the first green RPM build on this branch since January.

Resolved versions confirmed in the logs:

  • el/8 -> Release versions: 14,15,16,17,18 (PG19 correctly excluded)
  • el/9 -> Release versions: 14,15,16,17,18,19

Package publishing skipped since current branch is not equal to redhat-topn confirmed — nothing was uploaded.

All required build images verified present on Docker Hub, including almalinux-8-pg14/15 and oraclelinux-8-pg14/15, which this matrix exercises for the first time.

⚠️ Merging publishes

on: push: branches: ["**"] with --build_type release, and upload_to_package_cloud.py only skips when current_branch != MAIN_BRANCH. Merging this PR ships topn 2.7.1.citus-1 to citusdata/community.

ihalatci-msft and others added 4 commits August 20, 2026 13:52
Bump pkglatest/spec to 2.7.1.citus-1 and append a 2.7.1 entry to postgres-matrix.yml so PostgreSQL 19 is built and published.

Exclude PG19 on el/8 and ol/8: no almalinux-8 / oraclelinux-8 pg19 build image is published, only almalinux-9 (used by el/9 and ol/9).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
The build container's fetch_and_build_deb/_rpm scripts write
GITHUB_TOKEN into ~/.curlrc as an Authorization header before
resolving the upstream release tag. secrets.GH_TOKEN no longer
exists, so that header was empty/invalid and api.github.com
returned 401 -- breaking a request that succeeds anonymously.
The tag lookup then yielded null and the build aborted with
"could not determine commit for git tag".

Switch to the actions/create-github-app-token@v3 flow already
used on all-citus, exporting the installation token as both
GH_TOKEN and GITHUB_TOKEN.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
The RPM build images are generated only for the PostgreSQL versions
listed in update_dockerfiles on the packaging-images branch. Commit
3b0fcfe ("remove pg 10-13 from image checks", 2026-01-24) narrowed
that list to 14-18 (now 14-19), so citus/packaging:*-pg11/12/13 are
stale leftovers that are no longer regenerated and fail at rpmbuild.

redhat-hll was narrowed in lockstep at 2.19 ([16,17,18]); topn never
was, so its RPM builds have failed on every run since 2026-02-11 --
dying on PG11, the first entry in the matrix. Align 2.7.1 with the
image set. The deb side is unaffected because
DEB_PG_SUPPORTED_VERSIONS already intersects 11-13 away.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
tools v0.8.35 mutates input_output_parameters.output_dir inside
build_packages() and never restores it, so sign_packages() looks under
"{base}/{sub_folder}/{sub_folder}", matches zero packages, and skips
signing silently while the job still reports success. Fixed upstream in
4c862ce, first released in v0.8.36, which all-citus already uses.

Effect here: the produced .deb files regain the per-package dpkg-sig
signature that citus packages already carry. RPM verification was not
affected (packagecloud re-signs RPMs on upload with be79ad6a) and apt
verification was not affected (InRelease is signed by packagecloud), so
this restores defense-in-depth rather than repairing a broken trust path.

The only other runtime change between v0.8.35 and v0.8.36 is an optional
postgres_version argument to build_packages(); it defaults to None and is
not passed by this workflow.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
@ihalatci
ibrahim halatci (ihalatci) merged commit 67479df into redhat-topn Aug 21, 2026
9 checks passed
@ihalatci
ibrahim halatci (ihalatci) deleted the ihalatci-pg19-redhat-topn branch August 21, 2026 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants