Repository navigation
Add PostgreSQL 19 support (topn 2.7.1) and fix RPM matrix - #1213
Merged
ibrahim halatci (ihalatci) merged 4 commits intoAug 21, 2026
Merged
Conversation
Bump pkglatest/spec to 2.7.1.citus-1 and append a 2.7.1 entry to postgres-matrix.yml so PostgreSQL 19 is built and published. Exclude PG19 on el/8 and ol/8: no almalinux-8 / oraclelinux-8 pg19 build image is published, only almalinux-9 (used by el/9 and ol/9). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
The build container's fetch_and_build_deb/_rpm scripts write GITHUB_TOKEN into ~/.curlrc as an Authorization header before resolving the upstream release tag. secrets.GH_TOKEN no longer exists, so that header was empty/invalid and api.github.com returned 401 -- breaking a request that succeeds anonymously. The tag lookup then yielded null and the build aborted with "could not determine commit for git tag". Switch to the actions/create-github-app-token@v3 flow already used on all-citus, exporting the installation token as both GH_TOKEN and GITHUB_TOKEN. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
The RPM build images are generated only for the PostgreSQL versions listed in update_dockerfiles on the packaging-images branch. Commit 3b0fcfe ("remove pg 10-13 from image checks", 2026-01-24) narrowed that list to 14-18 (now 14-19), so citus/packaging:*-pg11/12/13 are stale leftovers that are no longer regenerated and fail at rpmbuild. redhat-hll was narrowed in lockstep at 2.19 ([16,17,18]); topn never was, so its RPM builds have failed on every run since 2026-02-11 -- dying on PG11, the first entry in the matrix. Align 2.7.1 with the image set. The deb side is unaffected because DEB_PG_SUPPORTED_VERSIONS already intersects 11-13 away. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
tools v0.8.35 mutates input_output_parameters.output_dir inside
build_packages() and never restores it, so sign_packages() looks under
"{base}/{sub_folder}/{sub_folder}", matches zero packages, and skips
signing silently while the job still reports success. Fixed upstream in
4c862ce, first released in v0.8.36, which all-citus already uses.
Effect here: the produced .deb files regain the per-package dpkg-sig
signature that citus packages already carry. RPM verification was not
affected (packagecloud re-signs RPMs on upload with be79ad6a) and apt
verification was not affected (InRelease is signed by packagecloud), so
this restores defense-in-depth rather than repairing a broken trust path.
The only other runtime change between v0.8.35 and v0.8.36 is an optional
postgres_version argument to build_packages(); it defaults to None and is
not passed by this workflow.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1ed7b58a-0ba9-4f47-a1de-3ee665bae7f2
ibrahim halatci (ihalatci)
enabled auto-merge (squash)
August 20, 2026 17:15
Onur Tirtir (onurctirtir)
approved these changes
Aug 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds PostgreSQL 19 to the
postgresql-topnRPM packaging, bumping to upstreamv2.7.1, and repairs the currently-broken RPM matrix.Changes
pkgvars—pkglatest2.7.0.citus-1->2.7.1.citus-1postgres-matrix.yml— new entry2.7.1: postgres_versions: [ 14, 15, 16, 17, 18, 19 ](appended last; nightly readsversion_matrix[-1])topn.spec—Version2.7.0.citus->2.7.1.citus, source archivev2.7.0.tar.gz->v2.7.1.tar.gz, new%changelogentrypg_exclude.yml—el/8: [19]andol/8: [19]underrelease:.github/workflows/build-package.yml— migrated off the retiredsecrets.GH_TOKENPAT toactions/create-github-app-token@v3, matchingall-citusWhy the matrix drops PG 11-13
This branch is currently red on
MAIN_BRANCHand has been since 2026-02-11 — every RPM build since then has failed, on PG11, roughly two minutes in.Root cause is 3b0fcfe ("remove pg 10-13 from image checks", 2026-01-24), which changed
update_dockerfilesfrompgversions='11 12 13 14 15 16 17 18'to'14 15 16 17 18'. The RPM path runs one container per PG version, so a matrix entry with no corresponding build image is a hard failure. The firstredhat-topnbuild after that commit is the first failure — exact correlation.redhat-hllhit the same wall and was narrowed at 2.19 ([11..17]->[16, 17, 18]).redhat-topnnever was.[14, 15, 16, 17, 18, 19]matches the current image set (pgversions='14 15 16 17 18 19'on the packaging-images branch) and the debDEB_PG_SUPPORTED_VERSIONS.The historical
2.7.0entry is left untouched. The deb branch is unaffected — see that PR for why.Why
el/8/ol/8exclude PG19PGDG does not publish PostgreSQL 19 for EL8;
update_dockerfilescarries the same guard explicitly, so noalmalinux-8-pg19/oraclelinux-8-pg19image exists.ol/8needs its own key becausecitus_package.py'sdocker_image_nameshas nool/8entry — it falls through tooraclelinux-8, notalmalinux-8.Why the workflow change is in here
scripts/fetch_and_build_rpmwritesAuthorization: token ${GITHUB_TOKEN}into~/.curlrcand resolves the upstream tag through the GitHub API.secrets.GH_TOKENno longer exists, so that call returned 401 on a request that succeeds anonymously.MAIN_BRANCHstill references the dead secret, so this fix has to land here for the branch to build at all.Upstream tag note
v2.7.1was originally signed with a key GitHub reported asunknown_key, which trips the signature gate infetch_and_build_rpm. The tag has been re-signed with the established release key (4FB72F64B64E3FFC) and force-pushed upstream — same commit, same message, GitHub now reportsverification=true, reason=valid. Local clones may needgit fetch --tags --force.Verification
Dry run on the feature branch: all 4 rpm platforms green (
el/8,el/9,ol/8,ol/9) — the first green RPM build on this branch since January.Resolved versions confirmed in the logs:
el/8->Release versions: 14,15,16,17,18(PG19 correctly excluded)el/9->Release versions: 14,15,16,17,18,19Package publishing skipped since current branch is not equal to redhat-topnconfirmed — nothing was uploaded.All required build images verified present on Docker Hub, including
almalinux-8-pg14/15andoraclelinux-8-pg14/15, which this matrix exercises for the first time.on: push: branches: ["**"]with--build_type release, andupload_to_package_cloud.pyonly skips whencurrent_branch != MAIN_BRANCH. Merging this PR shipstopn 2.7.1.citus-1tocitusdata/community.