Generalize focal PostGIS build to a PG12-16 pipeline - #1214
Merged
Merged
Conversation
Contributor
Author
|
@microsoft-github-policy-service agree company="Microsoft" |
Kemal Büyükkaya (kemalbuyukkaya)
approved these changes
Aug 21, 2026
Kemal Büyükkaya (kemalbuyukkaya)
left a comment
Contributor
There was a problem hiding this comment.
Thanks, LGTM!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
PGDG removed Ubuntu 20.04 entirely —
focal-pgdg404s on its Release file, and the frozenapt-archivemirror tops out at PostGIS 3.5.3. There is no 3.6.x focal build to pin to, so a newer PostGIS on focal has to be rebuilt from upstream source.Driver is MSRC Incident-31000000674353, which requires PostGIS 3.6.4.
What this adds
dockerfiles/focal-postgis-builder/Dockerfilescripts/build_postgis_focaldebian/→dpkg-buildpackagescripts/smoke_test_focal_postgis_debs.github/workflows/build-postgis-focal.ymlModelled closely on
build-pg-focal.yml/build_pg_focal/smoke_test_focal_debs, including the debsigner mount convention and the.ddeb→.debrename.How it differs from the PostgreSQL core pipeline
No per-major matrix, and no
assemblejob. PostGIS's Debian packaging is multi-version by design (debian/pgversions+pg_buildext), so one source build emitspostgresql-<major>-postgis-3for every major in a single pass. The sharedpostgis/postgis-docpackages are produced exactly once, so there is no duplicate-name problem to de-duplicate.The archive components list includes
12.focal-pg-builderenablesmain 13 14 15 16 17; PostGIS 3.6 supports PG12+, sopostgresql-server-dev-12has to be reachable.PG11 is unsupported. PostGIS 3.6 requires PostgreSQL 12–18.
Two deliberate deviations from PGDG's package layout
Both are load-bearing — each fixes a failure that is silent at the package layer.
1. The arch-independent
-scriptspackage is folded into the runtime package.Upstream splits it so the SQL can be shared across architectures; we build amd64 only, so there is no benefit. Worse, the runtime's dependency on
-scriptsis unversioned, so a partial update happily pairs a 3.6.4.sowith 3.5.3 SQL andCREATE EXTENSIONthen runs the wrong definitions. One package makes that impossible.2. Extension control files are named
postgis-3.6.control, notpostgis-3.control, registered withupdate-alternativesat priority 36 (PGDG uses 30).PGDG's
-scriptsprerm runsupdate-alternatives --remove ... postgis-3.controlon removal. Sharing that path means removing the old package drops the last alternative and deletes thepostgis.controlsymlink — leaving a host wheredpkg -lreports the new version,default_versionreads3.6.4, the right contrib directory is on disk, and yet:A distinct suffix keeps the two alternatives independent. The runtime also carries
Conflicts/Replaces/Providesonpostgresql-<major>-postgis-3-scriptsso apt removes the old package in the same transaction.Integrity
The upstream tarball is sha256-pinned and verified (
download.osgeo.orgpublishes no detached signature):The frozen
debian/packaging is fetched withapt-get source, so it is authenticated by the archive's signedRelease.Testing
Built and verified locally under rootless podman using these exact scripts.
Build:
Smoke test — clean install, and install over PGDG's 3.5.3 runtime + dbgsym + scripts:
The build also fails hard if a dbgsym's exact-version dependency ever drifts from its runtime — that mismatch previously broke downstream image burns and is invisible until
apt --fix-broken installruns.Notes for reviewers
RUN_TESTS=1(upstream regression suite) is wired but never exercised — it may need build-deps the image lacks. Worth one dispatch before relying on it.DEB_REVISIONdefaults to1.citus20.04+1→3.6.4-1.citus20.04+1, which sorts above3.5.3+dfsg-1~exp1.pgdg20.04+1. Happy to change if that's not the convention you want.push:trigger onpostgis-focalmirrorspg-focalin the PG workflow, so this can be run before it reachesdevelop.dockerfiles/debsigner/scripts/import_and_signhas no post-signing verification, unlikerpmsigner, which was explicitly hardened against the "silent unsigned" bug. gpg failing there can exit 0 with unsigned debs. This workflow'sVerify signatures are embeddedstep covers it for this pipeline, but the signer itself may deserve the same treatment in a separate PR.